Srdnlen 2025 - Kinderheim 511

Heap challenge with the goal of achieving arbitrary write to read the flag from the heap.

January 21, 2025 · leo_something & Lotus · 0 views

Kpwn tecniques: modprobe_path

modprobe_path is a global variable that in most kernels is RW. This variable is contains a path to an executable, do you see where this is going..?

January 14, 2025 · leo_something · 0 views

Kpwn tecniques: struct msg_msg

msg_msg is a really powerful and elastic kernel struct that can be abused to obtain strong primitives, such as arbitrary read/write/free.

January 14, 2025 · leo_something · 0 views

CTE24 - DiDUP

This is an hard pwn challenge I wrote for Compete Against TeamEurope, this CTF was part of the training for ECSC2024. The vulnerability is a double-free triggerable through a race condition. No bruteforce is needed.

September 16, 2024 · leo_something · 0 views

UIUCTF24 - Pwnymalloc

Pwnymalloc is a nice custom allocator challenge from UIUCTF 2024. The vulnerability was about an incorrect handling of the prev_size during consolitation.

July 8, 2024 · leo_something · 0 views

Ret2dlresolve in 64bit binaries

Ret2dlresolve is a really powerful tecnique to use in pwn challenges (even tho it’s not frequently seen). It’s useful when we don’t have libc leaks or don’t know the libc version.

June 12, 2024 · leo_something · 0 views