Master the fundamental concepts of binary exploitation through this focused micro-challenge.
Three hints are available for this task, revealed one at a time inside the code workspace so you can struggle productively before seeing them.
Every task includes starter code, theory, and hidden tests so you can implement and verify locally in the browser.
How it worksBy overflowing a buffer on the stack, an attacker can overwrite the saved return address of the current function. When the function returns, the CPU pops this corrupted address into RIP, diverting execution to an attacker-chosen location.
The key step is finding the exact byte offset from the buffer start to the return address:
char buf[16] gives offset = 16 + 8 = 24 bytes to the return addressTools like pwntools' cyclic() and GDB's pattern_create automate finding this offset by generating unique byte sequences.
You will build the exploit payload arithmetic itself: given a frame layout and a target address, compute the byte offset to the return address, the total payload size, and the little-endian byte sequence that the target address becomes in memory. This is the exact computation every exploit generator performs before shipping a payload.
After finding the offset, you place a target address at exactly that byte position. In a real exploit, the address might point to shellcode (pre-NX), a ROP gadget (post-NX), or a win() function in a CTF binary. GDB's x/20gx $rsp shows the stack layout live, confirming your offset calculation before you build the final payload with a tool like pwntools. Addresses stored little-endian means a target like 0x401126 appears in the payload as the byte sequence 26 11 40 00 00 00 00 00, and any 00 bytes in that sequence will truncate a strcpy()-based delivery.
Write a C program that reads three values from stdin (the local buffer size, the saved frame pointer size, and a target address in hex) and computes the return-address overwrite payload.
Requirements:
Success Criteria: