HTB - Scanner (Challenge)
by x1rx - Friday September 6, 2024 at 02:29 AM
#1
Let's discuss the pwn challenge
Reply
#2
(09-06-2024, 02:29 AM)x1rx Wrote: Let's discuss the pwn challenge

I haven't completed the exploit part, but this should lead you; Leak heap → leak libc → off-by-one overwrite → brute-force stack alignment → return to libc → get the flag.
Reply
#3
[Image: dwM3f8B.png]
[Image: htb_scanner_98_bf_all.jpg]

These hints should be enough to show you the path finishing the exploit part. Enjoy
Reply
#4
(09-07-2024, 03:28 AM)Axura Wrote: [Image: dwM3f8B.png]
[Image: htb_scanner_98_bf_all.jpg]

These hints should be enough to show you the path finishing the exploit part. Enjoy

My instance always gets fcked up! lol Smile
Reply
#5
1 - heap leak
2 - libc leak
3 - rbp leak
4 - stack pivot --> new rbp with off by null
5 - rop chain
6 - hijack execution flow


All steps are done and I got the flag(while loop) but my script is unstable . When I use off by null and pivoting on stack , process crashes .

What am I missing? any hint
Reply
#6
exp.py
Hidden Content
You must register or login to view this content.
Reply
#7
this is a good initiative will like to see this 
will appreciate if got it free
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 368 115,634 Yesterday, 09:29 AM
Last Post: jokowi69
  HTB Academy - Active Directory Penetration Tester Path 2024 loganpaul09 19 11,018 09-01-2026, 06:25 AM
Last Post: adolfoL
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 95 27,892 08-31-2026, 03:15 PM
Last Post: Marlb0r0Man
  HTB Eloquia User and Root Flags - Insane Box 69646B 14 19,054 08-21-2026, 07:27 PM
Last Post: tangol
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 25 20,959 08-15-2026, 06:06 PM
Last Post: m4573rx



 Users browsing this thread: 1 Guest(s)