Skip to content

Solve

Solution script and a containerized solver environment for the "heap0" challenge.

Prerequisites

  1. Build the solver image:

    docker build -t heap0-solver .
    
  2. Ensure ../publish/chall exists (for local solving) -- see ../build/README.md and ../publish/README.md.

Running the solution

1. Local solve (inside container)

Runs the exploit against the binary directly inside the solver container. We mount the current directory (for exploit.py) and ../publish (for chall and its libc/loader).

docker run --rm -it \
    -v "$(pwd):/solve" \
    -v "$(pwd)/../publish:/publish" \
    -w /publish \
    heap0-solver \
    python3 /solve/exploit.py

2. Solve against a local deployment

Runs the exploit against the challenge service started via ../deploy/README.md (listening on localhost:31010).

[!NOTE] Linux: --network host lets the container reach localhost on the host directly. macOS/Windows: use host.docker.internal instead of 127.0.0.1 and drop --network host.

docker run --rm -it --network host \
    -v "$(pwd):/solve" \
    heap0-solver \
    python3 /solve/exploit.py REMOTE HOST=127.0.0.1 PORT=31010

3. Solve against a remote target

docker run --rm -it \
    -v "$(pwd):/solve" \
    heap0-solver \
    python3 /solve/exploit.py REMOTE HOST=1.2.3.4 PORT=31010