RaceCar: use the format-string bug for a leak or write, then redirect execution to the flag path.
Linux
134 postsEl Mundo
El Mundo: calculate the overflow offset, redirect control flow, and land a reliable flag read.
El Pipo
El Pipo: calculate the overflow offset, redirect control flow, and land a reliable flag read.
LinkVortex
LinkVortex: use CVE-2023-40028 where it fits the service, gain a shell, and escalate to root.
Bizness
Bizness: use CVE-2023-49070 and CVE-2023-51467 where it fits the service, gain a shell, and escalate to root.
Inject
Inject: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Unrested
Unrested: use CVE-2024-36467 and CVE-2024-42327 where it fits the service, gain a shell, and escalate to root.
Vintage
Vintage: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Kernel Adventures 2
Kernel Adventures 2: build the shellcode path, control execution, and read the flag.
Execute
Alert
Dont't Panic
Dont't Panic: trace the binary, isolate the validation routine, and invert it to recover the flag.
El Teteo
El Teteo: build the shellcode path, control execution, and read the flag.
Mathematricks
Mathematricks: build the exploit primitive, stabilize the payload, and use it to read the flag.
Que Onda
Que Onda: build the exploit primitive, stabilize the payload, and use it to read the flag.
Regularity
Regularity: build the exploit primitive, stabilize the payload, and use it to read the flag.
SpellBrewery
SpellBrewery: build the exploit primitive, stabilize the payload, and use it to read the flag.
BlockBlock
Ghost
WayBack
Administrator
Administrator: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Certified
Certified: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Blazorized
Blazorized: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Epsilon
Epsilon: enumerate the services, turn the exposed weakness into a shell, and escalate to root.
Shattered Tablet
Shattered Tablet: trace the binary, isolate the validation routine, and invert it to recover the flag.
Mist
Mist: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Axlle
Axlle: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Beep
Beep: use CVE-2012-4869 where it fits the service, gain a shell, and escalate to root.