GynvaelEN[Full video: youtube.com/live/eq9p9koSYws] Google CTF 2024 Qualification Round ended a few weeks ago, so let's solve a couple of challenges from it! And let's start with HX8 TEASER 2 challenge, which is a Hackceler8 (i.e. Google CTF Finals) challenge.
Powered by Gynvael Coldwind Video Editor: @majiddeshmukh (instagram.com/majiddeshmukh) More info: https://gynvael.live/faq_en.html My Company: https://hexarcana.ch/ My Discord: https://gynvael.coldwind.pl/discord My Twitter: https://x.com/gynvael My Blog: https://gynvael.coldwind.pl
Solving Hackceler8 Teaser Task 2 (Part 3)GynvaelEN2024-07-21 | [Full video: youtube.com/live/eq9p9koSYws] Google CTF 2024 Qualification Round ended a few weeks ago, so let's solve a couple of challenges from it! And let's start with HX8 TEASER 2 challenge, which is a Hackceler8 (i.e. Google CTF Finals) challenge.
Powered by Gynvael Coldwind Video Editor: @majiddeshmukh (instagram.com/majiddeshmukh) More info: https://gynvael.live/faq_en.html My Company: https://hexarcana.ch/ My Discord: https://gynvael.coldwind.pl/discord My Twitter: https://x.com/gynvael My Blog: https://gynvael.coldwind.plThe tragedy of low-level exploitationGynvaelEN2024-08-04 | "I love low-level exploitation and exploit development! How can I make this my whole career?" Well. there is bad news and a bit of good news. In this video I go through my newest blogpost addressing a frequent question. Blog post: https://gynvael.coldwind.pl/?id=791
Powered by Gynvael Coldwind My Company: https://hexarcana.ch/ My Discord: https://gynvael.coldwind.pl/discord My Twitter: https://x.com/gynvael My Blog: https://gynvael.coldwind.plHx8 Teaser 2 Highlights! (part 2)GynvaelEN2024-07-18 | [Full video: youtube.com/watch?v=eq9p9koSYws] Google CTF 2024 Qualification Round ended a few weeks ago, so let's solve a couple of challenges from it! And let's start with HX8 TEASER 2 challenge, which is a Hackceler8 (i.e. Google CTF Finals) challenge.
Powered by Gynvael Coldwind Video Editor: @majiddeshmukh (instagram.com/majiddeshmukh) More info: https://gynvael.live/faq_en.html My Company: https://hexarcana.ch/ My Discord: https://gynvael.coldwind.pl/discord My Twitter: https://x.com/gynvael My Blog: https://gynvael.coldwind.plSolving Hackceler8 Teaser Task 2 (Part 3)GynvaelEN2024-07-18 | Google CTF 2024 Qualification Round ended a few weeks ago, so let's solve a couple of challenges from it! And let's start with HX8 TEASER 2 challenge, which is a Hackceler8 (i.e. Google CTF Finals) challenge.
Powered by Gynvael Coldwind More info: https://gynvael.live/faq_en.html My Company: https://hexarcana.ch/ My Discord: https://gynvael.coldwind.pl/discord My Twitter: twitter.com/gynvael My Blog: https://gynvael.coldwind.pl
Livestream ID: EN 132Solving Hackceler8 Teaser Task 2 (Part 2)GynvaelEN2024-07-16 | Google CTF 2024 Qualification Round ended a few weeks ago, so let's solve a couple of challenges from it! And let's start with HX8 TEASER 2 challenge, which is a Hackceler8 (i.e. Google CTF Finals) challenge.
Powered by Gynvael Coldwind More info: https://gynvael.live/faq_en.html My Company: https://hexarcana.ch/ My Discord: https://gynvael.coldwind.pl/discord My Twitter: twitter.com/gynvael My Blog: https://gynvael.coldwind.pl
Livestream ID: EN 131Hx8 Teaser 2 Highlights! (part 1)GynvaelEN2024-07-14 | [Full video: youtube.com/watch?v=FvrucwKL7kg] Google CTF 2024 Qualification Round ended a few weeks ago, so let's solve a couple of challenges from it! And let's start with HX8 TEASER 2 challenge, which is a Hackceler8 (i.e. Google CTF Finals) challenge.
Powered by Gynvael Coldwind Video Editor: @majiddeshmukh (instagram.com/majiddeshmukh) More info: https://gynvael.live/faq_en.html My Company: https://hexarcana.ch/ My Discord: https://gynvael.coldwind.pl/discord My Twitter: https://x.com/gynvael My Blog: https://gynvael.coldwind.plSolving Hackceler8 Teaser Task 2GynvaelEN2024-07-10 | Google CTF 2024 Qualification Round ended a few weeks ago, so let's solve a couple of challenges from it! And let's start with HX8 TEASER 2 challenge, which is a Hackceler8 (i.e. Google CTF Finals) challenge.
Powered by Gynvael Coldwind More info: https://gynvael.live/faq_en.html My Company: https://hexarcana.ch/ My Discord: https://gynvael.coldwind.pl/discord My Twitter: twitter.com/gynvael My Blog: https://gynvael.coldwind.pl
Livestream ID: EN 130Non-IT books on my shelves (2024 edition)GynvaelEN2024-01-06 | Yesterday we run out of time for fiction (sci-fi/fantasy) books, so let's go through some of my fiction shelves today.
Powered by Gynvael Coldwind More info: https://gynvael.live/faq_en.html My Discord: https://gynvael.coldwind.pl/discord My Twitter: twitter.com/gynvael My Blog: https://gynvael.coldwind.pl My Company: https://hexarcana.ch/
Livestream ID: EN 129Whats on my IT book shelves? (2024 edition)GynvaelEN2024-01-04 | It's been a while since I went through the books I have in my library, so let's do a BookTube livestream! I'll start with my computer/IT books, then go through a few shelves of soft skills books. Note: fantasy/sci-fi was moved to the next livestream.
Powered by Gynvael Coldwind More info: https://gynvael.live/faq_en.html My Discord: https://gynvael.coldwind.pl/discord My Twitter: twitter.com/gynvael My Blog: https://gynvael.coldwind.pl My Company: https://hexarcana.ch/
Livestream ID: EN 128Learning Rust Challenge! #8GynvaelEN2023-08-18 | I've read some docs, but only half way through. Now I want to try a single-link linked list once again.
Powered by Gynvael Coldwind More info: https://gynvael.live/faq_en.html My Discord: https://gynvael.coldwind.pl/discord My Twitter: twitter.com/gynvael My Blog: https://gynvael.coldwind.pl My Company: https://hexarcana.ch/
Livestream ID: EN 127Learning Rust Challenge! #7GynvaelEN2023-08-15 | Time to say "Hi!" to the borrow checker and start learning it.
Powered by Gynvael Coldwind More info: https://gynvael.live/faq_en.html My Discord: https://gynvael.coldwind.pl/discord My Twitter: twitter.com/gynvael My Blog: https://gynvael.coldwind.pl My Company: https://hexarcana.ch/
Livestream ID: EN 126Learning Rust Challenge! #6GynvaelEN2023-08-10 | Linked lists in Rust are apparently evil, so I'm going to play a bit with them.
Powered by Gynvael Coldwind More info: https://gynvael.live/faq_en.html My Discord: https://gynvael.coldwind.pl/discord My Twitter: twitter.com/gynvael My Blog: https://gynvael.coldwind.pl My Company: https://hexarcana.ch/
Livestream ID: EN 125Learning Rust Challenge! #5GynvaelEN2023-08-08 | While typing in sondrele's BMP parser a lot of questions popped up. I think I should start looking for some answers.
Powered by Gynvael Coldwind More info: https://gynvael.live/faq_en.html My Discord: https://gynvael.coldwind.pl/discord My Twitter: twitter.com/gynvael My Blog: https://gynvael.coldwind.pl My Company: https://hexarcana.ch/
Livestream ID: EN 124Learning Rust Challenge! #4GynvaelEN2023-08-08 | My first step when learning a new language is to type in some code someone else has written – there are multiple good reasons for this! And in this episode I finally should finish my first "type in" and start trying to get it to work.
Powered by Gynvael Coldwind More info: https://gynvael.live/faq_en.html My Discord: https://gynvael.coldwind.pl/discord My Twitter: twitter.com/gynvael My Blog: https://gynvael.coldwind.pl My Company: https://hexarcana.ch/
Livestream ID: EN 123Learning Rust Challenge! #3GynvaelEN2023-08-06 | It's time for me to learn a new programming language - Rust! Join me on my adventure and sneak a peak how a programmer with over 30 years of experience approaches the topic of learning a programming language.
Powered by Gynvael Coldwind More info: https://gynvael.live/faq_en.html My Discord: https://gynvael.coldwind.pl/discord My Twitter: twitter.com/gynvael My Blog: https://gynvael.coldwind.pl My Company: https://hexarcana.ch/
Livestream ID: EN 122Learning Rust Challenge! #2GynvaelEN2023-08-05 | It's time for me to learn a new programming language - Rust! Join me on my adventure and sneak a peak how a programmer with over 30 years of experience approaches the topic of learning a programming language.
Powered by Gynvael Coldwind More info: https://gynvael.live/faq_en.html My Discord: https://gynvael.coldwind.pl/discord My Twitter: twitter.com/gynvael My Blog: https://gynvael.coldwind.pl My Company: https://hexarcana.ch/
Livestream ID: EN 121Learning Rust Challenge! #1GynvaelEN2023-08-02 | It's time for me to learn a new programming language - Rust! Join me on my adventure and sneak a peak how a programmer with over 30 years of experience approaches the topic of learning a programming language.
Powered by Gynvael Coldwind More info: https://gynvael.live/faq_en.html My Discord: https://gynvael.coldwind.pl/discord My Twitter: twitter.com/gynvael My Blog: https://gynvael.coldwind.pl My Company: https://hexarcana.ch/
Livestream ID: EN 120PCI Express To HellGynvaelEN2023-07-29 | If you're building your own PCs you should watch this talk! Last year I reworked my whole computer setup and learned a lot about PCI Express. This talk is a summary of lessons learned and should help you to not make the same mistakes I did.
Powered by Gynvael Coldwind More info: https://gynvael.live/faq_en.html My Discord: https://gynvael.coldwind.pl/discord My Twitter: twitter.com/gynvael My Blog: https://gynvael.coldwind.pl My Company: https://hexarcana.ch/
Livestream ID: EN 119On Leaving Google and Whats NextGynvaelEN2023-07-04 | With the end of April I left Google's security team after a bit over 12 years to rest a bit and build something of my own. Let's use this livestream as an opportunity to chat about what was and what's next.
Powered by Gynvael Coldwind More info: https://gynvael.live/faq_en.html My Discord: https://gynvael.coldwind.pl/discord My Twitter: twitter.com/gynvael My Blog: https://gynvael.coldwind.pl
Livestream ID: EN 118Just chatting (logo and LEDs)GynvaelEN2022-11-15 | Working on the background of my livestream. I have a laser-cut logo, now I need to figure out how to attach LEDs to it's back.
This was a random stream - will be moved to 'Random Chats' playlist later on.
Powered by Gynvael Coldwind ⁂ https://gynvael.coldwind.pl My Discord: https://gynvael.coldwind.pl/discordJust chatting (logo and LEDs)GynvaelEN2022-11-15 | Working on the background of my livestream. I have a laser-cut logo, now I need to figure out how to attach LEDs to it's back.
This was a random stream - will be moved to 'Random Chats' playlist later on.
Powered by Gynvael Coldwind ⁂ https://gynvael.coldwind.pl My Discord: https://gynvael.coldwind.pl/discordJust chatting (crashing cam in OBS with a piece of paper)GynvaelEN2022-11-05 | On this livestream I continued getting RPi 3B to output webcam video to HDMI, but also tested USB-over-IP. To my surprise one of the tests crashed the input webcam stream in OBS - pretty fun!
This was a random stream - will be moved to 'Random Chats' playlist later on.
Powered by Gynvael Coldwind ⁂ https://gynvael.coldwind.pl My Discord: https://gynvael.coldwind.pl/discord#117: A CCTV H4CK1NG G00GLE challengeGynvaelEN2022-10-19 | Ever heard of Twitch Plays Pokemon? Well, we will be playing Youtube Solves Challenges! This one should be fun!
Powered by Gynvael Coldwind More info: https://gynvael.live/faq_en.html My Discord: https://gynvael.coldwind.pl/discord My Twitter: twitter.com/gynvael My Blog: https://gynvael.coldwind.pl#116: Google Beginners Quest 2021GynvaelEN2021-10-01 | [Sorted in solving order] 0:00 - Start 15:46 - Task 1: CCTV (rev) 23:38 - Task 2: Logic Lock (misc) 34:27 - Task 3: High Speed Chase (misc) 49:25 - Task 5: Twisted robot (misc) 1:07:50 - Task 8: Hide and seek (misc) 1:22:10 - Task 10: Spycam (hw) 1:47:15 - Task 12: Old lock (web) 1:55:47 - Task 13: Noise on the wire (net) 2:04:45 - Task 15: Just another keypad (rev) 2:14:48 - Task 17: Playing golf (misc) 3:01:08 - Task 18: Strange Virtual Machine (rev) 3:41:49 - Task 4: Electronics Research Lab (hw) 3:51:41 - Task 6: To the moon (misc) 4:16:40 - Task 7: ReadySetAction (crypto) 4:25:30 - Task 9: Konski-Hiakawa Law of Droids (rev) 4:28:23 - Task 11: pwn-notebook (pwn) 4:41:59 - Task 14: web-quotedb (web) 4:45:04 - Task 16: Hash-meee (misc)
Our Discord: https://gynvael.coldwind.pl/discord Our IRC: irc.gynvael.live (type /LIST to see channels)Gears of Chaos exploit demoGynvaelEN2021-06-29 | NETGEAR WAC104 had a nasty set of vulnerabilities. If you have this access point, please go and patch now. kb.netgear.com/000063785/Security-Advisory-for-Authentication-Bypass-on-WAC104-PSV-2021-0075 https://gynvael.coldwind.pl/?id=736#115: Random TopicsGynvaelEN2020-11-04 | Our Discord: discord.gg/QAwfE5R Our IRC: #gynvaelstream-en on freenode#114: Google CTFGynvaelEN2020-09-02 | Easy challenges (part 2/2) 8:32 Intro 25:32 Crypto / Chunk Norris 1:28:55 Web / Pasteurize 2:01:56 Sandbox / WriteOnly 2:55:58 Outro
Our Discord: discord.gg/QAwfE5R Our IRC: #gynvaelstream-en on freenode#113: Google CTFGynvaelEN2020-08-26 | Easy challenges (part 1/2). 4:57 Intro 18:07 Hardware / Basics 1:00:14 Crypto / Chunk Norris (failed to solve; restart in part 2) 1:37:29 Pwn / Tracing 2:41:19 Reversing / Beginner
Our Discord: discord.gg/QAwfE5R Our IRC: #gynvaelstream-en on freenode#112: Hack The BoxGynvaelEN2020-08-12 | Using PwnBox to solve a Machine (or try at least - this is the second machine I'm ever doing on HTB). Part 2 Hack The Box: bit.ly/3flYmmZ
Our Discord: discord.gg/QAwfE5R Our IRC: #gynvaelstream-en on freenode#111: Hack The BoxGynvaelEN2020-08-05 | Using PwnBox to solve a Machine (or try at least - this is the second machine I'm ever doing on HTB). Hack The Box: bit.ly/3flYmmZ
Our Discord: discord.gg/QAwfE5R Our IRC: #gynvaelstream-en on freenode#94: picoCTF 2019 (part 4)GynvaelEN2019-12-11 | ⏱ Table of Content
00:00:10 [PROLOG] nervous_testpilot - Focus | http://nervoustestpilot.co.uk 00:02:17 [PROLOG] nervous_testpilot - Office | http://nervoustestpilot.co.uk 00:08:30 [PROLOG] TheFatRat - Monody (feat. Laura Brehm) | youtube.com/user/ThisIsTheFatRat 00:13:24 [PROLOG] Stellardrone - Between The Rings
00:17:41 ⁂ START ⁂
00:19:00 Announcements
- Today's moderator: foxtrot_charlie | foxtrotlabs.cc - Paged Out! #2 3rd version released
00:23:16 Let's get started!
00:24:04 Explanation why NewOverFlow-1 (from previous part) took so long
00:25:45 NewOverFlow-2 / bin exp / 250p
+ code review → if you see an unintended bug - just go for it
+ checksec(.sh)
- no stack canary
- NX on
- no PIE
+ RE - disassembler (IDA)
- flag() is there by creator's mistake, but we will ignore it to solve it another (return chaining) way
- we need to jump to win_fn() to win; description says we need to call win1/win2 with specific arguments, but we'll do it another way
- 00:32:24 chaining returns
- constructing the payload (and aligning the stack)
Q: What do you mean by "align the stack"?
Q: What's the topics/ideas for future streams?
Q: Is discrete math important?
Q: Any experience with Intel Pin or DynamoRio? Would You recommend any of them?
Q: How important is data structures / algorithms in InfoSec?
00:52:41 asm2 / reverse eng / 250p
+ this time we'll actually analyze the assembly! (or actually, reimplement it in Python)
+ differences between how Python's ints work and how C/C++/x86 ints work
- need to truncate ints to 32-bits
+ pretty standard approach to reversing - translate to be able to instrument easier
01:07:25 CanaRy / bin exp / 300
+ about stack cookies (paper mentioned: http://vexillium.org/pub/002.html)
+ 01:10:25 analysis of source code and binary
- run checksec(.sh)
* no canary found (i.e. this is a custom canary implementation)
* PIE enabled (we'll have to bypass this)
- in case of forkserver (duplicate process for every new connection) the canary is NOT reset (so it can be leaked byte-by-byte)
- example of how canary works - memcpy() of master cookie (key) to the canary on the beginning of the function; later checked
* if not there is exit(-1) which calls destructors (not to be confused with class destructors), better use _exit() which lead to an exiting syscall
* other bypass techniques
+ conception of attacking canary, same as on fork server - stack canary is secret but constant - we can brute-force values of each byte of canary (00..FF) separately
- oracle: when there is not "smash stack detected" → we guessed that byte correctly
- repeat for next byte, and next, ...
- instead of 2^32 we've done it in 2^10
Q: 01:24:37 What you mean about exit destructors? How can i define one?
+ 01:30:08 back to implementing the exploit
- always check if maybe we can just read the flag on the server due to faulty ACLs or sth (no luck this time)
- figuring out what exactly we need to do
- 1:33:26 writing the exploit and testing it locally
* patch the local binary to change some paths
- 1:43:01 let's do this remotely!
* adding proper shellcode/payload and dealing with ASLR
* ASLR moves memory pages only, so last 3 nibbles (1.5 bytes) are same as in the binary - we need to brute-force 0.5 of a byte
Q :01:48:16 What's the difference of ASLR and PIE?
Q: Can the 64-bit canary be bypassed?
Q: Can you recommend any good source for reversing cryptography?
01:57:03 Investigative Reversing 0 / forensics / 300
+ look at the files in hex editor
+ in IDA we see we understand that binary append some data to the PNG file, the modified bytes from flag file
+ doing basic math on hex in your head
02:05:35 Conclusions and Q&A
Q: In the normal condition is the cookie random?
02:06:54 Epilogue
Thanks for attending folks this year!
Thank you foxtrot_charlie for being my Moderator today!
02:07:35 [EPILOG] nervous_testpilot - Our Heroes | http://nervoustestpilot.co.uk (kudos to J.V. for ToC!)
Our Discord: discord.gg/QAwfE5R Our IRC: #gynvaelstream-en on freenode#93: picoCTF 2019 (part 3)GynvaelEN2019-12-04 | ⏱ Table of Content
00:00:14 [PROLOG] nervous_testpilot - Focus | http://nervoustestpilot.co.uk 00:02:16 [PROLOG] TheFatRat - Monody (feat. Laura Brehm) | youtube.com/user/ThisIsTheFatRat 00:07:12 [PROLOG] Stellardrone - Bettween The Rings
00:12:23 ⁂ START ⁂
00:13:30 Announcements
- Today's moderator: foxtrot_charlie | foxtrotlabs.cc - Paged Out!
00:15:45 Let's get started (with exploitation)
00:17:33 OverFlow 2 / bin exp / 250p
+ BOF in vuln() found; flag() never called.
+ Making the payload
+ It's crashes but output buffering is turned off so we've got the flag
+ We could do some 'brute-force' tries to pwn w/o full knowledge of stack, any debugging etc - this could be faster on a CTF.
00:26:51 We get the flag
Q: Any difference between Windows and Linux chars implementations?
- Not really - char is the same, signed, 1B. Differences are in processing text file, text streams and the functions themselves.
- With regards to 00:20:05 in gets() on Windows more characters are disallowed e.g. ctrl+d (End Of Transmission) (see also: 01:49:47)
Q: Any good tutorials for introduction to IDA?
- No known IDA tutorial, but check out "FAQ: How to learn reverse-engineering?" on my blog
00:32:17 NewOverFlow-1 / bin exp / 200
+ 64-bit are default nowadays
+ Differences between 32-bit and 64-bit exploitation
+ Using objdump this time around: objdump -x and objdump -Mintel -d
+ We try some things, they don't work.
+ 00:56:06 ... as this doesn't work, we go all the way in
- Looking for some machine code with side-effects
* '\xeb\xfe' - infinite loop
* Calls to puts() with buffer
* Jumping to flag() doesn't work - let's jump in the middle of it (it worked).
Q: Could you explain how to exploit global buffer overflow?
Q: Looking into starting with CTFs but I don't actually know exactly where I should start. Do you know any website where I can learn from the ground up?
Q: Did you watch Mr Robot?
Q: You should know the server is running Ubuntu 18.04 it's relevant for this chall.
Q: Would you approach more advanced challs the same way?
Q: In case of passing args to func in 64bit is shellcoding and ROP the only one option?
Q: Any books/tutorials on reverse engineering?
Q: What is the best tutorial for XYZ?
Q: How to get started with exploit development for 21 y.o. guy?
Q: Can we use ROP for all bof vulns?
01:14:51 like1000 / forensics / 250p
+ Started with a simple python script.
+ ...oh gosh! we don't need to process it recursive way - TAR isn't compressed!
Q: Are there any protections against ROP?
Q: Why do you use Windows?
Q: How to become red-teamer or exploit dev?
Q: What if there would be 1000 PNG files in that TAR archive?
+ Shout out to hackvent.hacking-lab.com 01:32:45 vault-door-4 / reverse eng / 250p
+ A print the flag (in a smart way) challenge.
Q: Have you been pwned by phishing?
01:38:26 Irish-Name-Repo 1 / web / 300p
+ Probably SQLi, but first let's analyze the source code of the page.
+ Preparing a very simple injection with tautology (remember about space after double-dash cause some MySQL version need this).
Q: 2FA protects against phishing.
Q: How malware analysis actually work as business model?
Q: Will admin=admin&password='+or+1=1+--+ work?
01:48:23 flag_shop / general skills / 300p
+ Code review in C
+ We found integer overflow: happens in C, in Java, .NET, ActiveStript, not in PHP (overflow? cast to float!), JS (? no integers let's start with floats!), Python (big nums ftw), nice fact that Ada will raise exception when you compile correctly, no idea what in Rust, for C/C++ some libs to deal with it.
+ Check my book (still only in Polish, sorry!) "Zrozumieć programowanie" ch. 4 & 5 for knowledge related with integers and floats. :)
01:58:45 Q: Will be integer overflow could be exploited?
02:02:44 asm1 / reverse eng / 200p
+ We have a disassembly listing of a function (x86-32)
+ To lazy to reverse - let's run it using Asmloader (see my GitHub repository) and get the return value.
- Agner Fog Calling convention guide p. 10 (Table 6 - Register usage) and any other work (which are amazing)
- http://gynvael.vexillium.org/dump/opcodes.txt for cheat-sheet by Sang Cho
- Calling convention @ Wikipedia
02:14:06 Epilog
We've pass -4 challs today. Thanks for attending folks!
Thank you foxtrot_charlie for being my Moderator today!
02:15:11 [EPILOG] nervous_testpilot - Our Heroes | http://nervoustestpilot.co.uk (kudos to J.V. for ToC!)
Our Discord: discord.gg/QAwfE5R Our IRC: #gynvaelstream-en on freenode#92: picoCTF 2019 (part 2)GynvaelEN2019-11-27 | ⏱ Table of Content 00:08 [PROLOG] nervous_testpilot - Focus | http://nervoustestpilot.co.uk 02:15 [PROLOG] TheFatRat - Monody (feat. Laura Brehm) | youtube.com/user/ThisIsTheFatRat 07:06 [PROLOG] Stellardrone - Bettween The Rings 13:20 ⁂ START ⁂ - Greetings 13:45 Short agenda about todays' stream; Q&A rules 14:50 Announcements and hypes - Today's moderator: foxtrot_charlie | foxtrotlabs.cc - Paged Out! #2 is out // Call For Papers (one page) until 02/20/2020 (20 Feb 2020); - 16:21 Authors of articles from 1st rel of Paged Out! who have chosen non-TIP/POOL SAA should receive an email; if not get back to me :) - I've made one of Winja CTF '18 tasks and now it's released | github.com/google/google-ctf/tree/master/other/re-risky - It looks like Dec 2018 will be exciting contest between TOP 4 of CTF Time | ctftime.org 19:24 Let's get started! 20:44 2Warm / general / 50pts 22:42 picobrowser / web exp / 200pts - on page we see that we are not picobrowser so we are going to change User-Agent - see Dev Tools in web browser, but could be solved in different way, e.g. curl 26:39 Question: Can we use CTFs for prepare for OSCP? Q @ YT chat: are CTFs useful for real life pentesting? 29:03 plumbing / general / 200pts - netcat + "grep to win" technique which is easy and was described previously 30:11 rsa-pop-quiz / crypto / 200pts - tools: netcat + Python CLI as helper for calculations - knowledge: basics of prime numbers and RSA theory - objectives of this task: get to know with RSA - it's really simple 51:31 slippery-shellcode / bin exp / 200pts - tools: checksec.sh (checking protection of running binary) - knowledge: basics of assembly and code review of C-like languages - objectives of this task: old-school basic exploitation with a NOP sled; 32-bit ELF binary (execute shellcode, get the rid of problem with buffering, have no protections, isn't PIE...) + 0:57:44 about shellcodes + 1:00:00 writing a shellcode that uses fopen/fgets found in memory at known locations 1:10:42 Q: Do you know what AVX2 is used for in assembly? - some historical roots of SIMD extensions in Intel CPUs (MMX, SSE, AVX), why was it created, and registers naming (mm0, xmm0, ymm0, zmm0) - note from viewer: there is JSON parser library that uses vectorized instructions 1:15:16 Q: Check whether it is statically linked on the server also, not just the downloaded version. - why this should *not* be true for CTFs because of annoying players and what's the difference from not-lab exploitation cases 1:16:40 vault-door-3 / rev eng / 200pts - reversing Java code 1:27:28 "I'm going to show you another way to do this" :) - taking a fresh look at the same problem since I got confused by trying to do the reverse mapping in my head on livestream (which I failed hard); so instead, I showed a way to get the mapping to generate itself 1:32:29 Q: What motivates you when doing a hard challenge? 1:34:10 whats-the-difference / general / 200pts - comparing two binary files with use of python Q: What about zip() in Python when the length of lists is not equal? Q: How hard does a challenge have to be to resemble that of a real life scenario in the work force (or as close as it come)? 1:39:58 where-is-the-file / general / 200pts - file starting with . 1:41:20 WhitePages / forensics / 250pts - three code units: E2 80 83 ... :) - funky ASCII art or binary ASCII encoding? - at the end: a note about ASCII and code pages 1:51:03 c0rrupt / forensics / 250pts 1:51:43 In YT chat Daniel mentioned 24/7 CTF challenges (247ctf.com/). Take a look at it - they are really cool! Returning to task: - broken PNG file... - ...but many files are simply based on zlib aka DEFLATE (e.g. ZIP, GZIP, HTTP compression, but also PNG) - we will try to brute force it! - ...and in the end hack it in GIMP. 2:01:55 Q: With zlib compression, can we decompress even without the beginning of the bytes stream? Or if we have "holes" in the bytes stream? 2:03:55 m00nwalk / forensics / 250pts - WAV file with 11MB Please make volume down, because we are m00nwalking with SSTV over the stream sound directly 8) - from 2:07:00 to 2:07:56 - from 2:09:57 to 2:10:03 - from 2:10:53 to 2:11:33 2:18:17 Q: What did you study in college/University and what certs did you get? See also (in Polish but Google Translate could do the thing): - https://gynvael.coldwind.pl/?id=337 - https://gynvael.coldwind.pl/?id=338 2:20:36 Epilog Thanks for attending folks! Thank you foxtrot_charlie for being my Moderator today! Next stream is planned on next Wednesday (part 3). 2:21:06 [EPILOG] nervous_testpilot - Our Heroes | http://nervoustestpilot.co.uk (kudos to J.V. for ToC!)
Our Discord: discord.gg/QAwfE5R Our IRC: #gynvaelstream-en on freenode#91: Dragon CTF 2019GynvaelEN2019-11-20 | Welcome back to Arcane Island! On this livestream I'll be showing the Arcane Sector II game made for the Dragon CTF 2019 (there aren't many engine changes vs AS1), and how to solve 4 in-game CTF tasks.