tl;dr
LOAD
andS_TYPE
opcodes lead to OOB when addr >DRAM_BASE+DRAM_SIZE
- Get libc and stack pointers and offset to obtain RIP offset and base
- Write ropchain on stack using libc gadgets
- Perform ORW on flag file
tl;dr
LOAD
and S_TYPE
opcodes lead to OOB when addr > DRAM_BASE+DRAM_SIZE
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
- CSS injection using url forging
- leaking password using :empty
selectors