Challenge #26 "Hashcalc2" was very similar to Hashcalc1.
Again, a good write-up is already available on sleepya's blog. He made an exploit bypassing any ASLR/NX using ROP.
Again since NX was not enabled, I used a similar exploitation with a few adjustements.
Showing posts with label got. Show all posts
Showing posts with label got. Show all posts
Tuesday, April 26, 2011
pCTF 2011 #22 Hashcalc1
Challenge #22 "Hashcalc 1" was binary exploitation over the network.
A good write-up is already available on sleepya's blog. He made an exploit bypassing any ASLR/NX using ROP.
However, NX was not enabled on the wargame machine... Organizers thought they did, but it was not effective :( Good for us it means only ASLR, and the binary was not even PIE. One could exploit it quickly by writing a shellcode in the GOT, let's see that.
A good write-up is already available on sleepya's blog. He made an exploit bypassing any ASLR/NX using ROP.
However, NX was not enabled on the wargame machine... Organizers thought they did, but it was not effective :( Good for us it means only ASLR, and the binary was not even PIE. One could exploit it quickly by writing a shellcode in the GOT, let's see that.
Monday, November 01, 2010
Hack.lu CTF - Challenge 19 "magicwall" writeup, double strcpy
I did not solve challenge 19 "magicwall" during the CTF - my friend Ivanlef0u (@Ivanlef0u) did - but since Fluxfingers (@fluxfingers) kept the CTF online, I had the chance to pwn it too! Just like challenge 20 "sscat", it was binary exploitation.
Hellman (@hellman1908) already made a very good writeup, I just wanted to share my different method.
Hellman (@hellman1908) already made a very good writeup, I just wanted to share my different method.
Subscribe to:
Posts (Atom)