Calling a function in C without naming it
Summary
Two researchers describe bypassing a controlled remote code execution grading system in C to obtain arbitrary shell access by leaking memory offsets between allowable functions (printf) and executable functions (execve), constructing a small in-memory syscall trampoline, and using ASan and ASLR interactions to bypass checks. The article includes a PoC and discusses potential mitigations and security implications for similar educational environments.