GynvaelEN
Summer Gamedev Challenge 2017 Game Review
updated
Blog post: https://gynvael.coldwind.pl/?id=791
Powered by Gynvael Coldwind
My Company: https://hexarcana.ch/
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: https://x.com/gynvael
My Blog: https://gynvael.coldwind.pl
Part 1:
→ Highlights: youtube.com/watch?v=6KGsshjzkEc
→ Full video: youtube.com/watch?v=FvrucwKL7kg
Part 2:
→ Highlights: youtu.be/S6PmBvvJwUk
→ Full video: youtube.com/live/eq9p9koSYws
Powered by Gynvael Coldwind
Video Editor: @majiddeshmukh (instagram.com/majiddeshmukh)
More info: https://gynvael.live/faq_en.html
My Company: https://hexarcana.ch/
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: https://x.com/gynvael
My Blog: https://gynvael.coldwind.pl
Part 1:
→ Highlights: youtube.com/watch?v=6KGsshjzkEc
→ Full video: youtube.com/watch?v=FvrucwKL7kg
Part 3:
→ Highlights: youtu.be/Hze_heJkQYQ
→ Full video: youtube.com/live/eq9p9koSYws
Powered by Gynvael Coldwind
Video Editor: @majiddeshmukh (instagram.com/majiddeshmukh)
More info: https://gynvael.live/faq_en.html
My Company: https://hexarcana.ch/
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: https://x.com/gynvael
My Blog: https://gynvael.coldwind.pl
And let's start with HX8 TEASER 2 challenge, which is a Hackceler8 (i.e. Google CTF Finals) challenge.
Part 1:
→ Highlights: youtube.com/watch?v=6KGsshjzkEc
→ Full video: youtube.com/watch?v=FvrucwKL7kg
Part 2:
→ Highlights: TBA
→ Full video: youtube.com/watch?v=eq9p9koSYws
Songs used in the video (et al):
youtube.com/watch?v=B7xai5u_tnk
Powered by Gynvael Coldwind
More info: https://gynvael.live/faq_en.html
My Company: https://hexarcana.ch/
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: twitter.com/gynvael
My Blog: https://gynvael.coldwind.pl
Livestream ID: EN 132
And let's start with HX8 TEASER 2 challenge, which is a Hackceler8 (i.e. Google CTF Finals) challenge.
Part 1:
→ Highlights: youtube.com/watch?v=6KGsshjzkEc
→ Full video: youtube.com/watch?v=FvrucwKL7kg
Songs used in the video (et al):
youtube.com/watch?v=B7xai5u_tnk
Powered by Gynvael Coldwind
More info: https://gynvael.live/faq_en.html
My Company: https://hexarcana.ch/
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: twitter.com/gynvael
My Blog: https://gynvael.coldwind.pl
Livestream ID: EN 131
Part 2:
→ Highlights: youtu.be/S6PmBvvJwUk
→ Full video: youtube.com/live/eq9p9koSYws
Part 3:
→ Highlights: youtu.be/Hze_heJkQYQ
→ Full video: youtube.com/live/eq9p9koSYws
Powered by Gynvael Coldwind
Video Editor: @majiddeshmukh (instagram.com/majiddeshmukh)
More info: https://gynvael.live/faq_en.html
My Company: https://hexarcana.ch/
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: https://x.com/gynvael
My Blog: https://gynvael.coldwind.pl
And let's start with HX8 TEASER 2 challenge, which is a Hackceler8 (i.e. Google CTF Finals) challenge.
Songs used in the video (et al):
youtube.com/watch?v=B7xai5u_tnk
Powered by Gynvael Coldwind
More info: https://gynvael.live/faq_en.html
My Company: https://hexarcana.ch/
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: twitter.com/gynvael
My Blog: https://gynvael.coldwind.pl
Livestream ID: EN 130
Shelf photos from this video:
photos.app.goo.gl/CFHfY9z3mVwBrG8G8
Previous livestream with IT and (a few) softskills books:
youtube.com/watch?v=cv72-_3cvhU
Books mentioned:
(link to photos will be added after the stream)
Songs used in the video (et al):
youtube.com/watch?v=B7xai5u_tnk
Powered by Gynvael Coldwind
More info: https://gynvael.live/faq_en.html
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: twitter.com/gynvael
My Blog: https://gynvael.coldwind.pl
My Company: https://hexarcana.ch/
Livestream ID: EN 129
Note: fantasy/sci-fi was moved to the next livestream.
Books mentioned:
photos.app.goo.gl/wMaQFXrSXoVTxn4a9 (IT)
photos.app.goo.gl/QZDFzczewBfJB1rn8 (soft skills)
Songs used in the video (et al):
youtube.com/watch?v=B7xai5u_tnk
Powered by Gynvael Coldwind
More info: https://gynvael.live/faq_en.html
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: twitter.com/gynvael
My Blog: https://gynvael.coldwind.pl
My Company: https://hexarcana.ch/
Livestream ID: EN 128
Notes:
docs.google.com/document/d/1AHuid4KDJhZMHy4WuPhCu-0GB6Y5ftrt5P3R9tt7mmg/edit?usp=sharing
Songs used in the video:
youtube.com/watch?v=B7xai5u_tnk
Thumbnail photo by KRiemer:
pixabay.com/photos/castle-padlock-metal-rust-1290860
Powered by Gynvael Coldwind
More info: https://gynvael.live/faq_en.html
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: twitter.com/gynvael
My Blog: https://gynvael.coldwind.pl
My Company: https://hexarcana.ch/
Livestream ID: EN 127
Notes:
docs.google.com/document/d/1AHuid4KDJhZMHy4WuPhCu-0GB6Y5ftrt5P3R9tt7mmg/edit?usp=sharing
Songs used in the video:
youtube.com/watch?v=B7xai5u_tnk
Thumbnail photo by KRiemer:
pixabay.com/photos/castle-padlock-metal-rust-1290860
Powered by Gynvael Coldwind
More info: https://gynvael.live/faq_en.html
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: twitter.com/gynvael
My Blog: https://gynvael.coldwind.pl
My Company: https://hexarcana.ch/
Livestream ID: EN 126
Songs used in the video:
youtube.com/watch?v=B7xai5u_tnk
Thumbnail photo by KRiemer:
pixabay.com/photos/castle-padlock-metal-rust-1290860
Powered by Gynvael Coldwind
More info: https://gynvael.live/faq_en.html
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: twitter.com/gynvael
My Blog: https://gynvael.coldwind.pl
My Company: https://hexarcana.ch/
Livestream ID: EN 125
Songs used in the video:
youtube.com/watch?v=B7xai5u_tnk
Thumbnail photo by KRiemer:
pixabay.com/photos/castle-padlock-metal-rust-1290860
Powered by Gynvael Coldwind
More info: https://gynvael.live/faq_en.html
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: twitter.com/gynvael
My Blog: https://gynvael.coldwind.pl
My Company: https://hexarcana.ch/
Livestream ID: EN 124
Songs used in the video:
youtube.com/watch?v=B7xai5u_tnk
Thumbnail photo by KRiemer:
pixabay.com/photos/castle-padlock-metal-rust-1290860
Powered by Gynvael Coldwind
More info: https://gynvael.live/faq_en.html
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: twitter.com/gynvael
My Blog: https://gynvael.coldwind.pl
My Company: https://hexarcana.ch/
Livestream ID: EN 123
Songs used in the video:
youtube.com/watch?v=B7xai5u_tnk
Thumbnail photo by KRiemer:
pixabay.com/photos/castle-padlock-metal-rust-1290860
Powered by Gynvael Coldwind
More info: https://gynvael.live/faq_en.html
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: twitter.com/gynvael
My Blog: https://gynvael.coldwind.pl
My Company: https://hexarcana.ch/
Livestream ID: EN 122
Songs used in the video:
youtube.com/watch?v=B7xai5u_tnk
Thumbnail photo by KRiemer:
pixabay.com/photos/castle-padlock-metal-rust-1290860
Powered by Gynvael Coldwind
More info: https://gynvael.live/faq_en.html
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: twitter.com/gynvael
My Blog: https://gynvael.coldwind.pl
My Company: https://hexarcana.ch/
Livestream ID: EN 121
Songs used in the video:
youtube.com/watch?v=B7xai5u_tnk
Thumbnail photo by KRiemer:
pixabay.com/photos/castle-padlock-metal-rust-1290860
Powered by Gynvael Coldwind
More info: https://gynvael.live/faq_en.html
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: twitter.com/gynvael
My Blog: https://gynvael.coldwind.pl
My Company: https://hexarcana.ch/
Livestream ID: EN 120
Slides:
docs.google.com/presentation/d/1xlxqbZGHt929jJLGW3TthWOtQQ8kOkBLytzQGLNvMNc/edit#slide=id.g25be9ef72a1_0_0
Blog posts mentioned:
https://gynvael.coldwind.pl/?lang=en&id=749
https://gynvael.coldwind.pl/?id=757
https://gynvael.coldwind.pl/?id=759
Songs used in the video:
youtube.com/watch?v=B7xai5u_tnk
Powered by Gynvael Coldwind
More info: https://gynvael.live/faq_en.html
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: twitter.com/gynvael
My Blog: https://gynvael.coldwind.pl
My Company: https://hexarcana.ch/
Livestream ID: EN 119
Songs used in the video:
youtube.com/watch?v=B7xai5u_tnk
Powered by Gynvael Coldwind
More info: https://gynvael.live/faq_en.html
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: twitter.com/gynvael
My Blog: https://gynvael.coldwind.pl
Livestream ID: EN 118
This was a random stream - will be moved to 'Random Chats' playlist later on.
Powered by Gynvael Coldwind ⁂ https://gynvael.coldwind.pl
My Discord: https://gynvael.coldwind.pl/discord
This was a random stream - will be moved to 'Random Chats' playlist later on.
Powered by Gynvael Coldwind ⁂ https://gynvael.coldwind.pl
My Discord: https://gynvael.coldwind.pl/discord
This was a random stream - will be moved to 'Random Chats' playlist later on.
Powered by Gynvael Coldwind ⁂ https://gynvael.coldwind.pl
My Discord: https://gynvael.coldwind.pl/discord
https://h4ck1ng.google/
youtube.com/watch?v=5nEyjYn9_LI&list=PL590L5WQmH8dsxxz7ooJAgmijwOz0lh2H
EDIT (and SPOILERS):
The challenge was open sourced and the source code is available here:
github.com/google/google-ctf/tree/master/2022/beginners/episode5/bonus
Songs:
youtube.com/watch?v=B7xai5u_tnk
Powered by Gynvael Coldwind
More info: https://gynvael.live/faq_en.html
My Discord: https://gynvael.coldwind.pl/discord
My Twitter: twitter.com/gynvael
My Blog: https://gynvael.coldwind.pl
0:00 - Start
15:46 - Task 1: CCTV (rev)
23:38 - Task 2: Logic Lock (misc)
34:27 - Task 3: High Speed Chase (misc)
49:25 - Task 5: Twisted robot (misc)
1:07:50 - Task 8: Hide and seek (misc)
1:22:10 - Task 10: Spycam (hw)
1:47:15 - Task 12: Old lock (web)
1:55:47 - Task 13: Noise on the wire (net)
2:04:45 - Task 15: Just another keypad (rev)
2:14:48 - Task 17: Playing golf (misc)
3:01:08 - Task 18: Strange Virtual Machine (rev)
3:41:49 - Task 4: Electronics Research Lab (hw)
3:51:41 - Task 6: To the moon (misc)
4:16:40 - Task 7: ReadySetAction (crypto)
4:25:30 - Task 9: Konski-Hiakawa Law of Droids (rev)
4:28:23 - Task 11: pwn-notebook (pwn)
4:41:59 - Task 14: web-quotedb (web)
4:45:04 - Task 16: Hash-meee (misc)
Our Discord: https://gynvael.coldwind.pl/discord
Our IRC: irc.gynvael.live (type /LIST to see channels)
kb.netgear.com/000063785/Security-Advisory-for-Authentication-Bypass-on-WAC104-PSV-2021-0075
https://gynvael.coldwind.pl/?id=736
Our IRC: #gynvaelstream-en on freenode
8:32 Intro
25:32 Crypto / Chunk Norris
1:28:55 Web / Pasteurize
2:01:56 Sandbox / WriteOnly
2:55:58 Outro
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
4:57 Intro
18:07 Hardware / Basics
1:00:14 Crypto / Chunk Norris (failed to solve; restart in part 2)
1:37:29 Pwn / Tracing
2:41:19 Reversing / Beginner
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
Hack The Box: bit.ly/3flYmmZ
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
Hack The Box: bit.ly/3flYmmZ
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
github.com/microsoft/GW-BASIC
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
github.com/microsoft/GW-BASIC
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
github.com/microsoft/GW-BASIC
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
github.com/microsoft/GW-BASIC
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
Our IRC: #gynvaelstream-en on freenode
Part 2: youtu.be/gHlundcY9GA
Part 3: youtu.be/3x4nzymm33Q
Part 4: youtu.be/gEPd1ref9s0
Part 5: youtu.be/gNvvZhpYHpw
Part 6: youtu.be/rK2y0wMS_9w
Part 7: youtu.be/A8uFdVi8j3g
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
Part 2: youtu.be/gHlundcY9GA
Part 3: youtu.be/3x4nzymm33Q
Part 4: youtu.be/gEPd1ref9s0
Part 5: youtu.be/gNvvZhpYHpw
Part 6: youtu.be/rK2y0wMS_9w
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
Part 2: youtu.be/gHlundcY9GA
Part 3: youtu.be/3x4nzymm33Q
Part 4: youtu.be/gEPd1ref9s0
Part 5: youtu.be/gNvvZhpYHpw
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
Part 2: youtu.be/gHlundcY9GA
Part 3: youtu.be/3x4nzymm33Q
Part 4: youtu.be/gEPd1ref9s0
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
00:00:10 [PROLOG] nervous_testpilot - Focus | http://nervoustestpilot.co.uk
00:02:17 [PROLOG] nervous_testpilot - Office | http://nervoustestpilot.co.uk
00:08:30 [PROLOG] TheFatRat - Monody (feat. Laura Brehm) | youtube.com/user/ThisIsTheFatRat
00:13:24 [PROLOG] Stellardrone - Between The Rings
00:17:41 ⁂ START ⁂
00:19:00 Announcements
- Today's moderator: foxtrot_charlie | foxtrotlabs.cc
- Paged Out! #2 3rd version released
00:23:16 Let's get started!
00:24:04 Explanation why NewOverFlow-1 (from previous part) took so long
00:25:45 NewOverFlow-2 / bin exp / 250p
+ code review → if you see an unintended bug - just go for it
+ checksec(.sh)
- no stack canary
- NX on
- no PIE
+ RE - disassembler (IDA)
- flag() is there by creator's mistake, but we will ignore it to solve it another (return chaining) way
- we need to jump to win_fn() to win; description says we need to call win1/win2 with specific arguments, but we'll do it another way
- 00:32:24 chaining returns
- constructing the payload (and aligning the stack)
Q: What do you mean by "align the stack"?
Q: What's the topics/ideas for future streams?
Q: Is discrete math important?
Q: Any experience with Intel Pin or DynamoRio? Would You recommend any of them?
Q: How important is data structures / algorithms in InfoSec?
00:52:41 asm2 / reverse eng / 250p
+ this time we'll actually analyze the assembly! (or actually, reimplement it in Python)
+ differences between how Python's ints work and how C/C++/x86 ints work
- need to truncate ints to 32-bits
+ pretty standard approach to reversing - translate to be able to instrument easier
01:07:25 CanaRy / bin exp / 300
+ about stack cookies (paper mentioned: http://vexillium.org/pub/002.html)
+ 01:10:25 analysis of source code and binary
- run checksec(.sh)
* no canary found (i.e. this is a custom canary implementation)
* PIE enabled (we'll have to bypass this)
- in case of forkserver (duplicate process for every new connection) the canary is NOT reset (so it can be leaked byte-by-byte)
- example of how canary works - memcpy() of master cookie (key) to the canary on the beginning of the function; later checked
* if not there is exit(-1) which calls destructors (not to be confused with class destructors), better use _exit() which lead to an exiting syscall
* other bypass techniques
+ conception of attacking canary, same as on fork server - stack canary is secret but constant - we can brute-force values of each byte of canary (00..FF) separately
- oracle: when there is not "smash stack detected" → we guessed that byte correctly
- repeat for next byte, and next, ...
- instead of 2^32 we've done it in 2^10
Q: 01:24:37 What you mean about exit destructors? How can i define one?
+ 01:30:08 back to implementing the exploit
- always check if maybe we can just read the flag on the server due to faulty ACLs or sth (no luck this time)
- figuring out what exactly we need to do
- 1:33:26 writing the exploit and testing it locally
* patch the local binary to change some paths
- 1:43:01 let's do this remotely!
* adding proper shellcode/payload and dealing with ASLR
* ASLR moves memory pages only, so last 3 nibbles (1.5 bytes) are same as in the binary - we need to brute-force 0.5 of a byte
Q :01:48:16 What's the difference of ASLR and PIE?
Q: Can the 64-bit canary be bypassed?
Q: Can you recommend any good source for reversing cryptography?
01:57:03 Investigative Reversing 0 / forensics / 300
+ look at the files in hex editor
+ in IDA we see we understand that binary append some data to the PNG file, the modified bytes from flag file
+ doing basic math on hex in your head
02:05:35 Conclusions and Q&A
Q: In the normal condition is the cookie random?
02:06:54 Epilogue
Thanks for attending folks this year!
Thank you foxtrot_charlie for being my Moderator today!
02:07:35 [EPILOG] nervous_testpilot - Our Heroes | http://nervoustestpilot.co.uk
(kudos to J.V. for ToC!)
Part 1: youtu.be/pYrGJuOUG7M
Part 2: youtu.be/gHlundcY9GA
Part 3: youtu.be/3x4nzymm33Q
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
00:00:14 [PROLOG] nervous_testpilot - Focus | http://nervoustestpilot.co.uk
00:02:16 [PROLOG] TheFatRat - Monody (feat. Laura Brehm) | youtube.com/user/ThisIsTheFatRat
00:07:12 [PROLOG] Stellardrone - Bettween The Rings
00:12:23 ⁂ START ⁂
00:13:30 Announcements
- Today's moderator: foxtrot_charlie | foxtrotlabs.cc
- Paged Out!
00:15:45 Let's get started (with exploitation)
00:17:33 OverFlow 2 / bin exp / 250p
+ BOF in vuln() found; flag() never called.
+ Making the payload
+ It's crashes but output buffering is turned off so we've got the flag
+ We could do some 'brute-force' tries to pwn w/o full knowledge of stack, any debugging etc - this could be faster on a CTF.
00:26:51 We get the flag
Q: Any difference between Windows and Linux chars implementations?
- Not really - char is the same, signed, 1B. Differences are in processing text file, text streams and the functions themselves.
- With regards to 00:20:05 in gets() on Windows more characters are disallowed e.g. ctrl+d (End Of Transmission) (see also: 01:49:47)
Q: Any good tutorials for introduction to IDA?
- No known IDA tutorial, but check out "FAQ: How to learn reverse-engineering?" on my blog
00:32:17 NewOverFlow-1 / bin exp / 200
+ 64-bit are default nowadays
+ Differences between 32-bit and 64-bit exploitation
+ Using objdump this time around: objdump -x and objdump -Mintel -d
+ We try some things, they don't work.
+ 00:56:06 ... as this doesn't work, we go all the way in
- Looking for some machine code with side-effects
* '\xeb\xfe' - infinite loop
* Calls to puts() with buffer
* Jumping to flag() doesn't work - let's jump in the middle of it (it worked).
Q: Could you explain how to exploit global buffer overflow?
Q: Looking into starting with CTFs but I don't actually know exactly where I should start. Do you know any website where I can learn from the ground up?
Q: Did you watch Mr Robot?
Q: You should know the server is running Ubuntu 18.04 it's relevant for this chall.
Q: Would you approach more advanced challs the same way?
Q: In case of passing args to func in 64bit is shellcoding and ROP the only one option?
Q: Any books/tutorials on reverse engineering?
Q: What is the best tutorial for XYZ?
Q: How to get started with exploit development for 21 y.o. guy?
Q: Can we use ROP for all bof vulns?
01:14:51 like1000 / forensics / 250p
+ Started with a simple python script.
+ ...oh gosh! we don't need to process it recursive way - TAR isn't compressed!
Q: Are there any protections against ROP?
Q: Why do you use Windows?
Q: How to become red-teamer or exploit dev?
Q: What if there would be 1000 PNG files in that TAR archive?
+ Shout out to hackvent.hacking-lab.com
01:32:45 vault-door-4 / reverse eng / 250p
+ A print the flag (in a smart way) challenge.
Q: Have you been pwned by phishing?
01:38:26 Irish-Name-Repo 1 / web / 300p
+ Probably SQLi, but first let's analyze the source code of the page.
+ Preparing a very simple injection with tautology (remember about space after double-dash cause some MySQL version need this).
Q: 2FA protects against phishing.
Q: How malware analysis actually work as business model?
Q: Will admin=admin&password='+or+1=1+--+ work?
01:48:23 flag_shop / general skills / 300p
+ Code review in C
+ We found integer overflow: happens in C, in Java, .NET, ActiveStript, not in PHP (overflow? cast to float!), JS (? no integers let's start with floats!), Python (big nums ftw), nice fact that Ada will raise exception when you compile correctly, no idea what in Rust, for C/C++ some libs to deal with it.
+ Check my book (still only in Polish, sorry!) "Zrozumieć programowanie" ch. 4 & 5 for knowledge related with integers and floats. :)
01:58:45 Q: Will be integer overflow could be exploited?
02:02:44 asm1 / reverse eng / 200p
+ We have a disassembly listing of a function (x86-32)
+ To lazy to reverse - let's run it using Asmloader (see my GitHub repository) and get the return value.
- Agner Fog Calling convention guide p. 10 (Table 6 - Register usage) and any other work (which are amazing)
- http://gynvael.vexillium.org/dump/opcodes.txt for cheat-sheet by Sang Cho
- Calling convention @ Wikipedia
02:14:06 Epilog
We've pass -4 challs today. Thanks for attending folks!
Thank you foxtrot_charlie for being my Moderator today!
02:15:11 [EPILOG] nervous_testpilot - Our Heroes | http://nervoustestpilot.co.uk
(kudos to J.V. for ToC!)
Part 1: youtube.com/watch?v=pYrGJuOUG7M
Part 2: youtu.be/gHlundcY9GA
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
00:08 [PROLOG] nervous_testpilot - Focus | http://nervoustestpilot.co.uk
02:15 [PROLOG] TheFatRat - Monody (feat. Laura Brehm) | youtube.com/user/ThisIsTheFatRat
07:06 [PROLOG] Stellardrone - Bettween The Rings
13:20 ⁂ START ⁂ - Greetings
13:45 Short agenda about todays' stream; Q&A rules
14:50 Announcements and hypes
- Today's moderator: foxtrot_charlie | foxtrotlabs.cc
- Paged Out! #2 is out // Call For Papers (one page) until 02/20/2020 (20 Feb 2020);
- 16:21 Authors of articles from 1st rel of Paged Out! who have chosen non-TIP/POOL SAA should receive an email; if not get back to me :)
- I've made one of Winja CTF '18 tasks and now it's released | github.com/google/google-ctf/tree/master/other/re-risky
- It looks like Dec 2018 will be exciting contest between TOP 4 of CTF Time | ctftime.org
19:24 Let's get started!
20:44 2Warm / general / 50pts
22:42 picobrowser / web exp / 200pts
- on page we see that we are not picobrowser so we are going to change User-Agent
- see Dev Tools in web browser, but could be solved in different way, e.g. curl
26:39 Question: Can we use CTFs for prepare for OSCP? Q @ YT chat: are CTFs useful for real life pentesting?
29:03 plumbing / general / 200pts
- netcat + "grep to win" technique which is easy and was described previously
30:11 rsa-pop-quiz / crypto / 200pts
- tools: netcat + Python CLI as helper for calculations
- knowledge: basics of prime numbers and RSA theory
- objectives of this task: get to know with RSA - it's really simple
51:31 slippery-shellcode / bin exp / 200pts
- tools: checksec.sh (checking protection of running binary)
- knowledge: basics of assembly and code review of C-like languages
- objectives of this task: old-school basic exploitation with a NOP sled; 32-bit ELF binary (execute shellcode, get the rid of problem with buffering, have no protections, isn't PIE...)
+ 0:57:44 about shellcodes
+ 1:00:00 writing a shellcode that uses fopen/fgets found in memory at known locations
1:10:42 Q: Do you know what AVX2 is used for in assembly?
- some historical roots of SIMD extensions in Intel CPUs (MMX, SSE, AVX), why was it created, and registers naming (mm0, xmm0, ymm0, zmm0)
- note from viewer: there is JSON parser library that uses vectorized instructions
1:15:16 Q: Check whether it is statically linked on the server also, not just the downloaded version.
- why this should *not* be true for CTFs because of annoying players and what's the difference from not-lab exploitation cases
1:16:40 vault-door-3 / rev eng / 200pts
- reversing Java code
1:27:28 "I'm going to show you another way to do this" :)
- taking a fresh look at the same problem since I got confused by trying to do the reverse mapping in my head on livestream (which I failed hard); so instead, I showed a way to get the mapping to generate itself
1:32:29 Q: What motivates you when doing a hard challenge?
1:34:10 whats-the-difference / general / 200pts
- comparing two binary files with use of python
Q: What about zip() in Python when the length of lists is not equal?
Q: How hard does a challenge have to be to resemble that of a real life scenario in the work force (or as close as it come)?
1:39:58 where-is-the-file / general / 200pts - file starting with .
1:41:20 WhitePages / forensics / 250pts
- three code units: E2 80 83 ... :)
- funky ASCII art or binary ASCII encoding?
- at the end: a note about ASCII and code pages
1:51:03 c0rrupt / forensics / 250pts
1:51:43 In YT chat Daniel mentioned 24/7 CTF challenges (247ctf.com/). Take a look at it - they are really cool!
Returning to task:
- broken PNG file...
- ...but many files are simply based on zlib aka DEFLATE (e.g. ZIP, GZIP, HTTP compression, but also PNG) - we will try to brute force it!
- ...and in the end hack it in GIMP.
2:01:55 Q: With zlib compression, can we decompress even without the beginning of the bytes stream? Or if we have "holes" in the bytes stream?
2:03:55 m00nwalk / forensics / 250pts
- WAV file with 11MB
Please make volume down, because we are m00nwalking with SSTV over the stream sound directly 8)
- from 2:07:00 to 2:07:56
- from 2:09:57 to 2:10:03
- from 2:10:53 to 2:11:33
2:18:17 Q: What did you study in college/University and what certs did you get?
See also (in Polish but Google Translate could do the thing):
- https://gynvael.coldwind.pl/?id=337
- https://gynvael.coldwind.pl/?id=338
2:20:36 Epilog
Thanks for attending folks!
Thank you foxtrot_charlie for being my Moderator today!
Next stream is planned on next Wednesday (part 3).
2:21:06 [EPILOG] nervous_testpilot - Our Heroes | http://nervoustestpilot.co.uk
(kudos to J.V. for ToC!)
Part 1: youtu.be/pYrGJuOUG7M
Our Discord: discord.gg/QAwfE5R
Our IRC: #gynvaelstream-en on freenode
See youtube.com/watch?v=omvRF4H4vjo and a couple of next in sequence archived livestreams for Arcane Sector 1 from 2018.


