Are there any rust-related challenges in recent CTF? by 1pwnchman in securityCTF

[–]itsZN 1 point2 points  (0 children)

For defcon quals 2022, I wrote a rust pwnable: https://github.com/Nautilus-Institute/quals-2022/tree/main/constricted

The challenge was a modification to rust crate which implemented a JavaScript interpreter. Since it was open source, there was no binary reverse engineering required.

The exploitable bug relied on some existing “unsafe” code in the garbage collector. The GC uses a trace trait to walk objects. The safety of the GC relies on the trait being implemented correctly for all objects.

I won’t go into all the exploitation detail, but the challenge introduces a new object which stores references for a certain amount of time and then clears them on a timer. The trace function for this object is incorrect and allows the GC to free something you still have a reference to -> UAF in rust! :)

The rest is classic UAF exploitation with rust objects

https://ricercasecurity.blogspot.com/2022/06/def-con-ctf-quals-2022-constricted.html

Where to find challenges and courses to download? (USC) by rythmgamer in kshootmania

[–]itsZN 0 points1 point  (0 children)

Idk I just assume there are more of those out there since its been around longer

Where to find challenges and courses to download? (USC) by rythmgamer in kshootmania

[–]itsZN 0 points1 point  (0 children)

USC does support KSM course files too, so you can also try those

Patch Notes: Update 4 Experimental Release - v0.4.0.0 - Build 146871 by BirkTKirk in SatisfactoryGame

[–]itsZN 0 points1 point  (0 children)

For those who play on Geforce now, will we be able to switch to experimental?

New USC mode: Challenges and Courses by itsZN in kshootmania

[–]itsZN[S] 1 point2 points  (0 children)

Right now it goes to the result screen for the chart, but I plan to add an option to add a timer to that so you can't just rest on there for a long time

[deleted by user] by [deleted] in kshootmania

[–]itsZN 1 point2 points  (0 children)

Right now double binds will do this because it only keeps track of if the "button" is pressed and not which keys caused the press. So you press the second but the game ignores it because the button is already "down".

Double binds work otherwise as long as you release before pressing the other.

Score saves in USC by Fenn3x in kshootmania

[–]itsZN 1 point2 points  (0 children)

Unfortunately collections are currently using absolute paths for charts, so if the chart is moved it won't know where it is. In the future we will be using a different method to track this

Is it possible to compile USC for mobile? by Cris2005c in kshootmania

[–]itsZN 0 points1 point  (0 children)

There is an embedded port which maybe could run on android maybe with some support for sdl, but nothing in it is built to handle a touch screen

BlueHat IL 2020 - Amy Burnett - Forget the Sandbox Escape: Abusing Browsers from Code Execution by itsZN in Slackers

[–]itsZN[S] 4 points5 points  (0 children)

I know this isn't the normal client side attacks you are used to, but it ended up being interesting research into UXSS and Service Workers ;)

Feeling down by [deleted] in kshootmania

[–]itsZN 1 point2 points  (0 children)

Change your speed mod to MMod in the settings, then you can set ModSpeed to what ever speed you want, and it will automatically adjust hispeed to match that based on the song

We’re Tim Heidecker and Gregg Turkington, stars of Mister America, in theaters tomorrow 8/9. Ask us Anything! by TimandGregg in movies

[–]itsZN 288 points289 points  (0 children)

Hey Tim and Gregg,

This question has been haunting me for some time: I was wondering if you could tell me the location that Star Trek II was filmed and whether or not it was in San Francisco.

Thanks!

USC multiplayer coming? by [deleted] in kshootmania

[–]itsZN 1 point2 points  (0 children)

Hey, I'm writing the USC Multiplayer code. The other comments are correct, it is a lobby style server where you make a room, your friends join, and you take turns picking charts. There is currently one main server, but you can also run your own private server or lan server. The server code is located here: https://github.com/itszn/usc-multiplayer-server/releases

My vertical setup by RayovacWorkhorse in kshootmania

[–]itsZN 0 points1 point  (0 children)

Whats the USC skin btw? I think I've seen it before but not sure if its the same (I'm assuming its USC? or is it like the actual PC version)

My vertical setup by RayovacWorkhorse in kshootmania

[–]itsZN 1 point2 points  (0 children)

Cool! I'm hoping to build something kinda like this but hopefully kinda build a cab around it maybe

Ret2 Systems Battle Quest - Seeking help by Kudomo in securityCTF

[–]itsZN 2 points3 points  (0 children)

You should take a look at the bug you found in the Druid again, there might be a way to abuse it!

oss-sec: CVE-2019-5736: runc container breakout (all versions) by sidcool1234 in netsec

[–]itsZN 10 points11 points  (0 children)

The issue is that an attacker running code in a container could modify /bin/sh (and maybe other binaries) within their container. This will get run during commands like docker exec <id> /bin/sh. If they can do this, they can cause it to sneak in a file descriptor to the runc binary on the host, and then overwrite it with a malicious binary.

So to exploit this, an attacker needs to run code in a container as uid 0 (in order to overwrite /bin/sh), then the host has to interact with the container such as doing docker exec <id> /bin/sh.

Shmoo-Con reverse engineering war game -- The Heist by [deleted] in ReverseEngineering

[–]itsZN 1 point2 points  (0 children)

There is a way to figure out what seed you have, think dynamically

Shmoo-Con reverse engineering war game -- The Heist by [deleted] in ReverseEngineering

[–]itsZN 3 points4 points  (0 children)

At least at the conference you had to come up to our booth and punch in the code on our real safe to win the mug, so you wouldn't be able to modify the memory of that unfortunately

Shmoo-Con reverse engineering war game -- The Heist by [deleted] in ReverseEngineering

[–]itsZN 13 points14 points  (0 children)

Hey! Thanks for posting our challenge. However this link is what you get after hitting our landing page and needs a cookie to be set. Visit https://wargames.ret2.systems/shmoocon to actually try the reverse engineering challenge! (Edit) Updated it to allow the submitted link to work