Arctic

Tuesday, May 30, 2023

ASIS CTF Quals 2015 - Sawthis Writeup - Srand Remote Prediction


The remote service ask for a name, if you send more than 64 bytes, a memory leak happens.
The buffer next to the name's is the first random value used to init the srand()


If we get this value, and set our local srand([leaked] ^ [luckyNumber]) we will be able to predict the following randoms and win the game, but we have to see few details more ;)

The function used to read the input until the byte \n appears, but also up to 64 bytes, if we trigger this second condition there is not 0x00 and the print shows the random buffer :)

The nickname buffer:



The seed buffer:



So here it is clear, but let's see that the random values are computed with several gpu instructions which are decompiled incorrectly:







We tried to predict the random and aply the gpu divisions without luck :(



There was a missing detail in this predcitor, but there are always other creative ways to do the things.
We use the local software as a predictor, we inject the leaked seed on the local binary of the remote server and got a perfect syncronization, predicting the remote random values:




The process is a bit ugly becouse we combined automated process of leak exctraction and socket interactive mode, with the manual gdb macro.




The macro:



















Read more


  1. Hack Tools For Pc
  2. Hack Tools 2019
  3. Pentest Tools Framework
  4. Hacking Tools For Mac
  5. Hacking Tools Mac
  6. Hack Tools For Games
  7. Hacker
  8. Hacking Tools Mac
  9. Game Hacking
  10. Github Hacking Tools
  11. Growth Hacker Tools
  12. Hacking Tools Windows 10
  13. Hack App
  14. Hacking Tools Windows
  15. Pentest Tools Port Scanner
  16. Hacker Tools For Ios
  17. Free Pentest Tools For Windows
  18. Android Hack Tools Github
  19. Pentest Tools For Mac
  20. Hacker Tools For Mac
  21. Nsa Hack Tools Download
  22. Hack Tools Download
  23. Hacker Tools Apk
  24. Hacking App
  25. Pentest Tools Review
  26. Pentest Tools Port Scanner
  27. Wifi Hacker Tools For Windows
  28. Hacker Tools Apk Download
  29. Nsa Hack Tools Download
  30. What Is Hacking Tools
  31. Hacking Tools For Games
  32. Pentest Tools List
  33. Pentest Recon Tools
  34. Best Pentesting Tools 2018
  35. How To Install Pentest Tools In Ubuntu
  36. Hack Apps
  37. What Are Hacking Tools
  38. Hack Tools Pc
  39. Growth Hacker Tools
  40. Best Hacking Tools 2020
  41. Tools Used For Hacking
  42. Hacking Tools 2020
  43. Underground Hacker Sites
  44. Pentest Tools Alternative
  45. Pentest Tools Url Fuzzer
  46. Hacking Tools For Windows Free Download
  47. Pentest Tools Review
  48. Hacking Tools Name
  49. Hacking Tools Github
  50. Hacker Tools Github
  51. How To Make Hacking Tools
  52. Black Hat Hacker Tools
  53. Install Pentest Tools Ubuntu
  54. Hacking Tools
  55. Hacking Tools For Kali Linux
  56. Hacking Tools
  57. Hacking Tools Github
  58. Hackrf Tools
  59. Hacking Tools 2019
  60. Nsa Hacker Tools
  61. Bluetooth Hacking Tools Kali
  62. Hacker Tools Software
  63. Pentest Reporting Tools
  64. Hacking Tools For Windows 7
  65. Hack Apps
  66. Game Hacking
  67. Github Hacking Tools
  68. Nsa Hack Tools
  69. Pentest Tools List
  70. Physical Pentest Tools
  71. Ethical Hacker Tools
  72. New Hack Tools
  73. Pentest Tools Find Subdomains
  74. Hacker Tools Hardware
  75. Pentest Tools Bluekeep
  76. Hackrf Tools
  77. Hack Tools Pc
  78. Pentest Tools Android
  79. Hacking Tools Usb
  80. Pentest Tools Find Subdomains
  81. Pentest Tools Online
  82. Pentest Tools Kali Linux
  83. Pentest Tools Website
  84. Nsa Hack Tools
  85. Hacking Tools Usb
  86. Hackrf Tools
  87. Pentest Tools Tcp Port Scanner
  88. Pentest Tools Framework
  89. Pentest Tools Nmap
  90. Hak5 Tools
  91. Pentest Tools Apk
  92. Hacking Tools For Games
  93. Pentest Tools Subdomain
  94. Hack Rom Tools
  95. Github Hacking Tools
  96. How To Make Hacking Tools
  97. Best Hacking Tools 2019
  98. Hacking Apps
  99. Hack Tools Download
  100. Hack Tools
  101. Hacking Tools Windows 10
  102. Growth Hacker Tools
  103. Hacker Tools Hardware
  104. Pentest Tools Tcp Port Scanner
  105. Hacker Tools List
  106. Hacking Tools And Software
  107. Pentest Tools Find Subdomains
  108. Wifi Hacker Tools For Windows
  109. Hacker Tools Apk Download
  110. What Are Hacking Tools
  111. Hak5 Tools
  112. Hacking Tools For Games
  113. Pentest Tools Github
  114. Pentest Tools Nmap
  115. Hacking App
  116. Pentest Tools For Android
  117. Physical Pentest Tools
  118. Pentest Tools Alternative
  119. Pentest Recon Tools
  120. Computer Hacker
  121. Free Pentest Tools For Windows
  122. Pentest Tools Kali Linux
  123. Hacker Tools For Windows
  124. Hacker Tools
  125. Hack Tools
  126. Hacking Tools 2019
  127. Hack Tool Apk
  128. Hacking Tools Download
  129. Pentest Tools Website Vulnerability
  130. Nsa Hack Tools
  131. Pentest Tools List
  132. Hack Rom Tools
  133. Hack Tools For Mac
  134. Hacker Tools Free Download
  135. Pentest Reporting Tools
  136. Pentest Recon Tools
  137. Hacker Tools Free Download
  138. Termux Hacking Tools 2019
  139. Bluetooth Hacking Tools Kali
  140. Computer Hacker
  141. Termux Hacking Tools 2019
  142. Pentest Tools Review
  143. Pentest Tools Url Fuzzer
  144. Hacking Tools Name
  145. Pentest Tools Github
  146. Nsa Hack Tools Download
  147. Pentest Tools Kali Linux
  148. Hacking Tools Online
  149. Pentest Box Tools Download

0 Comments:

Post a Comment

Subscribe to Post Comments [Atom]



<< Home