3 ms·
It should mention the bug only exists after some arbitrary "patch" was introduced. As the current title makes it sounds like the actual zlib has a security issu
by binaryturtle 1y ago
It should mention the bug only exists after some arbitrary "patch" was introduced. As the current title makes it sounds like the actual zlib has a security issue.
- pajko 1y agoSeems like it's not just arbitrary, but crafted. Could not find it anywhere, for example, searching for "DISTS so we can remove overflow checks from" (with quotes ofc) brings up just this site, both in Google and Bing. It has typos, btw. It would be another issue if it came from https://chromium.googlesource.com/chromium/src/+/HEAD/third_party/zlib/patches/ https://chromium.googlesource.com/chromium/src/+/HEAD/third_..., but that's not the case.
- Thorrez 1y agoCrafted for the Google CTF. Here's the challenge: https://capturetheflag.withgoogle.com/challenges/pwn-webz https://capturetheflag.withgoogle.com/challenges/pwn-webz There's an attachment link, which I believe contains the patch (I haven't looked though): https://storage.googleapis.com/2025-attachments/193040ef9e60cda29d43988bced206b49051516bb63ba39b7cf270437889b146994d84440a9725e687164a0cae5e5cae17f8af46aae8d50f22e3d179d13e9e47.zip https://storage.googleapis.com/2025-attachments/193040ef9e60...
- molticrystal 1y agoThe original title included "[CTF] Google CTF 2025" which would strongly hint(CTF=capture the flag) at the possibility of an artificial setting. That probably should of been included in the submission.
- rot22 1y agoNot the author. The first sentence of the article does say this “webz is a zlib exploitation challenge from Google CTF 2025. The Google-zlib implementation provided in the challenge is not upstream; it’s a version with an arbitrary patch applied.” It’s almost quite literally your comment word for word.