Premium Only Content

9: Overwriting Global Offset Table (GOT) Entries with printf() - Intro to Binary Exploitation (Pwn)
9th video from the "Practical Buffer Overflow Exploitation" course covering the basics of Binary Exploitation. NX and stack canaries are enabled this time, so we'll use a printf() format string vulnerability overwrite an entry from the Global Offset Table (GOT) with system() function from the Lib-C library. We'll use checksec, ghidra, pwndbg and create a manual printf() format write payload as well as using the pwntools FmtStr functionality! Write-ups/tutorials aimed at beginners - Hope you enjoy 🙂 #BinaryExploitation #BufferOverflow #BinExp #RE #Pwn #PwnTools
Find the binary files, source code and scripts to go with the series @ https://github.com/Crypto-Cat/CTF/tree/main/pwn/binary_exploitation_101
↢Social Media↣
Twitter: https://twitter.com/_CryptoCat
GitHub: https://github.com/Crypto-Cat
HackTheBox: https://app.hackthebox.eu/profile/11897
LinkedIn: https://www.linkedin.com/in/cryptocat
Reddit: https://www.reddit.com/user/_CryptoCat23
YouTube: https://www.youtube.com/CryptoCat23
Twitch: https://www.twitch.tv/cryptocat23
↢Binary Exploitation / Reverse Engineering↣
Pwn.College: https://pwn.college
How2Heap: https://github.com/shellphish/how2heap
NightMare: https://guyinatuxedo.github.io
Ir0nstone: https://ir0nstone.gitbook.io/notes/types/stack
PinkDraconian: https://www.youtube.com/playlist?list=PLeSXUd883dhjmKkVXSRgI1nJEZUDzgLf_
More: https://github.com/Crypto-Cat/CTF#readme
↢Video-Specific Resources↣
https://systemoverlord.com/2017/03/19/got-and-plt-for-pwning.html
https://ir0nstone.gitbook.io/notes/types/stack/aslr/plt_and_got
https://vickieli.dev/binary%20exploitation/format-string-vulnerabilities
https://codearcana.com/posts/2013/05/02/introduction-to-format-string-exploits.html
https://axcheron.github.io/exploit-101-format-strings
https://docs.pwntools.com/en/stable/fmtstr.html
↢Resources↣
Ghidra: https://ghidra-sre.org/CheatSheet.html
PwnTools: https://github.com/Gallopsled/pwntools-tutorial
CyberChef: https://gchq.github.io/CyberChef
HackTricks: https://book.hacktricks.xyz/exploiting/linux-exploiting-basic-esp
GTFOBins: https://gtfobins.github.io
Decompile Code: https://www.decompiler.com
Run Code: https://tio.run
↢Chapters↣
Start: 0:00
Basic File Checks: 0:32
Review Source Code: 2:10
Disassemble with Ghidra: 3:15
Outline Attack (GOT Overwrite): 4:60
GOT vs PLT vs GOT.PLT vs PLT.GOT: 6:07
Fuzz Printf Format Vuln: 8:55
Printf Format Write (%n) Explained: 9:36
Finding Correct Offset for Write: 13:00
How to Build a Manual Payload: 13:55
Manual Printf Write Exploit (%n): 18:08
PwnTools Script (FmtStr Auto): 22:07
End: 26:25
-
2:32:48
Tundra Tactical
6 hours ago $8.08 earnedSilencers, Senators, and Survival: Roasting Lies and a Security Breakdown of The MN Shooting
49.8K6 -
LIVE
Spartan
10 hours agoPro Halo Player | !politics Halo Infinite Ranked Arena into SWTOR and/or Gears Beta
310 watching -
40:25
The Connect: With Johnny Mitchell
1 day ago $8.78 earnedBlackwater CEO Erik Prince Gets HONEST About The Israeli Invasion Of Lebanon
42.9K46 -
2:14:37
BlackDiamondGunsandGear
7 hours agoAfter Hours Armory / Is the World ENDING?
64.4K3 -
4:21:28
cosmicvandenim
9 hours ago[NEW] FIVE NIGHTS AT FREDDY'S - SECRET OF THE MIMIC - Horror Game
78.1K1 -
2:14:37
DLDAfterDark
7 hours ago $1.30 earnedThe After Hours Armory - WWIII - The World Is Melting - Feat. Gideon Optics
38.8K3 -
5:52:04
Right Side Broadcasting Network
5 days agoLIVE REPLAY: President Trump Honors U.S. Army's 250th Anniversary With a Grand Military Parade - 6/14/25
452K227 -
5:10:52
Barry Cunningham
14 hours agoWATCH LIVE: PRESIDENT TRUMP SALUTES AMERICA'S MILITARY WITH HUGE PARADE!
108K88 -
3:11:13
The White House
18 hours agoPresident Trump Participates in the 250th Anniversary of the U.S. Army Grand Military Parade
95.3K110 -
4:39:37
MoFio23!
17 hours agoNintendo Switch It UP Saturdays with The Fellas: LIVE - Episode #23 [Mario Golf: Super Rush]
31.3K1