video thumbnail 13:24
Format String to dump binary and gain RCE - 33c3ctf ESPR (pwn 150)

2017-01-13

[public] 40.9K views, 1.37K likes, 10.0 dislikes audio only

Solving Eat Sleep Pwn Repeat (ESPR - 150 pwn) challenge from the 33c3ctf. Dumping the binary through a format string vulnerability, leaking libc addresses in the global offset table, finding the matching libc and overwriting printf@got with system() to get RCE.

-=[ šŸ”“ Stuff I use ]=-

ā†’ Microphone:* https://geni.us/ntg3b

ā†’ Graphics tablet:* https://geni.us/wacom-intuos

ā†’ Camera#1 for streaming:* https://geni.us/sony-camera

ā†’ Lens for streaming:* https://geni.us/sony-lense

ā†’ Connect Camera#1 to PC:* https://geni.us/cam-link

ā†’ Keyboard:* https://geni.us/mech-keyboard

ā†’ Old Microphone:* https://geni.us/mic-at2020usb

US Store Front:* https://www.amazon.com/shop/liveoverflow

-=[ ā¤ļø Support ]=-

ā†’ per Video: https://www.patreon.com/join/liveoverflow

ā†’ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ šŸ• Social ]=-

ā†’ Twitter: https://twitter.com/LiveOverflow/

ā†’ Website: https://liveoverflow.com/

ā†’ Subreddit: https://www.reddit.com/r/LiveOverflow/

ā†’ Facebook: https://www.facebook.com/LiveOverflow/

-=[ šŸ“„ P.S. ]=-

All links with "*" are affiliate links.

LiveOverflow / Security Flag GmbH is part of the Amazon Affiliate Partner Programm.

#CTF #FormatString #BinaryExploitation


A simple Format String exploit example - bin 0x11 by LiveOverflow
/youtube/video/0WvrSfcdq1I
print a stack value as a pointer
/youtube/video/XuzuFUGuQv0?t=109.49
find the offset of the stick to our input
/youtube/video/XuzuFUGuQv0?t=138.14
recognize the leak values
/youtube/video/XuzuFUGuQv0?t=200.75
move the address at the back of the string
/youtube/video/XuzuFUGuQv0?t=275.39001
print the address for 0 0 0 from the stack
/youtube/video/XuzuFUGuQv0?t=309.17001
open the dump with a disassembler
/youtube/video/XuzuFUGuQv0?t=449.979
convert the raw byte string to a proper number
/youtube/video/XuzuFUGuQv0?t=478.77899
calculate the ellipse e-base address from the leaked addresses
/youtube/video/XuzuFUGuQv0?t=562.71002
LiveOverflow just a wannabe hacker... making videos about various IT security topics and participating in hacking competitions. -=[ ā¤ļø Support me ]=- Patreon per Video: https://www.patreon.com/join/liveoverflow YouTube Membership per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join -=[ šŸ“„ Imprint ]=- Security Flag GmbH Celsiusstr. 72 12207 Berlin Germany
/youtube/channel/UClcE-kVhqyiHCcjYwcpfj9w
Iā€™m moving, no videos sorry 17,544 views
/youtube/video/9CS3q0uG1LI
CTF video write-ups by LiveOverflow
/youtube/video/MpeaSNERwQA