<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Pwn :: X3ric Blog</title><link>https://x3ric.com/blog/tags/pwn/</link><description>CTF notes, systems work, and writeups.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 06 Jun 2026 21:41:13 +0200</lastBuildDate><atom:link href="https://x3ric.com/blog/tags/pwn/index.xml" rel="self" type="application/rss+xml"/><item><title>HackTheBox TicTacToed Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-TicTacToed-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-TicTacToed-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>format-string</category><category>heap</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>Binary Exploitation</title><link>https://x3ric.com/blog/posts/Binary-Exploitation/</link><guid>https://x3ric.com/blog/posts/Binary-Exploitation/</guid><pubDate>Tue, 04 Feb 2025 04:10:00 +0800</pubDate><category>notes</category><category>notes</category><category>linux</category><category>pwn</category><description>Assembly Overview Assembly language is a low-level programming language that translates high-level code into machine instructions. Registers temporarily hold data and facilitate operations.</description></item><item><title>HackTheBox Rebuilding Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Rebuilding-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Rebuilding-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Rebuilding: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Under the web Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Under-the-web-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Under-the-web-Challenge/</guid><pubDate>Sat, 11 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Vault-breaker Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Vault-breaker-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Vault-breaker-Challenge/</guid><pubDate>Tue, 17 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Vault-breaker: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Getting Started Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Getting-Started-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Getting-Started-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>linux</category><description>Getting Started: calculate the overflow offset, redirect control flow, and land a reliable flag read.</description></item><item><title>HackTheBox Questionnaire Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Questionnaire-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Questionnaire-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>format-string</category><category>canary</category><category>linux</category><description>Questionnaire: use the format-string bug for a leak or write, then redirect execution to the flag path.</description></item><item><title>HackTheBox Space Pirate Going Deeper Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Space-Pirate-Going-Deeper-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Space-Pirate-Going-Deeper-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Space Pirate Going Deeper: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Wizard's Diary Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Wizards-Diary-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Wizards-Diary-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>linux</category><description>Wizard's Diary: calculate the overflow offset, redirect control flow, and land a reliable flag read.</description></item><item><title>HackTheBox Writing on the Wall Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Writing-on-the-Wall-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Writing-on-the-Wall-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Writing on the Wall: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Entity Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Entity-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Entity-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Entity: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Pixel Audio Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Pixel-Audio-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Pixel-Audio-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Pixel Audio: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox RaceCar Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-RaceCar-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-RaceCar-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>format-string</category><category>linux</category><description>RaceCar: use the format-string bug for a leak or write, then redirect execution to the flag path.</description></item><item><title>HackTheBox El Mundo Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-El-Mundo-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-El-Mundo-Challenge/</guid><pubDate>Mon, 09 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>linux</category><description>El Mundo: calculate the overflow offset, redirect control flow, and land a reliable flag read.</description></item><item><title>HackTheBox El Pipo Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-El-Pipo-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-El-Pipo-Challenge/</guid><pubDate>Mon, 09 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>linux</category><description>El Pipo: calculate the overflow offset, redirect control flow, and land a reliable flag read.</description></item><item><title>HackTheBox Kernel Adventures 2 Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Kernel-Adventures-2-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Kernel-Adventures-2-Challenge/</guid><pubDate>Tue, 03 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>shellcode</category><category>linux</category><description>Kernel Adventures 2: build the shellcode path, control execution, and read the flag.</description></item><item><title>HackTheBox Execute Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Execute-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Execute-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>shellcode</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox El Teteo Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-El-Teteo-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-El-Teteo-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>shellcode</category><category>linux</category><description>El Teteo: build the shellcode path, control execution, and read the flag.</description></item><item><title>HackTheBox Mathematricks Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Mathematricks-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Mathematricks-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Mathematricks: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Que Onda Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Que-Onda-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Que-Onda-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Que Onda: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Regularity Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Regularity-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Regularity-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Regularity: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox SpellBrewery Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-SpellBrewery-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-SpellBrewery-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>SpellBrewery: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>TryHackMe DearQA Challenge</title><link>https://x3ric.com/blog/posts/TryHackMe-DearQA-Challenge/</link><guid>https://x3ric.com/blog/posts/TryHackMe-DearQA-Challenge/</guid><pubDate>Fri, 28 Jun 2024 01:20:00 +0800</pubDate><category>challenge</category><category>thm</category><category>pwn</category><category>bof</category><category>format-string</category><category>heap</category><category>shellcode</category><category>linux</category><description>DearQA: shape the heap state, gain the needed write or leak, and pivot to flag access.</description></item></channel></rss>