> For the complete documentation index, see [llms.txt](https://ad3n.gitbook.io/ad3n/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ad3n.gitbook.io/ad3n/home/ctf-writeups/curtin-malaysia-ctf-2023/pwn-and-reverse.md).

# Pwn & Reverse

* ## Intro to Buffer Overflow

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2F3GS1cmSQLiUNhDiW4Aij%2Fimage.png?alt=media&amp;token=c483ae51-2be9-4de7-88bf-f6ae1c43ffeb" alt="" width="377"><figcaption></figcaption></figure>

Just overflow the buffer with `1` and got the flag!

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FQGyKtnNZhCNteWihiZIp%2Fimage.png?alt=media&amp;token=8d8d5cb4-a19f-4b65-a7d7-2611692694a0" alt="" width="548"><figcaption></figcaption></figure>

Flag: `CURTIN_CTF{Y0UR_F1R5T_0V3RFL0W}`

***

* ## Let The Random Games Begin 1

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FoWQg1iGmu8pDqHauprT6%2Fimage.png?alt=media&amp;token=cd198573-d5b5-488d-8fc8-e2ae1368d8be" alt="" width="353"><figcaption></figcaption></figure>

After a few run on the given program, I see that the program not generate random numbers as the challenge mention and from that it can be easily predict what the next numbers is, and got the flag.

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2Fqna4TxlnrRT8h4XZktMd%2Fimage.png?alt=media&amp;token=b3f9a57c-4a2b-43c3-8eba-4399d5b61605" alt="" width="368"><figcaption></figcaption></figure>

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FVKdWMzaDh9gi1RojbEbu%2Fimage.png?alt=media&amp;token=232a21d9-48de-411a-902d-7ac00ef2cfc6" alt="" width="323"><figcaption></figcaption></figure>

Flag: `CURTIN_CTF{N0_S33D_N0_R4ND0M}`

***

* ## Don't  go overboard

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2Fg8ywz3dHkTp9k4LeFKR6%2Fimage.png?alt=media&amp;token=c002efca-bf1e-424a-92ab-3904bedfd02b" alt="" width="326"><figcaption></figcaption></figure>

Open the file in ghidra to know how the program run, which we need to change the value of `showflag` and `secured` to be able to get the flag. For this challenge, proper way to do it is using `gdb-gef` to find the exact offset of the buffer.

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FMvpGmgUXx3p9nXgiUocB%2Fimage.png?alt=media&amp;token=e3222cac-9c1c-4a50-93db-c027d36d3c94" alt="" width="482"><figcaption></figcaption></figure>

But since I'm not master using `gdb-gef`, the best way is to try and error to find the exact offset of the buffer and when found the offset then I can change the value of `showflag` and `secured` to get the flag.

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FPWvxmMqRtgKWM1Yx9VdP%2Fimage.png?alt=media&amp;token=0d208431-d58b-4e0f-a7c3-a84d8e97f3b1" alt="" width="408"><figcaption></figcaption></figure>

Flag: `CURTIN_CTF{T@RG3TT3D_0V3RF10W}`

***

* ## Let The Random Games Begin 2

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FFvlqX8bf7EgTPCeA1Oya%2Fimage.png?alt=media&amp;token=b1088326-35f8-4087-8f3f-6ee885d94040" alt="" width="309"><figcaption></figcaption></figure>

This challenge is same as the previous challenge, but this time the program has many set of random numbers generate and it will repeat the number again.

<div align="center"><figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FjjtngBhBIeJFibOD7qPQ%2Fimage.png?alt=media&amp;token=e9013067-bd9e-4fe1-996b-0dd99bc5c046" alt="" width="238"><figcaption></figcaption></figure> <figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FXtJtZ2EZM4CP8sqPRiOV%2Fimage.png?alt=media&amp;token=f83d3afa-b17a-4ec3-b7bd-55b0d2e78b91" alt="" width="231"><figcaption></figcaption></figure></div>

From list of set numbers of genarated number, I can predict next number and obtain the flag.

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FSQka7Nyu4hlETNPbICPP%2Fimage.png?alt=media&amp;token=55a45ff4-c424-4bc2-b463-1acecf8415b8" alt="" width="554"><figcaption></figcaption></figure>

Flag: `CURTIN_CTF{7H3_F1RS7_P53UD0}`
