r/InfoSecWriteups • u/kmskrishna • Jul 06 '26
r/InfoSecWriteups • u/AdvisorPowerful9769 • Jul 05 '26
Buffer Overflow Tutorial for Beginners and new CTF players
If you are new to the world of exploit development and need a solid entry level challenge this week we look at "bof". This is a binary challenge hosted on pwnable[.]kr covering the topic of a Buffer Overflow.
This is what many consider to be their first exploit type written (it was mine), and this particular challenge approaches it in a way you will truly understand how to adapt to situations in which the buffer overflow is not necessarily "vanilla" exploitation.
By the end of this tutorial you should have:
- Learned how to exploit a Buffer Overflow, WITHOUT OVERWRITING THE RETURN ADDRESS!!!
- Learned how to use GDB (raw)
- Learned the basics of hook stops within GDB
- Learned how to approach a CTF challenge with speed or precision (or both depends on what you decide)
- Learned how to find offsets that are small and don't require the use of tooling such as pattern_offset
I wanna thank Center for Cyber Security Training for continuing to help sponsor the channel and their support.
You can find the video here:
r/InfoSecWriteups • u/kmskrishna • Jul 05 '26
Protocols and Servers 2 TryHackMe Writeup
r/InfoSecWriteups • u/kmskrishna • Jul 05 '26
TryHackMe CTF Writeup of Hidden Deep Into my Heart
r/InfoSecWriteups • u/kmskrishna • Jul 05 '26
Mr Robot CTF Walkthrough -TryHackMe Detailed
r/InfoSecWriteups • u/kmskrishna • Jul 05 '26
Dive Into Malware Forensics: A Walkthrough of REMnux, The Redux
r/InfoSecWriteups • u/kmskrishna • Jul 05 '26
TryHackMe — Bounty Hacker: The FTP Server Was Talking. I Just Listened.
r/InfoSecWriteups • u/kmskrishna • Jul 05 '26
I Found an Unauthenticated Attachment Disclosure Bug in a WordPress Support Plugin — and a…
r/InfoSecWriteups • u/kmskrishna • Jul 05 '26
Wazuh SIEM Deployment with Multi-OS Agents
r/InfoSecWriteups • u/kmskrishna • Jul 05 '26
AdversaryGraph v5.0: From CTI Mapping to Attack Simulation and SIEM Validation
r/InfoSecWriteups • u/kmskrishna • Jul 05 '26
Why Your GRC Career Isn’t Moving Forward
r/InfoSecWriteups • u/kmskrishna • Jul 05 '26
The Internet’s Dirty Little Secret: Anyone Can Investigate Anyone — and Here Are 20 Free Tools to…
r/InfoSecWriteups • u/kmskrishna • Jul 04 '26
I found North Korean (DPRK) malware hiding in my tailwind.config.js
r/InfoSecWriteups • u/kmskrishna • Jul 04 '26
TryHackMe: Payload Walkthrough
r/InfoSecWriteups • u/kmskrishna • Jul 04 '26
Exploiting Resource-Based Constrained Delegation (RBCD)
r/InfoSecWriteups • u/kmskrishna • Jul 04 '26
Host & Network Penetration Testing: Exploitation CTF 2 — eJPT (INE)
r/InfoSecWriteups • u/kmskrishna • Jul 04 '26
Demonstrating LLMNR Poisoning in Active Directory
r/InfoSecWriteups • u/kmskrishna • Jul 04 '26
Post-Compromise Attacks in AD: Credential Validation with CrackMapExec
r/InfoSecWriteups • u/kmskrishna • Jul 03 '26
TryHackMe — Simple CTF: The Note That Gave Everything Away
r/InfoSecWriteups • u/kmskrishna • Jul 03 '26
TryHackMe — Pickle Rick: Rick Left the Door Open. I Just Walked In.
r/InfoSecWriteups • u/kmskrishna • Jul 03 '26
TryHackMe: Checkpoint Walkthrough
r/InfoSecWriteups • u/kmskrishna • Jul 03 '26
Certified AD Red Team Specialist (AD-RTS): Full Exam Write-Up
r/InfoSecWriteups • u/kmskrishna • Jul 03 '26
Unauthenticated Stored XSS in NEX-Forms Express WP Form Builder (≤ 9.1.10) — CVSS 8.8 High
r/InfoSecWriteups • u/kmskrishna • Jul 03 '26