tl;dr
LOADandS_TYPEopcodes lead to OOB when addr >DRAM_BASE+DRAM_SIZE- Get libc and stack pointers and offset to obtain RIP offset and base
- Write ropchain on stack using libc gadgets
- Perform ORW on flag file
tl;dr
LOAD and S_TYPE opcodes lead to OOB when addr > DRAM_BASE+DRAM_SIZEtl;dr
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
- CSS injection using url forging
- leaking password using :empty selectors