<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Reverse Engineering on Locus Solus | Nagi's Blog</title><link>https://x-nagi.com/tags/reverse-engineering.html</link><description>Recent content in Reverse Engineering on Locus Solus | Nagi's Blog</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Mon, 06 Jun 2022 01:34:24 -0400</lastBuildDate><atom:link href="https://x-nagi.com/tags/reverse-engineering/index.xml" rel="self" type="application/rss+xml"/><item><title>Fixing A Rust Binary (Hack-A-Sat 2022 Once Unop a Djikstar)</title><link>https://x-nagi.com/post/has2022-rust-patching.html</link><pubDate>Mon, 06 Jun 2022 01:34:24 -0400</pubDate><guid>https://x-nagi.com/post/has2022-rust-patching.html</guid><description>&lt;h2 id="description"&gt;Description&lt;/h2&gt;&#10;&lt;p&gt;&lt;a href="https://x-nagi.com/file/challenge.tar.gz"&gt;My Challenge File Archive&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;The challenge is a Dijkstra algorithm problem. We are given 3 CSV files which contain distances between the stars, and we are asked to find a path from our ship “ShippyMcShipFace” to the destination “Honolulu”. Normal Dijkstra seems not to work on this challenge; perhaps the cost is not simply the sum of all distances.&lt;/p&gt;</description></item><item><title>Introduction to Intel AES-NI</title><link>https://x-nagi.com/post/aesni.html</link><pubDate>Mon, 22 Nov 2021 11:01:50 +0800</pubDate><guid>https://x-nagi.com/post/aesni.html</guid><description>&lt;div class="admonition info"&gt;&lt;p class="admonition-title"&gt;Notice&lt;/p&gt;&#10;&lt;p&gt;This article was originally published on Anquanke: &lt;a href="https://www.anquanke.com/post/id/260323"&gt;original article&lt;/a&gt;&lt;/p&gt;&#10;&lt;/div&gt;&#10;&lt;p&gt;&lt;a href="https://en.wikipedia.org/wiki/AES_instruction_set"&gt;AES-NI&lt;/a&gt; is Intel&amp;rsquo;s x86-64 SIMD extension for accelerating &lt;a href="https://en.wikipedia.org/wiki/Advanced_Encryption_Standard"&gt;AES&lt;/a&gt;. Anyone familiar with &lt;a href="https://en.wikipedia.org/wiki/SIMD"&gt;SIMD&lt;/a&gt; probably knows it exists, but AES&amp;rsquo;s asymmetric structure and AES-NI&amp;rsquo;s unusual design require considerable detail and theory to use correctly. Using &lt;code&gt;easyRE&lt;/code&gt; from &lt;a href="https://ctf2021.nu1l.com/"&gt;N1CTF 2021&lt;/a&gt; as an example, this article summarizes my understanding; corrections are welcome.&lt;/p&gt;</description></item><item><title>TCTF 2021 0bf: Emulating Obfuscated Code with Unicorn</title><link>https://x-nagi.com/post/tctf-2021-final.html</link><pubDate>Sun, 10 Oct 2021 22:11:48 +0800</pubDate><guid>https://x-nagi.com/post/tctf-2021-final.html</guid><description>&lt;div class="admonition info"&gt;&lt;p class="admonition-title"&gt;Notice&lt;/p&gt;&#10;&lt;p&gt;This article was originally published on Anquanke: &lt;a href="https://www.anquanke.com/post/id/255241"&gt;original article&lt;/a&gt;&lt;/p&gt;&#10;&lt;/div&gt;&#10;&lt;h2 id="introduction"&gt;Introduction&lt;/h2&gt;&#10;&lt;p&gt;With tremendous help from my teammates, we won the Rising Star division of the TCTF 2021 Finals. The challenge from which I learned the most was &lt;code&gt;0bf&lt;/code&gt;, a ten-round cipher hidden beneath extensive code obfuscation. The official post-event solution deobfuscated it first, but during the competition we lacked time to study the obfuscation pattern and had to analyze it directly. This was also my first use of Unicorn to emulate function logic.&lt;/p&gt;</description></item><item><title>An Introduction to Reversing mruby Bytecode</title><link>https://x-nagi.com/post/mruby.html</link><pubDate>Mon, 27 Sep 2021 21:17:11 +0800</pubDate><guid>https://x-nagi.com/post/mruby.html</guid><description>&lt;div class="admonition info"&gt;&lt;p class="admonition-title"&gt;Notice&lt;/p&gt;&#10;&lt;p&gt;This article was originally published on Anquanke: &lt;a href="https://www.anquanke.com/post/id/253572"&gt;original article&lt;/a&gt;&lt;/p&gt;&#10;&lt;/div&gt;&#10;&lt;h1 id="introduction-to-mruby"&gt;Introduction to mruby&lt;/h1&gt;&#10;&lt;p&gt;&lt;a href="https://mruby.org/"&gt;mruby&lt;/a&gt; is a lightweight implementation of Ruby. It works much like CPython: Ruby source is compiled to bytecode, which is then interpreted by a virtual machine.&lt;/p&gt;&#10;&lt;p&gt;I first encountered mruby bytecode in the DEF CON 2021 Finals. The barb-metal challenge used mruby bytecode to run simulated IoT firmware. A few months later, another mruby reversing challenge appeared in the Fifth Space online competition, so I decided to summarize the characteristics of mruby bytecode.&lt;/p&gt;</description></item><item><title>PlaidCTF 2021 Watness 3</title><link>https://x-nagi.com/post/plaidctf2021.html</link><pubDate>Wed, 25 Aug 2021 21:59:22 +0800</pubDate><guid>https://x-nagi.com/post/plaidctf2021.html</guid><description>&lt;p&gt;In PlaidCTF 2021, I solved the challenge &lt;code&gt;The Watness III&lt;/code&gt;, then I spent my time on another challenge &lt;code&gt;dr&lt;/code&gt;. Unfortunately, the regular expression algorithm in &lt;code&gt;dr&lt;/code&gt; is too complex to understand, thus I failed to solve it.&lt;/p&gt;&#10;&lt;p&gt;There was a similar challenge in PlaidCTF 2020, &lt;code&gt;The Watness II&lt;/code&gt;. I solved that last year when I was a member of A*0*E; it was a reverse challenge of a HyperCard game on the m68k platform. I thought that this challenge had the same game logic as the previous one, so I spent some time finding the color logic used in &lt;code&gt;The Watness II&lt;/code&gt;. But the result shows that this challenge is different from that one.&lt;/p&gt;</description></item><item><title>DEF CON CTF 2021 Finals Retrospective</title><link>https://x-nagi.com/post/dc2021f.html</link><pubDate>Fri, 13 Aug 2021 00:04:08 +0800</pubDate><guid>https://x-nagi.com/post/dc2021f.html</guid><description>&lt;p&gt;Hangzhou was rainy again today, making it difficult to feel energetic. I swore long ago that I would stop procrastinating, but nothing has changed after several years. After both the DEF CON CTF 2020 Finals and the 2021 Qualifiers, I confidently planned to publish something, only to abandon it each time. I could not postpone it again, so here is an account of my two days in Shanghai.&lt;/p&gt;</description></item><item><title>*CTF 2021 Reverse*5</title><link>https://x-nagi.com/post/starctf2021.html</link><pubDate>Tue, 19 Jan 2021 09:02:47 +0800</pubDate><guid>https://x-nagi.com/post/starctf2021.html</guid><description>&lt;p&gt;The endless exams finally ended, and after half a year I returned to competing with my AAA teammates—and to staying up all night. We solved five of the six reverse-engineering challenges. The remaining one, &lt;code&gt;RL_Env&lt;/code&gt;, appeared to involve machine learning; I did not even understand what it was asking us to do.&lt;/p&gt;</description></item><item><title>TCTF 2020 Finals Writeup</title><link>https://x-nagi.com/post/tctf-2020-final.html</link><pubDate>Mon, 28 Sep 2020 17:53:02 +0800</pubDate><guid>https://x-nagi.com/post/tctf-2020-final.html</guid><description>&lt;p&gt;I realized that the blog had not been updated for a year, so it was time to fill in one of the gaps.&lt;/p&gt;&#10;&lt;p&gt;TCTF 2020 began at 10 a.m. and lasted 24 hours. My teammates and I spent the entire day competing in room 108, until I could no longer stay awake and fell asleep at 4 a.m. We ultimately placed second in the Rising Star division. In KoH, we lost to NeSE because we could not determine how to wire an S-box efficiently from logic gates.&lt;/p&gt;</description></item><item><title>SECCON 2019 Finals Writeup: bad mouse &amp; 四.3</title><link>https://x-nagi.com/post/seccon-2019.html</link><pubDate>Fri, 27 Dec 2019 12:52:57 +0800</pubDate><guid>https://x-nagi.com/post/seccon-2019.html</guid><description>&lt;h1 id="bad-mouse"&gt;bad mouse&lt;/h1&gt;&#10;&lt;p&gt;The challenge provided a small USB circuit board. Once connected, it behaved like an emulated mouse and drew the flag one character at a time. Its drawing speed continually decreased, so it clearly could not finish before the competition ended.&lt;/p&gt;&#10;&lt;p&gt;First convert the supplied firmware to binary with a tool such as &lt;a href="http://hex2bin.sourceforge.net/"&gt;hex2bin&lt;/a&gt;. Open it in IDA, select Atmel AVR as the processor and ATmega32 (or another suitable model) as the device, and the firmware can be disassembled.&lt;/p&gt;</description></item><item><title>The 5th USTC Information Security Contest</title><link>https://x-nagi.com/post/ustc-5.html</link><pubDate>Wed, 17 Oct 2018 22:45:30 +0800</pubDate><guid>https://x-nagi.com/post/ustc-5.html</guid><description>&lt;h2 id="check-in"&gt;Check-in&lt;/h2&gt;&#10;&lt;p&gt;Press F12 in Chrome to open Developer Tools. The input field has the following attribute:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;&#10;&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;&#10;&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1&#10;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&#10;&lt;td class="lntd"&gt;&#10;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-html" data-lang="html"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;p&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Key: &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;input&lt;/span&gt; &lt;span class="na"&gt;type&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;#34;text&amp;#34;&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;#34;key&amp;#34;&lt;/span&gt; &lt;span class="na"&gt;maxlength&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;#34;13&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;/&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;p&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&#10;&lt;/div&gt;&#10;&lt;/div&gt;&lt;p&gt;Remove the &lt;code&gt;maxlength&lt;/code&gt; attribute, then enter &lt;code&gt;hackergame2018&lt;/code&gt;.&lt;/p&gt;&#10;&lt;p&gt;flag: &lt;code&gt;flag{Hackergame2018_Have_Fun!}&lt;/code&gt;&lt;/p&gt;</description></item><item><title>MeePwn 2018: image-crackme</title><link>https://x-nagi.com/post/meepwn2018.html</link><pubDate>Wed, 17 Oct 2018 22:43:16 +0800</pubDate><guid>https://x-nagi.com/post/meepwn2018.html</guid><description>&lt;h2 id="image-crackme"&gt;image-crackme&lt;/h2&gt;&#10;&lt;p&gt;I tried to reverse the challenge with IDA Pro, but IDA crashed halfway through loading it, so I had to work by inference. After running &lt;code&gt;image-crackme.exe&lt;/code&gt; several times, I found that it always generated a &lt;code&gt;MeePwn.ascii&lt;/code&gt; containing a 160×160 block of seemingly random characters. The directory also contained a 160×160 &lt;code&gt;MeePwn.jpg&lt;/code&gt;, without which the program would not run. I suspected a relationship between the image pixels and the output. I replaced the original with a completely white 160×160 image so every pixel was identical, then entered &lt;code&gt;0123456789:;&amp;lt;=&amp;gt;?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}&lt;/code&gt; (ASCII 48–126) as the key. The output had a very regular pattern:&lt;/p&gt;</description></item><item><title>SCTF 2018 Writeup</title><link>https://x-nagi.com/post/sctf2018.html</link><pubDate>Wed, 17 Oct 2018 20:20:02 +0800</pubDate><guid>https://x-nagi.com/post/sctf2018.html</guid><description>&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;Reverse&lt;/strong&gt; Script In Script&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Reverse&lt;/strong&gt; Where is my 13th count?&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Reverse&lt;/strong&gt; simple&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Misc&lt;/strong&gt; Welcome to SCTF 2018&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Misc&lt;/strong&gt; Mysterious Transaction&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Misc&lt;/strong&gt; Otaku&amp;rsquo;s Happy Challenge&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Misc&lt;/strong&gt; Introduction to Side Channels&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Web&lt;/strong&gt; easiest web - phpmyadmin&lt;/li&gt;&#10;&lt;/ul&gt;</description></item></channel></rss>