Master the fundamental concepts of binary exploitation through this focused micro-challenge.
You have read the whole brief, and the concepts above stay free on every task. Writing and running the code needs a plan.
Three hints are available for this task, revealed one at a time inside the code workspace so you can struggle productively before seeing them.
Every task includes starter code, theory, and hidden tests so you can implement and verify locally in the browser.
How it worksASLR randomizes the memory addresses used by process components: stack, heap, libraries, and (with PIE) the executable base. This makes it difficult for attackers to predict where to jump during an exploit.
Run the same program multiple times and observe that stack and libc addresses change each run. On 32-bit systems, entropy may be as low as 16 bits (~65536 positions), making brute force viable. On 64-bit, entropy is much higher.
Bypass techniques:
For example, leaking a libc address like 0x7f3a2b4c1000 lets you calculate system() at leaked_addr + known_offset.
You will perform the leak arithmetic itself: given a leaked libc address and the offsets of two symbols in that libc, compute the libc base and the address of the second symbol: the exact calculation that turns one leaked address into arbitrary libc code execution. You will also validate the result: a real libc base is always page-aligned, so a non-aligned result means your offsets or leak are wrong.
Once you leak printf at 0x7f1234567890, subtract the known offset from your libc version to get the libc base. Add the offset of system() to get its runtime address. The same technique works for stack addresses: leak a stack variable, calculate the distance to your shellcode or ROP chain. PIE requires leaking an address inside the executable to defeat code randomization too.
Write a C program that reads three hexadecimal values from stdin (a leaked libc function address, that symbol's offset within libc, and the offset of a second symbol) and reconstructs the libc base and the second symbol's runtime address.
Requirements:
Success Criteria: