I repropose my notes about x86, Linux and virtualization in a single text file (~2500 lines only) for my fellow students in Sapienza.
https://t.co/WAVkHShozW
Maybe I create a too hard challenge for realworld ctf this year. But I think this vulnerability is very interesting. It can be used to overwrite a heap like that:
a = malloc(0xa0);
...
a[you_can_control] = htons(ntohs(a[you_can_control])-num)
Been almost a year after I discovered this guest remote code execution on Fusion 11.x-11.0.2 and there is already a writeup by @theevilbit: https://t.co/VEaswnsT6j I'll be presenting more notes on reverse engineering this bug at #realworldctf tech forum.
First time to finish flareon! Now I can enjoy my holiday~
Thanks the great help from @zvikam and @hasherezade
Learn so much from last challenge! Which let me know I just a crackme player not a reverse engineer...😂 #flareon6
#flareon6
Ah...I am so stupid!!!
I worked for chal 5 from last night to now...I have tried many ways to get flag, but finally I realized that the solution was very simple!