Published onFebruary 17, 2024PUCon' 24 - Userspace - Palatepuconuserspacectfpwnpie-bypassprintfret2winUtilizing Format String Vulnerability to leak the address of PIE and then a simple Ret2Win with args.
Published onOctober 9, 2023Blackhat MEA '23 Quals - Pwn - Profilectfpwnblackhatmea23interger-overflowprintffsbExploiting an integer overflow to overwrite got entries, get leaks with printf and then overwriting the GOT entry of `free` with `system` to get a shell.