CSAW 2011 - Reversing - Python 200

Python - 200 Points nc csawctf.poly.edu 53080 When we connected to the port it was running a service Haderper: ----------------------------- | Welcome to Haderper! | | Please enter your command | ----------------------------- > help Haderper v0.1-alpha Command help: help - this screen exec - execute a command derp - derp a string underp - underp a string logout/exit - disconnect > derp hi UydoaScKcDAKLg== > underp UydoaScKcDAKLg== hi > If we decode the base64 string we can see that it looks like a Pickle dump file: ...

September 26, 2011 · 2 min

Hack.lu 2011 CTF – Python Crackme Solution

Python Crackme This challenge’s hero, needs your help. Sadly, our Commander Sheen has lost his Pogo Stick. Without his Pogo Stick, Commander Sheen is not WINNING. Can you help him? Solve the puzzle and find out what space-tool could support him. download After downloading the mentioned file, we can see it is a pyc file which can be run with python2.7, using the script provided here to review the structure of pyc files (if you are using 64 bits python make sure to change struct.unpack(‘L’, moddate)[0]) to struct.unpack(’<L’, moddate)[0]) to get it working.) we could see some stuff like how many arguments it required to run: ...

September 22, 2011 · 3 min

Hack.lu 2011 CTF - Scotty's last signal Solution

Challenge summary: Scotty’s last signal You might have heard about Montgomery Scott, the legendary chief engineer of the U.S.S. Enterprise. What you probably did not know is his passion for Video Games - especially really old classics. We recently lost contact with his transport shuttle and we think you should examine this old game file we recently recieved because he might have just put a message into there. This would make sense if he could not send a fully blown Space-Unicode message signal to avoid attracting any Borg ships in the sector… (Borg usually are very bad at video games) His passion for Beaming and Warping might be of interest for your analysis. https://ctf.hack.lu/files/mario ...

September 21, 2011 · 2 min

Campus Party Valencia 2011 - Premio ESET

Esta publicación la tenia pendiente hace casi un mes, desde que recibí el premio entregado por ESET a nuestro equipo NULL Life por haber logrado finalizar de primeros el WGSBD2 organizado para Campus Party España. Ya se ha publicado una recopilación de las soluciones WGSBD2 para los que esten interesados. Las categorias del wargame fueron las siguientes: Trivial Networking Binarios Crypto Web Agradecimientos a Security By Default por un excelente Wargame, a Campus Party España, y por ultimo, pero no menos importante, ESET por patrocinar este tipo de eventos. Sin más preambulo el unboxing del premio, una Macbook Pro 15" (con ESET Cybersecurity) otorgada por ESET. ...

September 15, 2011 · 1 min

iPhone 3G - Reparar error 1015 al actualizar a iOS 4.2.1

Advertencia: No me hago responsable de cualquier daño que pueda ocurrir. El proceso que documento en la siguiente entrada es el que me funciono a mi. Específicamente, el teléfono que se reparo fue un iPhone 3G, con baseband 06.10.00, este procedimiento ni el firmware que se proporciona funcionará en otros modelos. Primero intentare explicar porque se produce este error, muy seguramente tu telefono para poder liberarlo del Carrier Lock (abrirle las bandas, liberar la sim para que acepte otros operadores) la persona que lo liberó instalo el baseband 06.10.00 para iPad en su teléfono, y luego usó la herramienta ultrasn0w. ...

August 28, 2011 · 2 min

WGSBD2 - Campus Party Valencia 2011

Nuestro equipo NULL Life participó en el CTF de SecurityByDefault.com y logró finalizar de primero todos los retos, ademas de obtener el primer lugar por puntos al finalizar el evento :D Los miembros del equipo que participaron Daniel (Colombia), g30rg3_x (Mexico), g05u (Perú), emyei (Argentina), Perverths0 (Perú) y snr33 (Perú). Brillo por su ausencia nuestro CISSP, CEH fataku por motivos de su trabajo, o eso dice el xD Por cierto, esta entrada va desde el iPad obtenida en el CTF de Campus Party Colombia, me la entregaron el dia de ayer, y ya le estamos dando un buen uso. Este ha sido un buen año para NULL Life :D ...

July 17, 2011 · 1 min

CTF Campus Party 2011 Colombia

Este año representé a NULL-Life en el CTF de Campus Party Colombia, logré obtener el primer lugar, el premio fue un magico iPad 2 :D (que aún no me han entregado, pero la paciencia es la virtud de todo pentester). Les dejo el writeup para que vean la dificultad y solucion de todos los retos. La próxima semana viene el CTF de Campus Party Valencia, en el cual podremos participar como equipo :D ...

July 8, 2011 · 1 min

PlaidCTF 2011 - Division is HARD!!

Esta vez participamos en el PlaidCTF, organizado por el Plaid Parlament of Pwning. Muchos retos, casi 40 para resolverlos en 2 dias, y con una dificultad considerable. Obtuvimos la posicion numero 42 con NULL Life, aunque nos faltaba un miembro importante del equipo. Nos ubicamos por encima de los otros equipos Colombianos, el ultimo dia del ctf el equipo RICTeam nos logro empatar, pero teniamos un As bajo la manga y los pudimos dejar abajo faltando 5 minutos para terminar el CTF cuando ya poco podian hacer. Pueden ver la tabla de posiciones completa en el sitio de plaidctf. ...

April 28, 2011 · 2 min

Firefox 3.6.19 Remote Code Execution

To be disclosed soon.

April 15, 2011 · 1 min

Nuit Du Hack 2011 Prequals

Nuestro equipo NULL Life participó hace un par de semanas en los prequal de CTF Nuit Du Hack. Logramos finalizar en la posición número 12. Este es el ranking final de los prequals: Entre los equipos que conozco de este top, esta el equipo fail0verflow, es el grupo que encontró la falla de criptografía en el PS3 :D! holy cactus son los mismos de int3pids, Leet More, smoked chicken y Rdot.Org equipos rusos con bastante potencial. ...

April 11, 2011 · 1 min