<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Userland on kiperZ</title>
    <link>https://kiperz.dev/userland/</link>
    <description>Recent content in Userland on kiperZ</description>
    <generator>Hugo -- 0.147.7</generator>
    <language>en</language>
    <lastBuildDate>Fri, 27 Feb 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://kiperz.dev/userland/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Editeur de configuration - FCSC 2025</title>
      <link>https://kiperz.dev/userland/editeur-de-configuration/</link>
      <pubDate>Fri, 27 Feb 2026 00:00:00 +0000</pubDate>
      <guid>https://kiperz.dev/userland/editeur-de-configuration/</guid>
      <description>&lt;h1 id=&#34;tldr&#34;&gt;TL;DR&lt;/h1&gt;
&lt;p&gt;An off-by-null (House of Einherjar) lets us consolidate heap chunks. From there, tcache poisoning gives control over &lt;code&gt;pthread_tcache_struct&lt;/code&gt;, which redirects an allocation onto the stack for a ROP chain and a shell.&lt;/p&gt;
&lt;h2 id=&#34;overview&#34;&gt;Overview&lt;/h2&gt;
&lt;p&gt;The challenge provides an x86-64 ELF binary: a player configuration editor.
The program allows importing a configuration in a simplified INI format, then editing it through an interactive menu.&lt;/p&gt;
&lt;p&gt;The binary runs on &lt;strong&gt;Ubuntu 22.04&lt;/strong&gt; with &lt;strong&gt;glibc 2.35&lt;/strong&gt; (no &lt;code&gt;__malloc_hook&lt;/code&gt; / &lt;code&gt;__free_hook&lt;/code&gt;, removed since 2.34).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Solaris - 404CTF 2025</title>
      <link>https://kiperz.dev/userland/solaris/</link>
      <pubDate>Tue, 28 Oct 2025 00:00:00 +0000</pubDate>
      <guid>https://kiperz.dev/userland/solaris/</guid>
      <description>&lt;h2 id=&#34;tldr&#34;&gt;TL;DR&lt;/h2&gt;
&lt;p&gt;Null off-by-one bug in heap management → LSB pointer corruption → leak heap (safe linking) → tcache poisoning to unsorted bin → leak libc → tcache poisoning to stdout → leak stack → tcache poisoning to stack → ROP chain with stack pivot → open/read/write flag with seccomp bypass&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Challenge Files:&lt;/strong&gt; &lt;code&gt;chall&lt;/code&gt; (ELF binary), &lt;code&gt;libc.so.6&lt;/code&gt;, &lt;code&gt;chall.c&lt;/code&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This is one of my early CTF writeups! If you spot improvements, feel free to share!&lt;/p&gt;</description>
    </item>
    <item>
      <title>22 Bytes Pour Sauver L&#39;univers - 404CTF 2025</title>
      <link>https://kiperz.dev/userland/22-bytes-pour-sauver-l-univers/</link>
      <pubDate>Mon, 27 Oct 2025 00:00:00 +0000</pubDate>
      <guid>https://kiperz.dev/userland/22-bytes-pour-sauver-l-univers/</guid>
      <description>&lt;h2 id=&#34;tldr&#34;&gt;TL;DR&lt;/h2&gt;
&lt;p&gt;Buffer overflow + limited gadgets = SROP time! Leak addresses → chain two Sigreturn-Oriented Programming attacks → first SROP calls &lt;code&gt;read()&lt;/code&gt;, second calls &lt;code&gt;execve(&amp;quot;/bin/sh&amp;quot;)&lt;/code&gt; → shell!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Challenge Files:&lt;/strong&gt; &lt;code&gt;chall&lt;/code&gt; (ELF binary)&lt;/p&gt;
&lt;hr&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; There might be simpler approaches, but this SROP method worked great. If you spot improvements, feel free to share.&lt;/p&gt;&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id=&#34;challenge-overview&#34;&gt;Challenge Overview&lt;/h2&gt;
&lt;p&gt;We&amp;rsquo;re given a 64-bit ELF binary that implements custom syscall wrappers and has a juicy buffer overflow vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Book Writer - FCSC 2024</title>
      <link>https://kiperz.dev/userland/book-writer/</link>
      <pubDate>Sun, 26 Oct 2025 00:00:00 +0000</pubDate>
      <guid>https://kiperz.dev/userland/book-writer/</guid>
      <description>&lt;h2 id=&#34;tldr&#34;&gt;TL;DR&lt;/h2&gt;
&lt;p&gt;Integer overflow (&lt;code&gt;n * 128&lt;/code&gt; wraps to 0) → get 0x20 chunk → leak PIE from adjacent heap → overflow into next Book struct → overwrite function pointer to printf → format string leak libc → ROP chain to system(&amp;quot;/bin/sh&amp;quot;)&lt;/p&gt;
&lt;hr&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This is one of my first CTF writeups! Went through several failed attempts before finding the right path.&lt;/p&gt;&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id=&#34;challenge-overview&#34;&gt;Challenge Overview&lt;/h2&gt;
&lt;p&gt;Book management application with create/read/write/page turning functions. Heap-based exploitation.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Kerberint Space Program - 404CTF 2025</title>
      <link>https://kiperz.dev/userland/kerberint-space-program/</link>
      <pubDate>Sun, 01 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://kiperz.dev/userland/kerberint-space-program/</guid>
      <description>&lt;h2 id=&#34;tldr&#34;&gt;TL;DR&lt;/h2&gt;
&lt;p&gt;Off-by-two bug lets us corrupt a pointer byte-by-byte → leak libc addresses → overwrite GOT entries → redirect &lt;code&gt;free()&lt;/code&gt; to &lt;code&gt;system()&lt;/code&gt; → profit with &lt;code&gt;system(&amp;quot;/bin/sh&amp;quot;)&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Challenge Files:&lt;/strong&gt; &lt;code&gt;chall&lt;/code&gt; (ELF binary), &lt;code&gt;libc.so.6&lt;/code&gt;, &lt;code&gt;ld-linux-x86-64.so.2&lt;/code&gt;, &lt;code&gt;main.c&lt;/code&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This is my first CTF writeup! At the time I solved this challenge, I was just starting out with heap exploitation. There are probably cleaner/simpler ways to solve this, but this approach worked for me. If you spot improvements, feel free to share!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Spaaaaaaace - 404CTF 2025</title>
      <link>https://kiperz.dev/userland/spaaaaaaace/</link>
      <pubDate>Sun, 01 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://kiperz.dev/userland/spaaaaaaace/</guid>
      <description>&lt;h2 id=&#34;tldr&#34;&gt;TL;DR&lt;/h2&gt;
&lt;p&gt;RWX memory + 13-byte size limit = staged shellcode time! Upload a tiny loader (13 bytes) that reads a bigger shellcode (24 bytes), then execute it to get shell.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Challenge Files:&lt;/strong&gt; &lt;code&gt;chall&lt;/code&gt; (ELF binary)&lt;/p&gt;
&lt;hr&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This is one of my first CTF writeups! At the time I solved this challenge, I was just starting out with pwn. There are probably cleaner/simpler ways to solve this, but this approach worked for me. If you spot improvements, feel free to share!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Long Prime Shellcode - FCSC 2025</title>
      <link>https://kiperz.dev/userland/long-prime-shellcode/</link>
      <pubDate>Tue, 29 Apr 2025 00:00:00 +0000</pubDate>
      <guid>https://kiperz.dev/userland/long-prime-shellcode/</guid>
      <description>&lt;h2 id=&#34;tldr&#34;&gt;TL;DR&lt;/h2&gt;
&lt;p&gt;Program reads a decimal number, checks if it&amp;rsquo;s a 1024+ bit prime, converts it to binary, and executes it as code. The trick? Craft a prime number that&amp;rsquo;s actually valid x86-64 shellcode! →&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Challenge Files:&lt;/strong&gt; &lt;code&gt;long-prime-shellcode&lt;/code&gt; (ELF binary)&lt;/p&gt;
&lt;hr&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This is one of my first CTF writeups! If you spot improvements, feel free to share!&lt;/p&gt;&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id=&#34;challenge-overview&#34;&gt;Challenge Overview&lt;/h2&gt;
&lt;p&gt;We&amp;rsquo;re given a binary that asks for a decimal number and does something&amp;hellip; unusual with it:&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
