- Stack Overflow
gets()
doesn't check a boundary of input array.
- pwndbg
- ghidra
ROPgadget
-
Soooooooooo simple binary
-
Exploit
- ROP Chain
---------------- <- return address pop rdi ; ret ---------------- 0xdeadbeef ---------------- & get_flag() ----------------
ex.py
- ROP Chain
-
utflag{thanks_for_the_string_!!!!!!}