Defcon 2015 Coding Skillz 1 Writeup

Just connecting to the service, a 64bit cpu registers dump is received, and so does several binary code as you can see:



The registers represent an initial cpu state, and we have to reply with the registers result of the binary code execution. This must be automated becouse of the 10 seconds server socket timeout.

The exploit is quite simple, we have to set the cpu registers to this values, execute the code and get resulting registers.

In python we created two structures for the initial state and the ending state.

cpuRegs = {'rax':'','rbx':'','rcx':'','rdx':'','rsi':'','rdi':'','r8':'','r9':'','r10':'','r11':'','r12':'','r13':'','r14':'','r15':''}
finalRegs = {'rax':'','rbx':'','rcx':'','rdx':'','rsi':'','rdi':'','r8':'','r9':'','r10':'','r11':'','r12':'','r13':'','r14':'','r15':''}

We inject at the beginning several movs for setting the initial state:

for r in cpuRegs.keys():
    code.append('mov %s, %s' % (r, cpuRegs[r]))

The 64bit compilation of the movs and the binary code, but changing the last ret instruction by a sigtrap "int 3"
We compile with nasm in this way:

os.popen('nasm -f elf64 code.asm')
os.popen('ld -o code code.o ')

And use GDB to execute the code until the sigtrap, and then get the registers

fd = os.popen("gdb code -ex 'r' -ex 'i r' -ex 'quit'",'r')
for l in fd.readlines():
    for x in finalRegs.keys():
           ...

We just parse the registers and send the to the server in the same format, and got the key.


The code:

from libcookie import *
from asm import *
import os
import sys

host = 'catwestern_631d7907670909fc4df2defc13f2057c.quals.shallweplayaga.me'
port = 9999

cpuRegs = {'rax':'','rbx':'','rcx':'','rdx':'','rsi':'','rdi':'','r8':'','r9':'','r10':'','r11':'','r12':'','r13':'','r14':'','r15':''}
finalRegs = {'rax':'','rbx':'','rcx':'','rdx':'','rsi':'','rdi':'','r8':'','r9':'','r10':'','r11':'','r12':'','r13':'','r14':'','r15':''}
fregs = 15

s = Sock(TCP)
s.timeout = 999
s.connect(host,port)

data = s.readUntil('bytes:')


#data = s.read(sz)
#data = s.readAll()

sz = 0

for r in data.split('\n'):
    for rk in cpuRegs.keys():
        if r.startswith(rk):
            cpuRegs[rk] = r.split('=')[1]

    if 'bytes' in r:
        sz = int(r.split(' ')[3])



binary = data[-sz:]
code = []

print '[',binary,']'
print 'given size:',sz,'bin size:',len(binary)        
print cpuRegs


for r in cpuRegs.keys():
    code.append('mov %s, %s' % (r, cpuRegs[r]))


#print code

fd = open('code.asm','w')
fd.write('\n'.join(code)+'\n')
fd.close()
Capstone().dump('x86','64',binary,'code.asm')

print 'Compilando ...'
os.popen('nasm -f elf64 code.asm')
os.popen('ld -o code code.o ')

print 'Ejecutando ...'
fd = os.popen("gdb code -ex 'r' -ex 'i r' -ex 'quit'",'r')
for l in fd.readlines():
    for x in finalRegs.keys():
        if x in l:
            l = l.replace('\t',' ')
            try:
                i = 12
                spl = l.split(' ')
                if spl[i] == '':
                    i+=1
                print 'reg: ',x
                finalRegs[x] = l.split(' ')[i].split('\t')[0]
            except:
                print 'err: '+l
            fregs -= 1
            if fregs == 0:
                #print 'sending regs ...'
                #print finalRegs
                
                buff = []
                for k in finalRegs.keys():
                    buff.append('%s=%s' % (k,finalRegs[k]))


                print '\n'.join(buff)+'\n'

                print s.readAll()
                s.write('\n'.join(buff)+'\n\n\n')
                print 'waiting flag ....'
                print s.readAll()

                print '----- yeah? -----'
                s.close()
                



fd.close()
s.close()





Related posts


  1. Hacker Hardware Tools
  2. Hacking Tools For Windows Free Download
  3. Top Pentest Tools
  4. Hacking Tools For Windows
  5. Beginner Hacker Tools
  6. Hack Tools For Pc
  7. Blackhat Hacker Tools
  8. Hack Website Online Tool
  9. Hacking Tools For Mac
  10. Hacker Tools 2019
  11. Hack Tools Github
  12. Wifi Hacker Tools For Windows
  13. Pentest Tools Linux
  14. Hacking Tools For Windows
  15. Nsa Hacker Tools
  16. Hack Tools Mac
  17. Hack Tools Github
  18. Hack Tools
  19. Hacking Tools For Mac
  20. Hack Tools Online
  21. New Hacker Tools
  22. Pentest Automation Tools
  23. Hacker Tools Software
  24. Hack Apps
  25. Hak5 Tools
  26. Usb Pentest Tools
  27. Wifi Hacker Tools For Windows
  28. Growth Hacker Tools
  29. Pentest Tools Tcp Port Scanner
  30. Hacker Tools Hardware
  31. Nsa Hack Tools
  32. Pentest Tools Bluekeep
  33. Hacking Tools Software
  34. Hacking Tools Kit
  35. Hacking Tools Kit
  36. Hacker Techniques Tools And Incident Handling
  37. Hacker Tools 2020
  38. Hacker Tools Windows
  39. Bluetooth Hacking Tools Kali
  40. Hacker Tools Windows
  41. Ethical Hacker Tools
  42. Hackrf Tools
  43. Hacking Tools Hardware
  44. Hacker Tools Free Download
  45. Game Hacking
  46. Hacking Tools For Windows
  47. Hacking Tools Online
  48. Hacking Tools For Beginners
  49. What Is Hacking Tools
  50. Hacker Tool Kit
  51. Tools Used For Hacking
  52. Tools 4 Hack
  53. Pentest Tools Github
  54. Hacking Tools Online
  55. Hacking Tools Software
  56. Hack Tool Apk No Root
  57. Hacking Apps
  58. Pentest Recon Tools
  59. Pentest Tools Review
  60. Pentest Tools For Android
  61. Pentest Tools Bluekeep
  62. Pentest Tools For Mac
  63. Hacking Tools For Mac
  64. Hacker Search Tools
  65. Hack Tool Apk No Root
  66. Hacking Tools Windows 10
  67. Hacking Tools For Mac
  68. Black Hat Hacker Tools
  69. Hacker Tools For Mac
  70. Tools Used For Hacking
  71. Pentest Tools Github
  72. Hack Tools Online
  73. Hacking Tools Online
  74. Hacker
  75. World No 1 Hacker Software
  76. Hacking Tools Github
  77. Hack Tool Apk

Komentar