KOrUPt

June 21, 2009

Defcon CTF 2009 Potent Pwnable’s 200 write up

Filed under: General, Reversing — Tags: , , , , , , , , , , , — KOrUPt @ 13:47

Okay so ADC was nice to enough to do a write up for the Potent Pwnable’s 200 challenge…

During the qualification round I took a brief look over this challenge and was able to locate the upload scripts and made a note of the SQL commands contained within the files you could download(once they were unpacked)… However I got sidetracked with Binary Analysis so I left this challenge to my team, unfortunately we didn’t solve it… Which makes this write up all the more interesting :) .

As usual you can find it over at Pastie:

http://pastie.org/505249.txt

I’ll have it mirrored locally in a few days.

Nice work Adc! I’m about to read over it now ;) .

KOrUPt.

June 17, 2009

Defcon CTF 2009 Trivia 400 write up

Filed under: General, Reversing — Tags: , , , , , , , , , , , , , , — KOrUPt @ 18:12

Seems someone took the time to do a write up for this years Defcon Trivial Pursuits 400 challenge :D .

Let me start by saying me nor my team take any credit for this write up, it’s unclear as to who the author is but my guess is ADC of Loller Skaters produced it? Please correct me if I’m wrong in this assumption.

The write up can be found over at Pastie:

http://pastie.org/510841

I’ve also mirrored it locally just incase, it can be found here:

http://korupt.co.uk/defcon/T400Writeup.txt

I strongly recommend you view the above write up within a web browser(preferably Firefox).

To the author of the above guide, very nice work :) . My team and I didn’t manage to solve the T400 challenge during the qualification round. If you’d like me to update the above links please leave a comment and I’ll do so at the earliest opertunity.

KOrUPt ~ Sapheads.

June 14, 2009

Haha’s Defcon Crypto Badness 400 write up…

Filed under: General, Reversing — Tags: , , , , , , , , , , , , , — KOrUPt @ 00:20

Just thought I’d bring this to your attention :)

For those interested in solving the Crypto Badness 400 challenge of the Defcon quals…
Hahah did a very good write up, which can be found at:

http://beist.org/defcon2009/defcon2009_crypto400_solution.txt

Good work Hahah, looking forward to any others you may do :) .

Thanks to T1g3r for bringing the article to my attention :p.

Enjoy!

KOrUPt.

Edit: Author updated.

June 12, 2009

Defcon CTF 09 Quals…

Filed under: General — Tags: , , , , , , , , , , , — KOrUPt @ 23:55

Okay so recently I said I’d post my views regarding my experience at this years Defcon CTF qualifications…

This year we put forward a new and considerably stronger team than last year and we decided to go by the name of “Sapheads”, for those wondering, the definition of a “saphead” is an “idiot”, this name was chosen out of comedic value with [I assume] the intention of having a touch of irony to it… Similar to Lastplace, who tend to end up in first place ;) (props @tlas and co ;) ).

In fact, our team this year is the combined force of three of last years teams…

We finished 11th,  after 48 hours of what seemed to be near non-stop analysis, I got a passive 4 hours sleep during that period.

Our final result I think goes to show just how important it is to be well prepared, organized and to communicate correctly. Our team members excelled themselves and without the collaboration between us I doubt we’d of done as well as we did…

Binary Leetness 400 is a prime example of this, I served as my teams binary analyst. 85MB’s of JPEG’s… To a binary analyst, that doesn’t mean much… Though I was able to put together some of the puzzle. After handing the file down to our teams forensics expert, he eventually came back to us with an executable which I was able to provide an analysis of… That said, without his efforts, we wouldn’t have solved the challenge.

During the qualification rounds, good resource utilization is also helpful… Thinking about it, I did initially intend to stock 20 or so energy drinks, don’t know what happened to that plan though.

I think most of our team this year were a bit apprehensive once they’d learned that Kenshoto had stepped down and Ddtek opted to fill their shoes(props to you guys!)… I know I was! None of us were sure what to expect this year.

My initial impression wasn’t a very good one, the scoreboard was very slow to begin with and some of the services were periodically updated which threw a few of us off during mid-analysis. However, I have to admit the Ddtek crew did a very very good job to resolve the issues at hand, after a while things where once again bearable and all went well. I think I speak for everyone when I say we all had a great time!

Our team did solve all of the Binary Leetness challenges, which is something I’m proud of. We’ll be doing write up’s soon, as it stands I’ve already done a write up for the Binary Leetness 300 challenge, which can be found via a quick search.

Currently we intend to solve some of the challenges we weren’t able to solve during the qualification rounds and hopefully do write up’s of their solutions.

That said, I’m just one side of this team, you can find the rest of us over at http://www.sapheads.org, I’ll be mirroring most of the content here over there, with the intention of having a more centralized source of information for you all :) . I hope you all drop by sometime ;) .

I’d like to conclude this post by extending a very big thank you to the ddtek team, and of course Kenshoto, who also put on a very good game over the years.

To my team, very good job, we will only continue to get stronger ;) .

DDTek, best of luck handling the CTF at Defcon, I’m sure you’ll do well… P.S Mars, let me know how it goes if possible :) .

That just about wraps this article up for now I think… At this rate I’ll have to make a category specifically for Defcon related content :D .

References:

http://www.sapheads.org/ < our team.

http://ddtek.biz/ < this years ctf organizers.

http://shallweplayaga.me/ < VedaGodz.

http://brycekerley.net/blog/2009/06/trivia300.html < Bryce’s T300 solution.

Signing off.

~ KOrUPt.

June 11, 2009

Defcon CTF 2009 Binary Leetness 300

Filed under: General, Reversing — Tags: , , , , , , , , , , , — KOrUPt @ 00:56

Well, the Defcon CTF 2009 qualifications are over… I’ve decided to do a write up for the Binary Leetness 300 challenge :) .

Feedback appreciated!

Note: your anti-virus may detect the below archive as infected, it contains the b300 binary, which is packed. This is a false positive, I recommend you disable your AV.

http://korupt.co.uk/defcon/B300Writeup.rar

I’ll be posting a more in-depth overview of my experience at the quals shortly.

Enjoy!

KOrUPt ~ Sapheads.org.

Powered by WordPress