This time I decided to check format1 challenge from Protostar CTF. Here we go...
We will start here:
Opening file in gdb:
Better. Go back to the console:
Good, rewrite time:
Variable we need to overwrite is located in BSS section:
First of all we know that the length is 133. Now we need an address of the target, that's the time for objdump. In the end we need to run ./format1 with our new created payload:
See you next time!