Posts

HTB - Pwn: TicTacToed

Reverse-engineering the hidden Rust auth flow, then hijacking the dropped C2 binary via UAF to execute getSecret and recover the flag.

HTB - Pwn: Portaloo

UAF + safe-linking heap recovery + canary leak + staged RWX heap shellcode for reliable remote command execution.

HTB - Pwn: Evil Corp

Wide-char truncation overflow to controlled RIP, then Unicode-safe shellcode execution from a fixed executable mmap region.

 

Zero

CTF notes by Zero