Ciscn2021 Pwn
Ciscn2021-pwn国赛部分pwn题的解答 lonelywolfdouble_free leak heap address ,打tcache_struct,leak libc,控制 next指针覆写__mallo
Challenges | Tricks |
---|---|
pwnble.tw-silver_bullet | stack overflow |
pwnable.tw-applestore | UAF in stack |
pwnable.tw-Re-alloc | UAF +tcache poisoning |
pwnable.tw-Tcache Tear | tcache poisoning |
Lilac 2021 五一欢乐赛-babyFAT | 数组超界 |
Lilac 2021 五一欢乐赛-befunge | 数组超界 |
Lilac 2021 五一欢乐赛-noleak | house_of_roman +IO_file leak |
Challenges | Tricks |
---|---|
BUU-hitcontraining-magicheap | unsortedbin attack |
BUU-hitcontraining_bamboobax | unlink /house_of_force |
BUU-0ctf_2017_babyheap | heap overflow +house_of_spirit |
BUU-heapcreator | off-by-one |
BUU-[ZJCTF2019]easyheap | unlink |
安恒三月赛-fruitpie | mmap attack |
NahamconCTF-2021-sort_it | 数组超界 +ROP |
Challenges | Tricks |
---|---|
BUU-houseoforange_hitcon_2016 | house_of_orange |
BUU-npuctf2020-easyheap | off-by-one +ovlapping chunk |
BUU-hitcon2018_children_tcache | off-by-null +tcache_psisoning |
BUU-vn2020-easyTHeap | tcache_psisoning +hacking tcache struct |
BUU-vn2020-simpleheap | off-by-one +ovlapping chunk +house_of_spirit |
BUU-vn2020-warmup | orw |
BUU-hitcontraining-stkof | unlink |