bi0s
  •  Home
  •  Categories
  •  Archives
  •  Tags
  •  Home
  •  Categories
  •  Archives
  •  Tags

Baby Glob - InCTF Internationals 2021

Cyb0rG
2021-08-17
Pwn

tl;dr

  • Heap Overflow in glob function while handling Tilde operator.
  • Abuse null byte overflow to gain RCE.
Read More
InCTFi Exploitation Heap CVE-2017-15804

Kqueue - InCTF Internationals 2021

Cyb0rG
2021-08-17
Pwn

tl;dr

  • Use the integer overflow to trigger a kernel heap overflow.
  • Use the heap overflow to overwrite tty structure function pointers to get code execution.
Read More
InCTFi Exploitation Linux Kernel Kernel Heap

Ancient House - InCTF Internationals 2021

Pwn-Solo
2021-08-15
Pwn

tl;dr

  • Jemalloc heap challenge
  • A buggy implementation of strncat in merge allows for an overwrite onto the next region
Read More
InCTFi Exploitation Linux Heap Jemalloc

DeadlyFastGraph - InCTF Internationals 2021

d4rk_kn1gh7
2021-08-15
Pwn

tl;dr

  • Arbitrary type confusion in DFG JIT
  • Bug eliminates a single CheckStructure node
Read More
InCTFi Exploitation Browser Safari

Favourite Architecture-1 - StarCTF 2021

Pwn-Solo
2021-01-20
Pwn

tl;dr

  • Abusing a stack overflow on a RISC-V binary to then return to shellcode.
Read More
Exploitation Linux StarCTF Shellcode RISC-V

Smash - TokyoWesterns CTF 2020

Cyb0rG
2020-09-22
Pwn / CET

tl;dr

  • Leak with Format String bug.
  • Use the arbitrary heap pointer write to overwrite __GI__IO_file_jumps.
  • Inject shellode in heap and get code execution in dfprintf.
Read More
Exploitation Format String CET BOF TokyoWesterns CTF

Grid - CSAW Quals 2020

d4rk_kn1gh7
2020-09-18
Pwn

tl;dr

  • Out-of bounds index write allows byte-by-byte overwrite of return address
Read More
Exploitation Linux CSAW Quals

The Bards' Fail - CSAW Quals 2020

Pwn-Solo
2020-09-15
Pwn

tl;dr

  • Carefully arranging structs on stack so as to overwrite saved rip , without corrupting the stack canary.
  • Leak libc with puts and execute a ret2libc to get shell
Read More
Exploitation Linux CSAW Quals

bartender - InCTF Internationals 2019

slashb4sh
2019-10-11
Pwn / Windows

Writeup from InCTFi 2019 bartender

tl;dr Windows 32-bit SEH exploitation

Read More
InCTFi Exploitation Write-up Windows

ateles - InCTF Internationals 2019

sherl0ck
2019-10-09
Pwn / Browser-Exploitation

tl;dr 2 element overflow in Array when jit compiled

Read More
Exploitation Write-up CTF JIT spidermonkey

 Previous 

2 / 3

 Next 

Official blog of team bi0s

  Projects
  •   bi0s-wargame
    (Unraveling)
  •   bi0s-wiki
    (Free Encyclopedia)
  •   InCTF
    (Nationals CTF)
  •   InCTFj
    (Juniors CTF)

Made With Love and Coffee



Blog content follows the Attribution-NonCommercial-ShareAlike 4.0 International (CC BY-NC-SA 4.0) License

Use Material X as theme, total visits times.