logo

RedpwnCTF 2020 Pwn Writeups (Four Function Heap, Zero the Hero)

ID: 1f65cdac-cf99-5495-978a-5154d21267a1

STIX ID: report--1f65cdac-cf99-5495-978a-5154d21267a1

Feed Name: Will's Root

Threat Score
15/100

Date Published: 2020-06-26

Date Updated: 2026-04-19

Author: Unknown

...
...

RedpwnCTF 2020 pwn writeup covering two heap exploitation challenges: 'Four Function Heap' — a libc 2.27 tcache double-free and tcache_perthread_struct poisoning leading to an overwrite of __free_hook to execute system("/bin/sh"); and 'Zero the Hero' — an FSOP-based attack that forges _IO_FILE structures to overwrite __malloc_hook with a one-gadget. The report includes reversed pseudocode, a 14-step exploit plan for the first challenge, a bruteforce-and-FSOP approach for the second, and complete Python/Pwn scripts and notes about target libc offsets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.