Zigzag Medium 5.0 (1) Challenge Rating XP r...
Tạo vào: 24 tháng 7, 2026
Trả lời bằng GPT-5.6 Thinking bởi Chat01
Tạo vào: 24 tháng 7, 2026
Trả lời bằng GPT-5.6 Thinking bởi Chat01
Zigzag
Medium
5.0 (1)
Challenge Rating
XP reward
text390 XP reward
Difficulty distribution bar chart Piece of Cake Very Easy Easy Not Too Easy Medium A Bit Hard Hard Too Hard Extremely Hard Brainfuck!
Votes 1 0 1 0 9 1 0 0 0 0
User-Rated Difficulty
Target Host 154.57.164.81:30191
Challenge Scenario
VAULTRIX runs the quiet backend for people who need something to vanish — blackmail files, insider ledgers, kill lists rebranded as "enterprise notes." Tonight one of those notes goes to auction, and your handler wants it gone before the bidding closes. Their pitch deck brags — "We rewrote our entire backend in Zig. No garbage collector. No hidden allocations. No glibc heap exploits from 2015. Memory safety isn't a feature — it's the foundation." — but you've got a leaked socket, a countdown, and a hunch that "memory safe" doesn't mean "exploit safe."
154.57.164.81:30191
Solved. The exploit is locally verified and produces a root shell.
Each note uses:
textdata pointer | size | render callback
GET and PATCH incorrectly validate access against the note object’s address rather than its allocated data length. With two adjacent 32-byte notes, this enables:
GET 0 48.RENDER 1 to the hidden routine at offset 0x6b820, which executes /bin/sh.Relevant offsets:
textNormal render callback: 0x14f30 Hidden execve("/bin/sh"): 0x6b820
Run it against the challenge:
bashpython3 solve_zigzag.py
Or test locally:
bashpython3 solve_zigzag.py --local ./zigzag --command 'echo PWNED; id'
Verified local result:
textPWNED uid=0(root) gid=0(root) groups=0(root)
The supplied endpoint 154.57.164.81:30191 currently returns Connection refused, so I could not retrieve the remote flag. Restarting the challenge instance and rerunning the script should execute the included flag-search command automatically.