Uploaded March 2020 | Updated September 2026, 2 weeks ago
This video solves part 1 of the CSCG 2020 intro_pwn challenge by combining a format-string information leak with a stack buffer overflow. After following the mind map and Docker workflow, try parts 2 and 3 yourself!
2020 participation links (historical):
International players: earth.2020.cscg.de
CSCG 2020 (german): cscg.de/cscg/teilnehmen
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-format-string/yt-modern-format-vuln
Join the Hextree Discord: discord.gg/xgQpCQCpvy
Introduction to docker workflow: youtube.com/watch?v=cPGZMt4cJ0I
Basic pwnable challenge: youtube.com/watch?v=OqTpc_ljPYk
Some more resources: github.com/LiveOverflow/pwn_docker_example
intro_pwn/pwn1: earth.2020.cscg.de/tasks/Intro%20to%20Pwning%201
CHAPTERS
00:00 - The intro_pwn challenge series and goal
00:57 - Starting the challenge with Docker Compose
02:23 - Inspecting mitigations and source code
03:41 - Mind mapping the buffer overflow and PIE problem
05:01 - Exploring the format-string leak
07:31 - Combining the information leak and overflow
08:17 - Building the local pwntools exploit
10:23 - Finding a binary address with GDB and vmmap
11:55 - Calculating the randomized WIN function address
12:39 - Finding the overflow offset and password constraint
14:27 - Building the return payload and aligning the stack
15:55 - Running the exploit against the challenge server
16:28 - Continuing with parts 2 and 3
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#BinaryExploitation #CSCG #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
This video solves part 1 of the CSCG 2020 intro_pwn challenge by combining a format-string information leak with a stack buffer overflow. After following the mind map and Docker workflow, try parts 2 and 3 yourself!
2020 participation links (historical):
International players: earth.2020.cscg.de
CSCG 2020 (german): cscg.de/cscg/teilnehmen
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-format-string/yt-modern-format-vuln
Join the Hextree Discord: discord.gg/xgQpCQCpvy
Introduction to docker workflow: youtube.com/watch?v=cPGZMt4cJ0I
Basic pwnable challenge: youtube.com/watch?v=OqTpc_ljPYk
Some more resources: github.com/LiveOverflow/pwn_docker_example
intro_pwn/pwn1: earth.2020.cscg.de/tasks/Intro%20to%20Pwning%201
CHAPTERS
00:00 - The intro_pwn challenge series and goal
00:57 - Starting the challenge with Docker Compose
02:23 - Inspecting mitigations and source code
03:41 - Mind mapping the buffer overflow and PIE problem
05:01 - Exploring the format-string leak
07:31 - Combining the information leak and overflow
08:17 - Building the local pwntools exploit
10:23 - Finding a binary address with GDB and vmmap
11:55 - Calculating the randomized WIN function address
12:39 - Finding the overflow offset and password constraint
14:27 - Building the return payload and aligning the stack
15:55 - Running the exploit against the challenge server
16:28 - Continuing with parts 2 and 3
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#BinaryExploitation #CSCG #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.










