Midnight Flag CTF 2026
2026
heapn⊕te-ic
Signed-length bug on glibc 2.39 turns into a heap primitive. Safe-linking leak, unsorted-bin libc leak, tcache poisoning through an XOR cipher, and a forged exit handler chain.
#heap #glibc-2.39 #tcache #safe-linking
hard Canvas of Fear
Stored XSS → localhost admin → heap underflow in a native canvas manager → libc leak → arbitrary R/W → libc ROP → flag. A full web-to-pwn chain.
#xss #heap #glibc-2.34 #ROP
hard