- Format String Bug (x86)
- pwndbg
- IDA 7.0
-
Vulnerability
-
Exploit
- In my case, overwrited
exit@got
with0x804AACD
because I thought it needs to enter several times using FSB. - Memory Leak
- Get shell
- I used one shot at
fileno@got
.- I had a hard time finding a function to match the constraints :(
- I used one shot at
ex.py
- In my case, overwrited
-
pctf{r3Pr0gr4mM1ng_tH3_Gam3_1z_th3_0nly_s0lut10n}