zer0pts CTF 2021 Nasm-Kit Writeup (unicorn engine emulator escape)
ID: 5058d151-5bd9-5d1a-8d10-a4771ce6a1ce
STIX ID: report--5058d151-5bd9-5d1a-8d10-a4771ce6a1ce
Feed Name: Will's Root
Threat Score
This is a CTF write-up detailing an exploit for an x86_64 emulator implemented with the Unicorn engine. The author describes using MAP_FIXED_NOREPLACE to probe memory and discover libc mappings under ASLR, then using MAP_FIXED with MAP_ANONYMOUS to overwrite a libc .text page with a NOP sled and a jump to shellcode, enabling an emulator escape and a shell; the report includes methodology, heuristics, and payload encoding notes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
