> For the complete documentation index, see [llms.txt](https://hyggehalcyon.gitbook.io/page/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hyggehalcyon.gitbook.io/page/ctfs/2023/tjctf/flip-out.md).

# flip out

simple reading from unchecked index

## Problem

<details>

<summary>Description</summary>

My friend made this app with a flag in it...

`nc tjc.tf 31601`

</details>

## Solution

the program is simple, saves the flag into a variable within the program then it ask us for an input and converts it into an integer. It then going to output somewhat index the buffer we given. Since there's no check to that index we can provide an index beyond that buffer's size/location/

<figure><img src="https://2174594300-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7LPLfgV3mKZQiLeCJCXU%2Fuploads%2FOHJuC6JvyKjwKHnFS7rH%2Fimage_2023-05-28_205042107.png?alt=media&amp;token=b700f7ba-f27a-4e24-87a0-5f2207cef503" alt=""><figcaption><p>Segment of Main Decompiled</p></figcaption></figure>

Here we can see the variables allignment. The flag is located down at the 16th element. Since this is a 64 bit ELF we can calculate that the index we should give in order the program to outputs the `flag_file` is 16 \* 8 = 128

<figure><img src="https://2174594300-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7LPLfgV3mKZQiLeCJCXU%2Fuploads%2FFwVp8Vfg7ln8Vl3m5Qfl%2Fimage_2023-05-28_204918488.png?alt=media&amp;token=5bdeadcb-2bd6-4c6f-a016-4fc0a933fc2c" alt=""><figcaption><p>Main stack alignment</p></figcaption></figure>

{% code title="exploit.py" lineNumbers="true" fullWidth="false" %}

```python
#!usr/bin/python3
from pwn import *

io = remote("tjc.tf", 31601)

io.sendlineafter(b'Input: ', b'128')
io.interactive()
```

{% endcode %}

## Flag

> ***tjctf{chop-c4st-7bndbji}***
