tl;dr
- This challenge revolves around a hidden
power_tower_modfunction. - To obtain the flag, we implement the function ourselves, apply Hensel lifting, collide a CMAC, decrypt an RSA ciphertext and finally solve a subset sum problem.
tl;dr
power_tower_mod function. tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
memcpy in CPY goes out-of-bounds of VM stack. memcpy to copy the register struct to stack and modify the values using stack operations and register operations.bp and sp registers.environ pointer to get stack leak.main function’s stack to overwrite return address with ROP chain or one-gadget.tl;dr
tl;dr
tl;dr
1 / 19