Taz
⌘Ctrl K

Journal

Writeups for challenges I solve, grouped by technique.

  1. 29 Sep 2026 Au Revoir stack overflow · ROP · ret2win · TCP half-close
  2. 29 Sep 2026 Full Clip format string · %n write · self-referential stack pointer
  3. 29 Sep 2026 Radio Los Santos format string · stack information leak
  4. 29 Sep 2026 Radio Vice City format string · positional specifiers · stack information leak
  5. 29 Sep 2026 Rocketman format string · %n write · multi-stage write
  6. 29 Sep 2026 Rootstar Games format string · %n write · authentication bypass
  7. 29 Sep 2026 Same Same But Different! format string · %n write · authentication bypass
  8. 29 Sep 2026 Short Fuse format string · GOT overwrite · %hn write · PLT/GOT pivot
  9. 29 Sep 2026 Speed Dial raw syscall
  10. 29 Sep 2026 The Safehouse format string · arbitrary write · ret2shellcode
  11. 29 Sep 2026 Wrong Number raw syscall · execveat
  12. 29 Sep 2026 Wrong Turn stack overflow · ret2shellcode · executable stack
  13. 20 Mar 2026 5959595959 stack overflow · SROP · stack pivot · sigreturn
  14. 20 Mar 2026 ARMBLUSBLUS stack overflow · ret2win · ROP · aarch64
  15. 20 Mar 2026 Fill me stack overflow · ret2win
  16. 20 Mar 2026 Flip Flip Flip arbitrary bit flip · loop counter corruption · function pointer overwrite
  17. 20 Mar 2026 Hope Exploitation use-after-free · tcache poisoning · safe-linking bypass · heap pointer leak
  18. 20 Mar 2026 print(xxx); format string · libc leak · canary bypass · GOT overwrite · one_gadget
  19. 20 Mar 2026 Who likes assembly anw ? stack overflow · ROP · shellcode · seccomp · /proc/self/maps scan

Journal / The Stack 1 / 19

Au Revoir

A TCP chat service overflows in a loop; half-closing the socket forces a return into a ROP call to the binary's own win().

29 Sep 2026 · 4 min read · stack overflow · ROP

The Stack

  • .1-the-program
  • .2-why-one-iteration-isnt-enough-by-itself
  • .3-the-exploit--solverpy
  • .4-running-it

profile

difficulty
medium
arch
amd64
read
4 min
Read full article

Journal / Format Strings 2 / 19

Full Clip

One read, one printf: a self-planted stack pointer lets a single %hhn write flip a loop-local integer to win()'s target value.

29 Sep 2026 · 3 min read · format string · %n write

Format Strings

  • .1-the-program
  • .2-getting-printf-to-write-into-i--with-no-leaked-address
  • .3-running-it
  • .4-lesson

profile

difficulty
easy
arch
amd64
read
3 min
Read full article

Journal / Format Strings 3 / 19

Radio Los Santos

The flag lands on the stack before the vulnerable printf(buf) runs, so a bare %s walks phantom arguments straight onto it.

29 Sep 2026 · 2 min read · format string · stack information leak

Format Strings

  • .1-the-program
  • .2-why-thats-dangerous-s-without-an-argument
  • .3-the-exploit
  • .4-running-it

profile

difficulty
easy
arch
amd64
read
2 min
Read full article

Journal / Format Strings 4 / 19

Radio Vice City

Same leak as Radio Los Santos, but deeper on the stack, so the exploit sweeps positional %p arguments instead of one offset.

29 Sep 2026 · 3 min read · format string · positional specifiers

Format Strings

  • .1-the-program
  • .2-the-exploit-sweep-with-positional-p
  • .3-why-this-works-without-any-got-overwrite-or-shellcode
  • .4-running-it

profile

difficulty
easy
arch
amd64
read
3 min
Read full article

Journal / Format Strings 5 / 19

Rocketman

Full Clip's sibling: a smaller buffer and two printf calls split the same %n write to a loop counter across two payloads.

29 Sep 2026 · 2 min read · format string · %n write

Format Strings

  • .1-the-program
  • .2-two-shots-two-writes
  • .3-running-it
  • .4-full-clip-vs-rocketman-side-by-side

profile

difficulty
medium
arch
amd64
read
2 min
Read full article

Journal / Format Strings 6 / 19

Rootstar Games

A login gate hides an embedded-NUL password, then a %n write flips the logged-in account's role field to "CEO".

29 Sep 2026 · 3 min read · format string · %n write

Format Strings

  • .1-the-program
  • .2-the-format-string-bug--targeting-the-role-field
  • .3-the-payload
  • .4-running-it

profile

difficulty
medium
arch
amd64
read
3 min
Read full article

Journal / Format Strings 7 / 19

Same Same But Different!

Rootstar Games with its struct reordered: every offset shifts, and the fix is overwriting the comparison buffer, not the role.

29 Sep 2026 · 3 min read · format string · %n write

Format Strings

  • .1-what-changed-vs-rootstar-games
  • .2-login-step
  • .3-the-format-string-write--overwriting-the-check-not-the-role
  • .4-running-it

profile

difficulty
medium
arch
amd64
read
3 min
Read full article

Journal / Format Strings 8 / 19

Short Fuse

A length check and a self-overlapping sprintf hide a %hn write that loops exit into main and pivots puts into system.

29 Sep 2026 · 7 min read · format string · GOT overwrite

Format Strings

  • .1-what-the-program-does
  • .2-trick-1--sneaking-past-the-5-characters-gate
  • .3-trick-2--the-self-overlapping-sprintf
  • .4-the-plan-overwrite-the-got-to-pop-a-shell

profile

difficulty
hard
arch
amd64
read
7 min
Read full article

Journal / Signals & Syscalls 9 / 19

Speed Dial

strlen(buf) picks the syscall, read()'s return value the fd; 3 bytes turns it into read(3,buf,511), replaying the flag fd through puts().

29 Sep 2026 · 2 min read · raw syscall

Signals & Syscalls

  • .1-the-program
  • .2-the-syscall
  • .3-the-payload
  • .4-running-it

profile

difficulty
easy
arch
amd64
read
2 min
Read full article

Journal / Shellcode 10 / 19

The Safehouse

A fixed-address RWX page is filled with shellcode via a format-string write, then a stack overflow jumps to it.

29 Sep 2026 · 3 min read · format string · arbitrary write

Shellcode

  • .1-the-program
  • .2-the-plan
  • .3-the-exploit--solverpy
  • .4-running-it

profile

difficulty
medium
arch
amd64
read
3 min
Read full article

Journal / Signals & Syscalls 11 / 19

Wrong Number

read()'s return value is passed straight through as a raw syscall number; 322 bytes turns it into execveat("/bin/sh").

29 Sep 2026 · 3 min read · raw syscall · execveat

Signals & Syscalls

  • .1-the-program
  • .2-picking-the-syscall-number
  • .3-turning-322-into-how-many-bytes-to-send
  • .4-running-it

profile

difficulty
easy
arch
amd64
read
3 min
Read full article

Journal / The Stack 12 / 19

Wrong Turn

With an executable stack and no canary, shellcode in buf is reached via a jmp rsi gadget with no leaked address needed.

29 Sep 2026 · 3 min read · stack overflow · ret2shellcode

The Stack

  • .1-the-program
  • .2-the-plan
  • .3-the-exploit--solverpy
  • .4-running-it

profile

difficulty
medium
arch
amd64
read
3 min
Read full article

Journal / Signals & Syscalls 13 / 19

5959595959

A stack overflow pivots the frame into .bss, then plants a SigreturnFrame there and SROPs into execve("/bin/sh").

20 Mar 2026 · 2 min read · stack overflow · SROP

Signals & Syscalls

  • .overview
  • .vulnerability-analysis
  • .exploitation-strategy-matches-solvepy
  • .result

profile

difficulty
hard
arch
amd64
read
2 min
Read full article

Journal / The Stack 14 / 19

ARMBLUSBLUS

An unbounded cin >> buf overflow on AArch64 is chained through a gadget that loads w0 to satisfy win(int)'s check.

20 Mar 2026 · 1 min read · stack overflow · ret2win

The Stack

  • .overview
  • .vulnerability-analysis
  • .exploitation-strategy-matches-solvepy
  • .notes

profile

difficulty
medium
arch
aarch64
read
1 min
Read full article

Journal / The Stack 15 / 19

Fill me

An 8-byte overflow clobbers an adjacent sentinel variable, enough to trip win() without touching the return address.

20 Mar 2026 · 1 min read · stack overflow · ret2win

The Stack

  • .overview
  • .vulnerability-analysis
  • .exploitation-strategy-matches-solvepy
  • .result

profile

difficulty
easy
arch
amd64
read
1 min
Read full article

Journal / Bit Flips 16 / 19

Flip Flip Flip

A 3-use bit-flip primitive becomes unlimited by corrupting its own loop counter, then rebuilds "/bin/sh" one bit at a time.

20 Mar 2026 · 2 min read · arbitrary bit flip · loop counter corruption

Bit Flips

  • .overview
  • .vulnerability-analysis
  • .exploitation-strategy-matches-solvepy
  • .result

profile

difficulty
medium
arch
amd64
read
2 min
Read full article

Journal / The Heap 17 / 19

Hope Exploitation

A UAF from an unset pointer leaks the safe-linking key and a heap address, then poisons tcache onto the flag bytes.

20 Mar 2026 · 3 min read · use-after-free · tcache poisoning

The Heap

  • .overview
  • .vulnerability-analysis
  • .exploitation-strategy-matches-solvepy
  • .notes--gotchas

profile

difficulty
hard
arch
amd64
read
3 min
Read full article

Journal / Format Strings 18 / 19

print(xxx);

A puts leak gives the libc base; one format string smashes the canary and points __stack_chk_fail at a one_gadget.

20 Mar 2026 · 3 min read · format string · libc leak

Format Strings

  • .overview
  • .vulnerability-analysis
  • .exploitation-strategy-matches-solvepy
  • .result

profile

difficulty
medium
arch
amd64
read
3 min
Read full article

Journal / Shellcode 19 / 19

Who likes assembly anw ?

The flag sits at a randomized address, so a stack overflow pivots into a fixed RWX page and shellcode scans /proc/self/maps.

20 Mar 2026 · 3 min read · stack overflow · ROP

Shellcode

  • .overview
  • .vulnerability-analysis
  • .exploitation-strategy-matches-solvepy
  • .result

profile

difficulty
hard
arch
amd64
read
3 min
Read full article
Esc

    ↓ results · Enter open · Esc close

    Keys

    jk
    Next and previous row
    ↓↑
    The same, once a row has focus
    Enter
    Open the row
    1234
    Home, Projects, Journal, About
    /
    Search
    CtrlK
    Search, from anywhere (⌘ K on a Mac)
    ?
    This list
    Esc
    Close a layer
    gg
    Back to the top