logo

RedpwnCTF 2020 Rust Pwn Writeups (Tetanus, Tetanus Shot)

ID: 194a22fb-971b-515c-a357-6fe4e586cead

STIX ID: report--194a22fb-971b-515c-a357-6fe4e586cead

Feed Name: Will's Root

Threat Score
45/100

Date Published: 2020-06-26

Date Updated: 2026-04-19

Author: Unknown

...
...

- This report analyzes two Rust pwnables from redpwnCTF 2020: “Tetanus” (contains a use-after-free due to unsafe drop_in_place leaving stale VecDeque references) and “Tetanus Shot” (abuses an unpatched VecDeque::reserve() OOB write, CVE-2018-1000657). Both writeups include full exploitation chains using heap metadata manipulation and tcache poisoning to overwrite __free_hook with system and spawn a shell; exploit scripts and mitigation context (libc versions, CVE) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.