Don't Crash

The full "Don't Crash" progression, from a single-address ret2win up to 32-bit syscalls under seccomp.

Each challenge binary lives at /challenge/<name> and is setuid root. For convenience, when a challenge starts you also get, in your home directory:

  • ~/flag.txt → a symlink to /flag (the name the binary reads from its cwd), and
  • ~/<name> → a symlink to the challenge binary.

So the intended workflow is simply, from ~:

./babybof          # or write a pwntools script that does process("./babybof")

Your cwd (~) is writable, which is where the proof file pwned is created. Run your exploits from your home directory.



Challenges

A classic stack buffer overflow.

Download handout (ELF, libc, loader, source)

This challenge is locked

This challenge is locked

This challenge is locked

This challenge is locked

This challenge is locked


30-Day Scoreboard:

This scoreboard reflects solves for challenges in this module after the module launched in this dojo.

Rank Hacker Badges Score