Format String Vulnerability - "Floor Mat Store" [INTIGRITI 1337UP LIVE CTF 2023]

Опубликовано: 15 Октябрь 2024
на канале: CryptoCat
1,670
63

Video walkthrough for "Floor Mat Store", a binary exploitation challenge I made for the ‪@intigriti‬ 1337UP LIVE CTF 2023. It was a fairly standard pwn challenge, requiring players to exploit a format string vulnerability (damn you printf *shakes fist at computer*). I tried to add some small twists and give it a theme to keep it interesting! Write-ups/tutorials aimed at beginners - Hope you enjoy 🙂 #INTIGRITI #CTF #Pwn #BinaryExploitation #BugBounty

↢Social Media↣
Twitter:   / _cryptocat  
GitHub: https://github.com/Crypto-Cat/CTF
HackTheBox: https://app.hackthebox.eu/profile/11897
LinkedIn:   / cryptocat  
Reddit:   / _cryptocat23  
YouTube:    / cryptocat23  
Twitch:   / cryptocat23  

↢INTIGRITI 1337UPLIVE CTF↣
https://ctftime.org/event/2134
https://ctf.intigriti.io
https://go.intigriti.com/discord

↢Resources↣
Ghidra: https://ghidra-sre.org/CheatSheet.html
Volatility: https://github.com/volatilityfoundati...
PwnTools: https://github.com/Gallopsled/pwntool...
CyberChef: https://gchq.github.io/CyberChef
DCode: https://www.dcode.fr/en
HackTricks: https://book.hacktricks.xyz/pentestin...
CTF Tools: https://github.com/apsdehal/awesome-ctf
Forensics: https://cugu.github.io/awesome-forensics
Decompile Code: https://www.decompiler.com
Run Code: https://tio.run

↢Chapters↣
0:00 Start
0:50 Basic file checks
3:48 Explore functionality
4:57 Identify format string vulnerability
9:38 PwnTools script
12:48 Disassemble with Ghidra
15:05 Leak flag
16:34 Challenge source code
17:46 End