logo

Yet Another House ASIS Finals 2020 CTF Writeup

ID: d3453cff-e161-5f5e-ab32-f260765fe963

STIX ID: report--d3453cff-e161-5f5e-ab32-f260765fe963

Feed Name: Will's Root

Threat Score
30/100

Date Published: 2020-12-30

Date Updated: 2026-04-19

Author: Unknown

...
...

This writeup documents a CTF heap pwnable exploit against glibc 2.32: the author combines a poison null byte, large/unsorted-bin manipulations, a tcache stashing unlink attack to overwrite mp_.tcache_bins, and a tcache poison to gain an arbitrary write to __free_hook, then uses a COP gadget to pivot, bypass seccomp, and execute a ROP/mprotect+shellcode sequence. The report includes implementation details, mitigation notes, and step-by-step heap massaging used to achieve the exploit.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.