[UCSB iCTF 2017] pokemon(type: pwn) write-ups

This is an interesting challenge in UCSB iCTF 2017, we had a lot of fun. But when we finished the exploit, the game server including the scoreboard went down before the end.

This wp contains only a writeup local exploit. One of my teammate improved it to achive arbitrary file read to get the flag. It’s a pity we can not actually get a real flag in the game.

DEFCON 2016 CTF Quals pwnable banker writeup

Banker is a big statically linked executable:

Plaid CTF 2015 writeup(prodmanager, clifford, ebp, unknown)

1. prodmanager(180 points)

0CTF-2015 freenote: playing with malloc library

I spent several hours on this challenge, the logic of this program is simple and an information leakage vulnerability was discovered. But I was not familiar with malloc’s heap management scheme and failed to exploit this vulnerability.

BCTF 2015 pwn challenge: zhongguancun

The general idea to pwn this toy online store system is as following, firstly we need to find a control flow hijack vulnerability which in this case is a vtable hijack based on heap buffer overflow, secondly we will bypass all the integrity checks in the program and the memory defenses(e.g. ASLR) to call “system(“sh”)” in libc.

