Getting Started: calculate the overflow offset, redirect control flow, and land a reliable flag read.
pwnlocked
Getting Started: calculate the overflow offset, redirect control flow, and land a reliable flag read.
Questionnaire: use the format-string bug for a leak or write, then redirect execution to the flag path.
Wizard's Diary: calculate the overflow offset, redirect control flow, and land a reliable flag read.
El Mundo: calculate the overflow offset, redirect control flow, and land a reliable flag read.
El Pipo: calculate the overflow offset, redirect control flow, and land a reliable flag read.
DearQA: shape the heap state, gain the needed write or leak, and pivot to flag access.