Questionnaire: use the format-string bug for a leak or write, then redirect execution to the flag path.
pwnlocked
Questionnaire: use the format-string bug for a leak or write, then redirect execution to the flag path.
RaceCar: use the format-string bug for a leak or write, then redirect execution to the flag path.
DearQA: shape the heap state, gain the needed write or leak, and pivot to flag access.