<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Emulation on Locus Solus | Nagi's Blog</title><link>https://x-nagi.com/tags/emulation.html</link><description>Recent content in Emulation on Locus Solus | Nagi's Blog</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sun, 10 Oct 2021 22:11:48 +0800</lastBuildDate><atom:link href="https://x-nagi.com/tags/emulation/index.xml" rel="self" type="application/rss+xml"/><item><title>TCTF 2021 0bf: Emulating Obfuscated Code with Unicorn</title><link>https://x-nagi.com/post/tctf-2021-final.html</link><pubDate>Sun, 10 Oct 2021 22:11:48 +0800</pubDate><guid>https://x-nagi.com/post/tctf-2021-final.html</guid><description>&lt;div class="admonition info"&gt;&lt;p class="admonition-title"&gt;Notice&lt;/p&gt;&#10;&lt;p&gt;This article was originally published on Anquanke: &lt;a href="https://www.anquanke.com/post/id/255241"&gt;original article&lt;/a&gt;&lt;/p&gt;&#10;&lt;/div&gt;&#10;&lt;h2 id="introduction"&gt;Introduction&lt;/h2&gt;&#10;&lt;p&gt;With tremendous help from my teammates, we won the Rising Star division of the TCTF 2021 Finals. The challenge from which I learned the most was &lt;code&gt;0bf&lt;/code&gt;, a ten-round cipher hidden beneath extensive code obfuscation. The official post-event solution deobfuscated it first, but during the competition we lacked time to study the obfuscation pattern and had to analyze it directly. This was also my first use of Unicorn to emulate function logic.&lt;/p&gt;</description></item><item><title>An Introduction to Reversing mruby Bytecode</title><link>https://x-nagi.com/post/mruby.html</link><pubDate>Mon, 27 Sep 2021 21:17:11 +0800</pubDate><guid>https://x-nagi.com/post/mruby.html</guid><description>&lt;div class="admonition info"&gt;&lt;p class="admonition-title"&gt;Notice&lt;/p&gt;&#10;&lt;p&gt;This article was originally published on Anquanke: &lt;a href="https://www.anquanke.com/post/id/253572"&gt;original article&lt;/a&gt;&lt;/p&gt;&#10;&lt;/div&gt;&#10;&lt;h1 id="introduction-to-mruby"&gt;Introduction to mruby&lt;/h1&gt;&#10;&lt;p&gt;&lt;a href="https://mruby.org/"&gt;mruby&lt;/a&gt; is a lightweight implementation of Ruby. It works much like CPython: Ruby source is compiled to bytecode, which is then interpreted by a virtual machine.&lt;/p&gt;&#10;&lt;p&gt;I first encountered mruby bytecode in the DEF CON 2021 Finals. The barb-metal challenge used mruby bytecode to run simulated IoT firmware. A few months later, another mruby reversing challenge appeared in the Fifth Space online competition, so I decided to summarize the characteristics of mruby bytecode.&lt;/p&gt;</description></item><item><title>SECCON 2019 Finals Writeup: bad mouse &amp; 四.3</title><link>https://x-nagi.com/post/seccon-2019.html</link><pubDate>Fri, 27 Dec 2019 12:52:57 +0800</pubDate><guid>https://x-nagi.com/post/seccon-2019.html</guid><description>&lt;h1 id="bad-mouse"&gt;bad mouse&lt;/h1&gt;&#10;&lt;p&gt;The challenge provided a small USB circuit board. Once connected, it behaved like an emulated mouse and drew the flag one character at a time. Its drawing speed continually decreased, so it clearly could not finish before the competition ended.&lt;/p&gt;&#10;&lt;p&gt;First convert the supplied firmware to binary with a tool such as &lt;a href="http://hex2bin.sourceforge.net/"&gt;hex2bin&lt;/a&gt;. Open it in IDA, select Atmel AVR as the processor and ATmega32 (or another suitable model) as the device, and the firmware can be disassembled.&lt;/p&gt;</description></item></channel></rss>