Skip to content

Tag: linux

NcN 2013 CTF canada write up

In this post I will cover the second binary challenge of the No Con Name 2013 CTF driven by the Facebook security team. The binary is available here

This binary challenge is based on a i386 stripped elf file which prompts for a flag:

$ file ./howtobasic
./howtobasic: ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, for GNU/Linux 2.6.26, BuildID[sha1]=4f288f1a66ad673dc50b51c7e85635358bb11da0, stripped
$ ./howtobasic
Facebook CTF
Enter flag: asdasdasdasd
Sorry, that is not correct.
$ 

NcN 2013 CTF australia bin write up

In this post I will cover the first binary challenge of the No Con Name 2013 CTF driven by the Facebook security team. The binary is available here

This binary challenge is based on a i386 elf file which prompts for a flag:

$ file ./derp 
./derp: ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, for GNU/Linux 2.6.26, BuildID[sha1]=b77361bfdab4b30a5ed258ee173fe306184a4438, not stripped
$ ./derp 
Facebook CTF
Enter flag: asdasdasdasd
Sorry, that is not correct.
$ 

Hacking the AR-DRONE Parrot

In this post I will talk about the AR-Drone Parrot.
These user-controlled helicopters are getting very popular, and a lot of people are using them in city parks and gardens.

Time ago, a friend told me he had bought one of this helicopters, so I meet him and his toy to perform some investigations. I now these is nothing new, and very good presentations does exist regarding UAVs (check rootedCon 2012 presentation by Hugo Teso), but is the first time I see this kind of drone in the Real-World 😀

First to be said, this drones can be controlled with an iPhone app via open wireless connection, so evil things can happend meanwhile the drone is operated by an legitime user ]:-)

PF_RING + intel igb + snort + DAQ on debian

In this article, I’m going to resume the steps to have a full packet capture solution with snort IDS and Intel NIC’s.

This solutions is based on Luca Deri’s software PF_RING, a new type of socket to exploit the capabilities of packet capture and snort.

We will follow these steps

  1. Download and compile PF_RING
  2. Compile the PF_RING aware network driver
  3. Compile the libpcap
  4. Download and compile DAQ
  5. Compile PF_RING DAQ module
  6. Download and compile snort agains DAQ

bypassing devmem_is_allowed with kernel probes

In this article I’m going to illustrate how to read the full content of /dev/mem on linux 3.x machines. I will bypass the function devmem_is_allowed with a kernel return probe.

The kernel probes is a kernel component designed for kernel developers to debug the system internals.It can dynamically break into any kernel routine and modify the function’s behavour. This proves had been heavily since yeah by kernel developers. RedHat has build an user interface to kprobes called SystemTap
You can find kprobes’ documentation in Documentation/kprobes.txt. You should also download the article example files kprobe.tgz