Ahmad Mahfouz

Random notes

Category: tech

SMASH THE STACK LEVEL2

time to play

let’s read what it says

first function catcher  and it trigger the suid  and drop the bash nice  this is what we want

SMASH THE STACK Level1

after login to the ssh server levels located on /levels so let’s play  level1

as u notice it had suid permeation  -r-sr-x— for level2  so it will lead us to a user (level2 )

I entered any test number and it leads me with no respond 😀 crazy huh! so I decided to look