Rating:

Using a format string attack on a remote server, an attacker can leverage certain data structures present in a running Linux process to ascertain key addresses to achieve remote code execution.

Mirror Here: https://nusgreyhats.org/write-ups/hitbgsecquals2018-babynya/

Original writeup (https://nandynarwhals.org/hitbgsecquals2018-babypwn/).