<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>d4ytox</title><description>Binary exploitation, vulnerability research and CTF writeups.</description><link>https://d4ytox.com/</link><language>en</language><lastBuildDate>Sun, 23 Aug 2026 00:00:00 GMT</lastBuildDate><item><title>aptitude-test</title><link>https://d4ytox.com/writeups/ctf/brunnerctf-2026/aptitude-test/</link><guid isPermaLink="true">https://d4ytox.com/writeups/ctf/brunnerctf-2026/aptitude-test/</guid><description>Reversing the score file cipher, working out the plaintext layout and spawn generation, then using the submission server itself as an oracle to land a score over 9000 without tripping the anti-cheat.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>cipher</category><category>oracle</category><category>anti-cheat</category><category>windows</category></item><item><title>brunner-stocks</title><link>https://d4ytox.com/writeups/ctf/brunnerctf-2026/brunner-stocks/</link><guid isPermaLink="true">https://d4ytox.com/writeups/ctf/brunnerctf-2026/brunner-stocks/</guid><description>The stack is executable and a gadget has been left in place, so the overflow in askf turns straight into shellcode execution rather than needing a ROP chain.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>shellcode</category><category>stack-execution</category><category>buffer-overflow</category></item><item><title>guessing-game</title><link>https://d4ytox.com/writeups/ctf/brunnerctf-2026/guessing-game/</link><guid isPermaLink="true">https://d4ytox.com/writeups/ctf/brunnerctf-2026/guessing-game/</guid><description>An unbounded OOB read leaks through a popcount side channel, and a saved-RBP overwrite gives a stack pivot. Combining them the obvious way dead-ends; the way out is to aim the pivot back into the program&apos;s own loop rather than at a one_gadget.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>stack-pivot</category><category>oob-read</category><category>side-channel</category><category>got-overwrite</category><category>glibc</category></item><item><title>locked-out</title><link>https://d4ytox.com/writeups/ctf/brunnerctf-2026/locked-out/</link><guid isPermaLink="true">https://d4ytox.com/writeups/ctf/brunnerctf-2026/locked-out/</guid><description>A format string at %9$p leaks the stack canary, and a limited attempt budget forces a single-byte partial overwrite rather than a full return address rewrite.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>format-string</category><category>canary-leak</category><category>partial-overwrite</category></item><item><title>mindbreaker</title><link>https://d4ytox.com/writeups/ctf/brunnerctf-2026/mindbreaker/</link><guid isPermaLink="true">https://d4ytox.com/writeups/ctf/brunnerctf-2026/mindbreaker/</guid><description>Pwning LEGO MINDSTORMS EV3 firmware under qemu-arm in a chroot. opSYSTEM is compiled into the lms2012 VM, the flag is mode 000, and the output channel is a 178x128 screen.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>embedded</category><category>arm</category><category>lego-ev3</category><category>sandbox-escape</category><category>firmware</category></item><item><title>pure-notes</title><link>https://d4ytox.com/writeups/ctf/brunnerctf-2026/pure-notes/</link><guid isPermaLink="true">https://d4ytox.com/writeups/ctf/brunnerctf-2026/pure-notes/</guid><description>A Haskell notes program with a use-after-free: delete frees the buffer but keeps the record. Defeating tcache safe-linking and the double-free check turns that into a read of the flag pointer left on the banner.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>heap</category><category>tcache</category><category>safe-linking</category><category>use-after-free</category><category>haskell</category></item><item><title>The Three Ways</title><link>https://d4ytox.com/writeups/ctf/brunnerctf-2026/three-ways/</link><guid isPermaLink="true">https://d4ytox.com/writeups/ctf/brunnerctf-2026/three-ways/</guid><description>A three-stage supply chain compromise. A fork PR reaches Drone&apos;s exec runner, CI secrets fall out of the build log past a redaction filter, and the last flag sits in a superseded package version that the registry still serves.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>supply-chain</category><category>ci-cd</category><category>gitea</category><category>drone</category><category>secrets</category></item><item><title>wordpressed-to-root</title><link>https://d4ytox.com/writeups/ctf/brunnerctf-2026/wordpressed-to-root/</link><guid isPermaLink="true">https://d4ytox.com/writeups/ctf/brunnerctf-2026/wordpressed-to-root/</guid><description>Two CVEs, one root. An unauthenticated chain gets www-data, then CVE-2025-32463 (\&quot;chwoot\&quot;) takes it to uid=0. Neither bug is in the custom theme, which is where the challenge wants you to look.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>wordpress</category><category>cve</category><category>rce</category><category>privesc</category><category>sudo</category></item></channel></rss>