Buffer Overflow Exploitation

October 2026

During the weekend of October 3rd, I attended the Rowdy Hacks XII hackathon. I had a great time talking to some like-minded people and acquainting with others. In the spirit of a hackathon, I made something to present for the hackathon's theme of "Heist." I went to Rowdy Hacks XII with the preconceived notion that one would would develop a project closely related to hacking (an unconventional way of doing something). I found out that hackathons, or at the very least the one I went to, are more like "product"-athons. Sure there were some cool projects there, such as a LiDAR scanner on a helmet, but they generally were apps.

Even the tracks provided to compete within at Rowdy Hacks XII were designed to award the best solution to X problem, or the best use of Gemini API (general purpose AI), ElevenLabs (generate AI voice), Tiger Data (easy database management), Vultr (IaaS), or Solana (transaction platform). All of these tracks felt like a nudge to get students to engage with modern technologies at the cost of projects just becoming "products." Regardless of the general theme of submitted projects, my project wasn't a necessarily creative one and I never expected to win any prizes.

What it Does

This project demonstrates code that is vulnerable to buffer overrun and vulnerable to information leaks. The web server hosts the website found in the www/ folder, and the pwn.py script will exploit the vulnerabilities to open a shell to steal assets from the host of the web server, bypassing protective measures such as data execution prevention (DEP) and address space layout randomization (ASLR).

How I Built it

I used Visual Studio, CMake, Vim, and GitHub to manage and edit the project. The project is composed of four parts: a website, a web server with a vulnerability, an exploit script, and a payload. The website was written with HTML and CSS. The web server was written in C++. The exploit script was written in Python. The payload does not exist, but would be position-independent shellcode.

Gallery

webserver.cpp
pwn.py