Skip to content

Guides tagged: #arbitrary-write

0x7000 · Exploitation Techniques

File-Structure Attacks: Hijacking a FILE Object

When hooks are gone, the FILE object is the target. A stdio call dispatches through a vtable pointer in writable memory — corrupt it and the next fwrite runs your code.

0x7000 · Exploitation Techniques

Format-String Bugs: Arbitrary Read and Write

One printf(user_input) is a full read/write primitive. Leak with %p, overwrite with %n via pwntools, then watch -Wformat=2 and FORTIFY_SOURCE shut it down.

0x7000 · Exploitation Techniques

Hijacking the GOT: Redirecting a libc Call

Lazy binding leaves the Global Offset Table writable. Aim an arbitrary write at a GOT entry, turn puts() into system(), then enable Full RELRO and watch the same write fault instantly.