IERAE CTF had one of the coolest pwn challenges I've done in the while. It was written by hugeh0ge.
Here's the full source:
// gcc chal.c -fno-stack-protector -static -o chal
#include <stdio.h>
#include | // color1 and color2 are R4G4B4 12bit RGB color values, alpha is 0-255 | |
| uint16_t blend_12bit( uint16_t color1, uint16_t color2, uint8_t alpha ) { | |
| uint64_t c1 = (uint64_t) color1; | |
| uint64_t c2 = (uint64_t) color2; | |
| uint64_t a = (uint64_t)( alpha >> 4 ); | |
| // bit magic to alpha blend R G B with single mul | |
| c1 = ( c1 | ( c1 << 12 ) ) & 0x0f0f0f; | |
| c2 = ( c2 | ( c2 << 12 ) ) & 0x0f0f0f; | |
| uint32_t o = ( ( ( ( c2 - c1 ) * a ) >> 4 ) + c1 ) & 0x0f0f0f; |
| // | |
| // ViewController.m | |
| // JBDetectTest | |
| // | |
| // Created by seo on 3/27/25. | |
| // | |
| #import "ViewController.h" | |
| #import <dlfcn.h> |
| S3_3_c4_c5_0 at min EL0: DSPSR | |
| S3_3_c4_c5_1 at min EL0: DLR | |
| S3_6_c4_c0_0 at min EL3: SPSR_EL3 | |
| S3_6_c4_c0_1 at min EL3: ELR_EL3 | |
| S3_1_c0_c0_0 at min EL1: CCSIDR_EL1 | |
| S3_6_c1_c0_0 at min EL3: SCTLR_EL3 | |
| S3_6_c1_c0_1 at min EL3: ACTLR_EL3 | |
| S3_6_c1_c1_2 at min EL3: CPTR_EL3 | |
| S3_6_c1_c1_0 at min EL3: SCR_EL3 | |
| S3_6_c1_c3_1 at min EL3: MDCR_EL3 |
IERAE CTF had one of the coolest pwn challenges I've done in the while. It was written by hugeh0ge.
Here's the full source:
// gcc chal.c -fno-stack-protector -static -o chal
#include <stdio.h>
#include | #!/bin/bash | |
| # Run the lsregister command and store the output in a variable | |
| output=$(/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister -dump) | |
| # Use awk to parse the relevant sections | |
| echo "$output" | awk ' | |
| # When "CFBundleDisplayName" is found, store the app name | |
| /CFBundleDisplayName/ { | |
| app_name = substr($0, index($0, "=") + 2) |
| # Download and install Git for Windows if not already installed | |
| if (-not (Test-Path "C:\Program Files\Git\bin\git.exe")) { | |
| Write-Host "Git for Windows not found. Downloading installer..." | |
| Invoke-WebRequest -Uri "https://github.com/git-for-windows/git/releases/download/v2.31.1.windows.1/Git-2.31.1-64-bit.exe" -OutFile "git-installer.exe" | |
| Write-Host "Installing Git for Windows..." | |
| Start-Process -FilePath ".\git-installer.exe" -ArgumentList "/VERYSILENT" -Wait | |
| Remove-Item ".\git-installer.exe" | |
| } | |
| # Create a temporary directory for downloads |
| #include <stdint.h> | |
| #include <stdio.h> | |
| #include <stdlib.h> | |
| #include <stdbool.h> | |
| #include <windows.h> | |
| #include "nt_crap.h" | |
| #define ArrayCount(arr) (sizeof(arr)/sizeof(arr[0])) | |
| #define assert(expr) if(!(expr)) { *(char*)0 = 0; } |
| """ | |
| 31-round sha256 collision. | |
| Not my research, just a PoC script I put together with numbers plugged in from the slide at | |
| https://twitter.com/jedisct1/status/1772647350554464448 from FSE2024 | |
| SHA256 impl follows FIPS 180-4 | |
| https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf | |
| """ |
| ### Test on https://github.com/yousseb/meld/releases/tag/osx-20 | |
| ### OSX - 3.21.0 (r4) Sonoma | |
| ### !!! Note: You need put the Meld.app r4 build to the /Applications path first. | |
| #!/bin/zsh | |
| #Fix libpng16.16.dylib not found | |
| install_name_tool -change /usr/local/opt/libpng/lib/libpng16.16.dylib @executable_path/../Frameworks/libpng16.16.dylib /Applications/Meld.app/Contents/Frameworks/libfreetype.6.20.0.dylib | |
| #Fix libbrotlidec.1.dylib not found |