<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>[&quot;Jacob P. Mohrbutter&quot;]</title>
    <description>Security Blog</description>
    <link>https://blog.jacobmohrbutter.com</link>
    <atom:link href="https://blog.jacobmohrbutter.com/feed.xml" rel="self" type="application/rss+xml" />
    <author>
      <name>Jacob Mohrbutter</name>
      <email>jmohrbutter@gmail.com</email>
      <uri>qu3b411.github.io</uri>
    </author>
    
      <item>
        <title>A ClickFix GPT, a weaponized MSI, and the implant that RickRolled itself</title>
        <description>&lt;h1 id=&quot;public-advisory&quot;&gt;Public Advisory&lt;/h1&gt;

&lt;aside class=&quot;callout callout--danger&quot; role=&quot;note&quot;&gt;
&lt;strong&gt;The fix is the attack.&lt;/strong&gt; In this lure, following the website&apos;s &quot;verification&quot; instructions is what would infect the computer. If a website tells you to press &lt;kbd&gt;Win&lt;/kbd&gt;+&lt;kbd&gt;R&lt;/kbd&gt;, then &lt;kbd&gt;Ctrl&lt;/kbd&gt;+&lt;kbd&gt;V&lt;/kbd&gt;, then &lt;kbd&gt;Enter&lt;/kbd&gt; to &quot;verify&quot; anything — stop and close the tab. No legitimate service needs that sequence.
&lt;/aside&gt;

&lt;p&gt;&lt;strong&gt;If you only read one section, read this one. Share it with someone who might follow a fake verification prompt.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I had searched for “gpt”. The browser record shows a Google ad redirect into a community GPT on the real ChatGPT site. Its notice claimed a service problem and sent me to a backup page. That page dressed itself as a human-verification check and told me to run a command on my own computer.&lt;/p&gt;

&lt;p&gt;The part to recognize is the keyboard sequence:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Windows key + R&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Ctrl + V&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Enter&lt;/code&gt; runs a command.&lt;/strong&gt; The first keys open Windows Run; the next keys paste whatever the page put on your clipboard; Enter executes it. A website asking you to do that is asking you to run its code.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;A human-verification check stays in the web page.&lt;/strong&gt; If a box claiming to be Cloudflare asks you to open Windows Run or PowerShell, close the tab.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;A familiar site can carry someone else’s instructions.&lt;/strong&gt; The malicious notice appeared inside a community GPT on the real ChatGPT site. The surrounding page was genuine; the instructions were supplied by a third party.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;What to do instead:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Close the tab. Do not paste or run the command, even if the page says your account or service will stop working.&lt;/li&gt;
  &lt;li&gt;If you are unsure, ask someone you trust before following the instructions.&lt;/li&gt;
  &lt;li&gt;If you already ran it, disconnect that computer from the internet and get help from someone who can examine it. This trick can install a hidden program.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I did not run the command on my host. The payload here targets Windows; the warning sign is a website telling you to execute a command outside the browser.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;strong&gt;Publication note:&lt;/strong&gt; While preparing this research for release, I discovered &lt;a href=&quot;https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat&quot;&gt;Huntress had already published analysis&lt;/a&gt; of the same “Plus 5.6” campaign and the Stardock/Build.dat loader chain. That work has publication priority on those overlapping findings. My investigation was conducted independently and was substantially complete before I found their report. The protocol reconstruction, controlled tasking, and reproducible lab described here were developed from my own captured artifacts and testing.&lt;/p&gt;

&lt;hr /&gt;

&lt;h1 id=&quot;executive-summary&quot;&gt;Executive Summary&lt;/h1&gt;

&lt;p&gt;An ordinary search for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpt&lt;/code&gt; took my browser across a Google ad redirect and into a community-built GPT on the real ChatGPT site. The GPT presented a fake service notice pointing to a Google Sites page dressed as a Cloudflare check. The browser record shows that page loading, although it does not preserve the physical click that opened it. A later saved copy of the page put a PowerShell launcher on the clipboard and told the visitor to press &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Win+R&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Ctrl+V&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Enter&lt;/code&gt;. In Windows those keys would run the launcher, fetch two more PowerShell stages, and silently install an MSI. The attacker needed the visitor to run a command, not a browser exploit.&lt;/p&gt;

&lt;p&gt;I did not run that command on my host. I collected the Windows payload afterward and examined it in isolation. The MSI hides its installed product, side-loads a DLL chain, and starts an implant with persistence and task-handling code. I reconstructed enough of its binary protocol to send a type-1 shell task to the resident implant. The first probe returned a marker and opened a local page; the prepared demo uses the same task path to open a locally served Rick Astley video. The released lab includes the primed infected VM, emulator, controller, and harness so another researcher can repeat that result without contacting the real C2.&lt;/p&gt;

&lt;p&gt;The saved samples came after the original browser visit, so I cannot say they are byte-for-byte what the first visitor would have received. The public package supports reproduction of the isolated tasking result; raw browser, mailbox, and lab captures remain private. I reported the attack in a ChatGPT conversation, and OpenAI acknowledged that report as &lt;strong&gt;Cyber attacks&lt;/strong&gt;. Firefox also retained the exact GPT conversation URL and fake-site URL from an OpenAI report-form submit event before a review reply said &lt;strong&gt;“no policy violation.”&lt;/strong&gt; I had no unrelated reports from that account; this was the reply to my first report about the attack. A GPT pointing people to a fake verification page that instructs them to run a command called for security and abuse triage. OpenAI had the reported conversation and the exact URL. I cannot see what a reviewer opened or how the report was routed internally; I can see the answer I received. After reading it, I reported the GPT itself as &lt;strong&gt;Scams and/or fraud&lt;/strong&gt;; OpenAI acknowledged “Plus 5.6” by name. I found no decision for that named report. The GPT became unavailable afterward. I do not know why.&lt;/p&gt;

&lt;hr /&gt;

&lt;h1 id=&quot;a-clickfix-gpt-a-weaponized-msi-and-the-implant-that-rickrolled-itself&quot;&gt;A ClickFix GPT, a weaponized MSI, and the implant that RickRolled itself&lt;/h1&gt;

&lt;p&gt;&lt;em&gt;A real ChatGPT page carried a fake verification prompt. I followed the payload into an isolated lab and eventually made its implant play Rick Astley.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Research materials:&lt;/strong&gt; &lt;a href=&quot;https://github.com/qu3b411/clickfix&quot;&gt;qu3b411/clickfix repository&lt;/a&gt; · &lt;a href=&quot;https://github.com/qu3b411/clickfix/releases/tag/iclickrickroll-lab-v1&quot;&gt;prepared lab release&lt;/a&gt; · &lt;a href=&quot;https://github.com/qu3b411/clickfix/blob/main/docs/demo-evidence.md&quot;&gt;demo-evidence guide&lt;/a&gt; · &lt;a href=&quot;https://github.com/qu3b411/clickfix/blob/main/SAFETY.md&quot;&gt;sample and lab safety&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Incident: September 25, 2026&lt;/em&gt;&lt;/p&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;dfiu&quot;&gt;DFIU&lt;/h2&gt;

&lt;p&gt;&lt;em&gt;(Don’t Fuck It Up. This is for the person excited enough to try the lab and tempted to take a shortcut.)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The archive linked below contains a live implant and a prepared infected Windows VM. If you only want to watch the result, the video is below. You do not need the lab to understand the joke.&lt;/p&gt;

&lt;p&gt;If you do run the lab, use a dedicated host you can afford to wipe and read the included warning first. The shipped harness checks its own VirtualBox setup, but you are responsible for the host around it.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Keep the VMs on the isolated internal network.&lt;/strong&gt; No NAT, bridged, or host-only adapter. No route to your LAN or the internet. Check the adapter settings before booting and again if you change anything.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Keep host integration off.&lt;/strong&gt; No shared folders, shared clipboard, drag-and-drop, or Guest Additions in the infected Windows VM. A convenient file transfer is a bad trade when the guest is running malware.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Do not point the sample at the real C2.&lt;/strong&gt; The address in this article is a live indicator. Inside the lab it is redirected to a local controller, with forwarding disabled. Do not copy that address into a browser or run the sample on a normal network.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Treat the downloads as hazardous.&lt;/strong&gt; The password is an acknowledgement, not a safety feature. Do not unpack the archive in Downloads and browse around casually. Keep the samples encrypted except inside the intended research environment.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Stop when the setup disagrees with the instructions.&lt;/strong&gt; A failed isolation check is a stop sign. Do not comment it out to get to the Rickroll. Inspect what changed and start again from a clean disposable clone.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Assume your guest is compromised after the demo.&lt;/strong&gt; Do not log into personal accounts in it. Do not give it secrets. Revert or delete disposable clones when you finish.&lt;/li&gt;
&lt;/ul&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;technical-teardown&quot;&gt;Technical Teardown&lt;/h2&gt;

&lt;p&gt;The evidence splits here. My browser record reaches the fake check; it does not contain the payload that would have landed had I followed the instructions on my host. I collected the later stages afterward and ran those saved bytes in isolation. That gives me a real execution path to analyze, but it ties the lab result to the supplementary samples rather than to an unseen download during the original visit.&lt;/p&gt;

&lt;h3 id=&quot;the-route-to-the-fake-check&quot;&gt;The route to the fake check&lt;/h3&gt;

&lt;p&gt;The preserved browser route starts with a search for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpt&lt;/code&gt;, crosses a Google &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/aclk&lt;/code&gt; ad redirect, and reaches a GPT called “Plus 5.6.” The click identifier matches across the redirect. I also remember a strange “New chat” transition, but I cannot place it from the browser record.&lt;/p&gt;

&lt;figure&gt;
  &lt;img src=&quot;/assets/clickfix/google-sponsored-result-later.png&quot; alt=&quot;A later Google search for gpt showing a sponsored ChatGPT result and a hovered google.com/aclk link&quot; /&gt;
  &lt;figcaption&gt;
    While preparing this article, I made the same search and again saw a sponsored ChatGPT result with a Google &lt;code&gt;/aclk&lt;/code&gt; link. This later screenshot shows how ordinary that entry point looks; it is not the incident ad and does not show that this result is malicious. I cropped out browser profile details and removed the ad URL&apos;s query parameters.
  &lt;/figcaption&gt;
&lt;/figure&gt;

&lt;p&gt;The GPT identified itself as community-built. I started a conversation (“Extract avatar”) and saw a “&lt;strong&gt;Service Availability Notice&lt;/strong&gt;” claiming trouble with the primary service and pointing to a backup site, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sites[.]google[.]com/view/antibot172881&lt;/code&gt;. The screenshot records that notice, and the browser record shows the site loaded afterward. It does not retain the initiating click. The fake notice came from third-party GPT content inside a genuine ChatGPT page; I have no evidence that OpenAI authored it.&lt;/p&gt;

&lt;h3 id=&quot;fake-cloudflare-verification&quot;&gt;Fake Cloudflare verification&lt;/h3&gt;

&lt;p&gt;My screenshot shows the Google Sites page rendering a full-screen &lt;strong&gt;Cloudflare-styled “Human Verification”&lt;/strong&gt; interface naming &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;chatgpt.com&lt;/code&gt;, with instructions to press &lt;strong&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Win+R&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Ctrl+V&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Enter&lt;/code&gt;.&lt;/strong&gt;&lt;/p&gt;

&lt;figure&gt;
  &lt;img src=&quot;/assets/clickfix/fake-cloudflare-verification.png&quot; alt=&quot;Fake Cloudflare &apos;Human Verification&apos; modal instructing the user to press Win+R, Ctrl+V, Enter&quot; /&gt;
  &lt;figcaption&gt;
    The fake Cloudflare &quot;Human Verification&quot; modal served from
    &lt;code&gt;sites[.]google[.]com/view/antibot172881&lt;/code&gt;. This is attacker-controlled content on
    Google Sites, not a real Cloudflare check. This crop has its metadata stripped;
    the public hash and handling notes are in
    &lt;a href=&quot;https://github.com/qu3b411/clickfix/tree/main/images/incident&quot;&gt;images/incident&lt;/a&gt;.
  &lt;/figcaption&gt;
&lt;/figure&gt;

&lt;p&gt;The checkbox is theater. The saved page places a PowerShell launcher in an offscreen textarea, selects it, and calls &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;document.execCommand(&apos;copy&apos;)&lt;/code&gt;. By the time the visitor reaches &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Ctrl+V&lt;/code&gt;, the command is already on the clipboard. The page also swaps visible &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;google.com&lt;/code&gt; text for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;chatgpt.com&lt;/code&gt;, blocks developer-tool shortcuts, and posts telemetry to a runtime-origin &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;api.php&lt;/code&gt;. It references an external script and a panel address that were not captured, so this copy cannot establish whether either one ran.&lt;/p&gt;

&lt;h3 id=&quot;payload-retrieval&quot;&gt;Payload retrieval&lt;/h3&gt;

&lt;p&gt;The clipboard launcher fetched &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/12&lt;/code&gt; from &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;1450003207&lt;/code&gt;, wrote a PowerShell script under &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;%TEMP%&lt;/code&gt;, and ran it. That number is decimal IPv4 notation for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;86[.]109[.]75[.]7&lt;/code&gt;: the request avoids a dotted address and a DNS lookup. The exact launcher bytes are preserved in the password-protected page sample. The three-stage retrieval was:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GET /12&lt;/code&gt; → &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;12.ps1&lt;/code&gt; (800 bytes) — sets TLS 1.2, a Chrome-like UA, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DownloadString&lt;/code&gt; of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/s/19481b28bd67&lt;/code&gt;, pipes the result into a hidden &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;powershell -nop -w hidden -ep bypass -&lt;/code&gt;.&lt;/li&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GET /s/19481b28bd67&lt;/code&gt; → &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;stage3.txt&lt;/code&gt; (54,235 bytes, arithmetic-obfuscated) — decodes to a downloader of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/app/19481b28bd67/IconEdit2Turb.msi&lt;/code&gt;, saved to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;%TEMP%&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Unblock-File&lt;/code&gt;, then &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;msiexec /i … /qn /norestart&lt;/code&gt; with a hidden window.&lt;/li&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GET /app/19481b28bd67/IconEdit2Turb.msi&lt;/code&gt; → the weaponized MSI (5,069,824 bytes).&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The first stage and MSI are saved bytes; I decoded the middle stage. These samples were collected after the original browser visit.&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;&lt;strong&gt;Artifacts:&lt;/strong&gt; the page, both PowerShell stages, and the MSI are published as live samples — in password-protected archives only — under &lt;a href=&quot;https://github.com/qu3b411/clickfix/tree/main/malware&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;malware/&lt;/code&gt;&lt;/a&gt;. Original and archive hashes are in &lt;a href=&quot;https://github.com/qu3b411/clickfix/blob/main/malware/README.md&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;malware/README.md&lt;/code&gt;&lt;/a&gt;; repository file hashes are in &lt;a href=&quot;https://github.com/qu3b411/clickfix/blob/main/manifests/SHA256SUMS.txt&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;manifests/SHA256SUMS.txt&lt;/code&gt;&lt;/a&gt;. &lt;strong&gt;Read &lt;a href=&quot;https://github.com/qu3b411/clickfix/blob/main/SAFETY.md&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;SAFETY.md&lt;/code&gt;&lt;/a&gt; first.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3 id=&quot;inside-the-msi&quot;&gt;Inside the MSI&lt;/h3&gt;

&lt;details&gt;
  &lt;summary&gt;&lt;strong&gt;Expand: MSI packaging, hidden-product flag, and the side-load chain&lt;/strong&gt;&lt;/summary&gt;

  &lt;p&gt;The MSI declares benign branding (“Stardock Smart DeElevation Tool”, v7.12.0, “Filezo”, Advanced Installer), installs in the user’s LocalAppData &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Programs&lt;/code&gt; tree, and sets &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ARPSYSTEMCOMPONENT=1&lt;/code&gt; to hide from the installed-programs list. A WiX &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;WixShellExec&lt;/code&gt; custom action (sequence 6602, after &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;InstallFinalize&lt;/code&gt;) &lt;strong&gt;launches &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DeElevate64.exe&lt;/code&gt;&lt;/strong&gt; without another user action. The dependency chain is &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DeElevate64.exe&lt;/code&gt; → &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DeElevator64.dll!RunNonElevated&lt;/code&gt; → &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;I++u.dll!contentsStroke&lt;/code&gt; → &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;senddmp.resources.dll&lt;/code&gt; (+ dynamically loaded &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;res.dll&lt;/code&gt;). &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DeElevator64.dll&lt;/code&gt; has its import directory in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.rsrc&lt;/code&gt; and a certificate directory pointing past EOF, both signs of a modified loader.&lt;/p&gt;

&lt;/details&gt;

&lt;h3 id=&quot;the-builddat-graft&quot;&gt;The Build.dat graft&lt;/h3&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Build.dat&lt;/code&gt; presents as a 36-entry NuGet-style ZIP but has a &lt;strong&gt;deliberately inserted region&lt;/strong&gt; at &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[0x5847b, 0xaba8e)&lt;/code&gt; — exactly 341,523 bytes. Removing precisely that range from an analysis copy restores a ZIP whose 36 members all pass CRC. The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;I++u.dll&lt;/code&gt; loader reads exactly that region, transforms it, copies it into executable memory allocated by &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;senddmp.resources.dll&lt;/code&gt;, and hands the buffer to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;EnumSystemCodePagesW&lt;/code&gt; as a callback — a code-execution loader, not data.&lt;/p&gt;

&lt;p&gt;The transformed region decodes to valid x64 position-independent code once all three changing state registers in the loader’s XOR loop are tracked correctly. My first pass got that loop wrong; the corrected decoder and recovered bytes are retained in my analysis record.&lt;/p&gt;

&lt;h3 id=&quot;an-isolated-execution&quot;&gt;An isolated execution&lt;/h3&gt;

&lt;p&gt;Static analysis had shown me a loader and task-handling code; it could not tell me whether the installed process would remain alive long enough to use either. I built a disposable Windows 11 VM with one NIC on a private VirtualBox internal network and no host integration. Sysmon, Procmon, ETW collection for DNS, Task Scheduler, and WinHTTP, plus process, socket, and memory-dump watchers from a read-only tools ISO recorded the run. I took a clean powered-off snapshot before introducing the sample and checked isolation again afterward.&lt;/p&gt;

&lt;p&gt;The released victim comes from the sealed run. Defender real-time protection was on, but its signatures were old and offline, and the specimen’s install folder had a narrow exclusion. The specimen survived under those conditions. That says nothing about current Defender detection on a fully updated Windows machine.&lt;/p&gt;

&lt;h3 id=&quot;network-emulation&quot;&gt;Network emulation&lt;/h3&gt;

&lt;p&gt;The Windows guest needed to reach the services the sample expected without gaining a route off the lab network. A second VM (Ubuntu 24.04) ran INetSim and dnsmasq on the same private segment: wildcard DNS to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;10.77.86.2&lt;/code&gt;, simulated HTTP/HTTPS, DHCP, &lt;strong&gt;no default route, IP forwarding 0&lt;/strong&gt;. I used a clean probe VM to check that service path before attaching the infected guest. Later, a small local replay server returned the three exact saved stage bodies, allowing the ClickFix chain to run end-to-end without an uplink.&lt;/p&gt;

&lt;h3 id=&quot;finding-the-c2-path&quot;&gt;Finding the C2 path&lt;/h3&gt;

&lt;p&gt;Once the implant stayed resident, I watched it query &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;dns.google&lt;/code&gt;, attempt TLS with SNI &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;dns.google&lt;/code&gt;, then attempt TCP to &lt;strong&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;45.140.205.28:443&lt;/code&gt;&lt;/strong&gt;, a candidate C2 endpoint. The first SYNs went unanswered. I then redirected that destination to a passive listener inside the emulator. &lt;strong&gt;No byte was sent to the real address.&lt;/strong&gt; The listener received 18 structured binary messages totaling 58,626 bytes and sent zero bytes back.&lt;/p&gt;

&lt;h3 id=&quot;reconstructing-the-protocol&quot;&gt;Reconstructing the protocol&lt;/h3&gt;

&lt;details&gt;
  &lt;summary&gt;&lt;strong&gt;Expand: the recovered wire format (header, descriptors, registration profile)&lt;/strong&gt;&lt;/summary&gt;

  &lt;p&gt;The messages use a &lt;strong&gt;120-byte arithmetic header&lt;/strong&gt; (constant &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;K=0x16df3822a8&lt;/code&gt;), &lt;strong&gt;88-byte field descriptors&lt;/strong&gt;, and XOR-transformed field data. A client-embedded UTC timestamp preceded the socket watcher’s first observation of the same source port in every stream, a useful cross-check on the decode. The body is a 26-field registration profile: username &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;analyst&lt;/code&gt;, computer &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CFX-LAB&lt;/code&gt;, Windows version, security product, CPU/GPU, locale, client version, executable, and install path. I also mapped the receive-side action tags (&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0x56bc&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0x56be&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0x5b90&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0x5608&lt;/code&gt;, …) and reproduced the frame-length arithmetic against the captured frames. The &lt;a href=&quot;https://github.com/qu3b411/clickfix/blob/main/c2/protocol-spec.md&quot;&gt;public protocol specification&lt;/a&gt; carries the wire details.&lt;/p&gt;

&lt;/details&gt;

&lt;h3 id=&quot;why-the-implant-stayed-alive&quot;&gt;Why the implant stayed alive&lt;/h3&gt;

&lt;p&gt;The first direct-MSI run persisted; several shorter runs did not. The difference turned out to be a “Syntax error” dialog left open by the de-elevation wrapper. The dialog kept &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DeElevate64.exe&lt;/code&gt; alive while the malicious DLL ran on another thread. The decoded task script waits &lt;strong&gt;150&lt;/strong&gt; and &lt;strong&gt;875 seconds&lt;/strong&gt; before writing the Run value and scheduled task. In a controlled run I left the dialog open and saw both writes. For this sample, in these runs, process lifetime was the condition that mattered.&lt;/p&gt;

&lt;h3 id=&quot;process-tree-and-sysmon&quot;&gt;Process tree and Sysmon&lt;/h3&gt;

&lt;p&gt;Sysmon joined the installer chain &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;msiexec.exe → msiexec.exe → 32-bit msiexec.exe → DeElevate64.exe&lt;/code&gt; to the DLL load order and the delayed HKCU Run value and scheduled task. The guest and emulator clocks differed after saved-state resume; I joined network events to the emulator capture by source port and packet order.&lt;/p&gt;

&lt;h3 id=&quot;a-local-controller&quot;&gt;A local controller&lt;/h3&gt;

&lt;p&gt;The receive-side reconstruction identified a type-1 task container, a start-shell field, and a field that feeds UTF-16LE command text to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cmd.exe&lt;/code&gt;. I wrote a controller under &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;c2/&lt;/code&gt; that binds to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;10.77.86.2:8443&lt;/code&gt;, rejects peers outside &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;10.77.86.0/24&lt;/code&gt;, and emits the fixed frames needed to test that path. It has &lt;strong&gt;no upstream or forwarding code&lt;/strong&gt;. Task types 2–4 appear in the disassembly; I did not exercise them.&lt;/p&gt;

&lt;h3 id=&quot;task-execution&quot;&gt;Task execution&lt;/h3&gt;

&lt;p&gt;The reconstructed frames let me test whether the client was actually parsing my replies:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;State flip:&lt;/strong&gt; changing decoded field &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0x56bc&lt;/code&gt; between &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;01&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;00&lt;/code&gt; repeatably changed the live client’s connection lifetime and reconnect cadence. Switching it back restored the first behavior. Both NIC captures contain the generated frames; the change came from the client acting on them.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Type-1 shell:&lt;/strong&gt; the implant spawned &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cmd.exe&lt;/code&gt;, returned &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CFX_RICKROLL_TASK_PROOF&lt;/code&gt;, and echoed the shell PID in reply field &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0x5975&lt;/code&gt;. A second fixed shell-input frame launched Edge at a local page. That first probe did not play the video; the later prepared demo served video through the same local address.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Sysmon recorded &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DeElevate64.exe → cmd.exe → msedge.exe&lt;/code&gt; during that controlled probe, after my controller sent the task. Edge was the result of my shell input, not an observed attacker command. I checked the replies against captures from both NICs and the Sysmon process tree. The public &lt;a href=&quot;https://github.com/qu3b411/clickfix/blob/main/docs/demo-evidence.md&quot;&gt;demo-evidence guide&lt;/a&gt; keeps the controlled probe distinct from the later video presentation.&lt;/p&gt;

&lt;h3 id=&quot;what-happened-after-i-reported-it&quot;&gt;What happened after I reported it&lt;/h3&gt;

&lt;p&gt;There were two reporting paths before I received the negative reply. Keeping them separate matters.&lt;/p&gt;

&lt;p&gt;First, I reported the attack from the &lt;strong&gt;ChatGPT conversation&lt;/strong&gt; under &lt;strong&gt;Cyber attacks&lt;/strong&gt;. OpenAI’s receipt says the report concerned “Cyber attacks” in a ChatGPT conversation. It does not print the conversation ID, but I made the report about the “Plus 5.6” conversation, and I had no unrelated reports from that account. This was the first report.&lt;/p&gt;

&lt;p&gt;I also used OpenAI’s &lt;strong&gt;Report Content form&lt;/strong&gt;. Firefox saved the fake-site URL and the exact “Plus 5.6” conversation URL together when that form was submitted. A case-system acknowledgment then said a report had been submitted. That email does not repeat the URLs. The form and its acknowledgment came before the negative review reply, but I cannot see whether OpenAI joined the form case to the conversation report internally.&lt;/p&gt;

&lt;p&gt;Then the same reporting mail system that acknowledged the &lt;strong&gt;Cyber attacks&lt;/strong&gt; conversation report sent a reply saying it had reviewed the content I reported in ChatGPT and &lt;strong&gt;“found no policy violation.”&lt;/strong&gt; With no unrelated reports from that account, this was the answer to my first attack-conversation report. The reply does not print a case ID, conversation ID, or GPT name, and I cannot see what the reviewer actually opened. I read it later that morning.&lt;/p&gt;

&lt;p&gt;That distinction matters to the failure. The first report came from a GPT conversation that led to a fake verification page telling Windows users to execute a command. The exact conversation and fake-site URLs were also in OpenAI’s report form before the reply. The later collected chain installed a resident implant that accepted shell tasks in my isolated lab. This called for security and abuse triage: inspect the GPT and outbound link, preserve the relevant records, and assess whether other users were exposed. I cannot tell whether the miss was in intake, routing, or review, or whether any separate investigation occurred. The answer sent back on the first report was &lt;strong&gt;“no policy violation.”&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;After reading that answer, I reported the &lt;strong&gt;GPT itself&lt;/strong&gt; as &lt;strong&gt;Scams and/or fraud&lt;/strong&gt;. The later acknowledgment explicitly names “Plus 5.6” and confirms receipt. It does not say OpenAI reviewed or removed the GPT, and I found no decision email for that GPT-level report in the preserved mailbox.&lt;/p&gt;

&lt;p&gt;I found some report messages only when I revisited the mailbox. Their headers show they were delivered on the incident date; delivery does not tell me when I first saw them. When I checked later, the GPT was unavailable. I do not know whether OpenAI removed it, its creator took it down, or something else happened.&lt;/p&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;rickroll&quot;&gt;RickRoll&lt;/h2&gt;

&lt;figure class=&quot;video-embed&quot; data-status=&quot;available&quot;&gt;
  &lt;iframe src=&quot;https://www.youtube-nocookie.com/embed/VRApu5B4TR8&quot; title=&quot;Plus 5.6: Community Builder, Meet Rickroll — isolated malware lab demo&quot; loading=&quot;lazy&quot; allow=&quot;accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture; web-share&quot; allowfullscreen=&quot;&quot;&gt;&lt;/iframe&gt;
  &lt;p&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=VRApu5B4TR8&quot;&gt;Watch the recorded demo on YouTube&lt;/a&gt;&lt;/p&gt;
  &lt;figcaption&gt;
    Two live VMs, side by side. The resident implant accepts the local controller&apos;s task,
    starts a shell, and opens Edge on the locally served concert video with sound.
    The controller pane shows the task and the implant&apos;s replies. The guest and emulator
    use one isolated internal network, with the sample&apos;s C2 address redirected to the
    local controller and no external route. The video is a presentation of a result
    I also checked in the packet capture and process tree.
    Served media: &lt;a href=&quot;https://commons.wikimedia.org/wiki/File:Rick_Astley_-_Never_Gonna_Give_You_Up_-_Festival_de_Vi%C3%B1a_del_Mar_2016_HD.webm&quot;&gt;&quot;Never Gonna Give You Up (Festival de Viña del Mar 2016)&quot;&lt;/a&gt;
    by FESTIVALDEVINACHILE, via Wikimedia Commons,
    &lt;a href=&quot;https://creativecommons.org/licenses/by/3.0/&quot;&gt;CC&amp;nbsp;BY&amp;nbsp;3.0&lt;/a&gt;.
    The source file is unmodified; this recording shows it playing inside the lab.
  &lt;/figcaption&gt;
&lt;/figure&gt;

&lt;p&gt;The search ad, community GPT, and copy-paste “verification” trick reached my browser. I did not run the command, but I saved the page and followed its later payload through an isolated lab. Static analysis exposed the loader and task-handling code; the runtime work gave me a resident implant sending registration messages. Once I had the frame arithmetic and enough of the receive path, I could &lt;strong&gt;speak the implant’s language back to it.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The first fixed task returned &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CFX_RICKROLL_TASK_PROOF&lt;/code&gt;, echoed the shell PID, and opened a page on the local emulator. That was the controlled probe. The video came later, through the same tested shell path. A browser window makes a good punchline, but the tasking claim rests on several things that agree with one another:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Protocol frames:&lt;/strong&gt; the public &lt;a href=&quot;https://github.com/qu3b411/clickfix/blob/main/c2/protocol-spec.md&quot;&gt;protocol specification&lt;/a&gt; documents the reconstructed format and the fixed controller frames.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Packet captures and Sysmon:&lt;/strong&gt; the original probe’s captures reconstruct both sides of the exchange; Sysmon records &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DeElevate64.exe → cmd.exe → msedge.exe&lt;/code&gt;, with the shell PID echoed in the reply. The &lt;a href=&quot;https://github.com/qu3b411/clickfix/blob/main/docs/demo-evidence.md&quot;&gt;demo-evidence guide&lt;/a&gt; separates that probe from the later video presentation.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Prepared baselines:&lt;/strong&gt; the &lt;a href=&quot;https://github.com/qu3b411/clickfix/blob/main/iclickrickroll/ARCHIVE-SHA256SUMS&quot;&gt;release manifest&lt;/a&gt; hashes each archive part and the assembled ZIP. The encrypted package contains internal file checksums and the saved VMs used for the repeatable demo.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Edge was the last process in that chain. The implant accepted a frame I constructed, started the shell, and acted on its input while every network path remained inside the lab. The packaged baselines preserve the resident state so another researcher can make the same check instead of taking my recording on faith.&lt;/p&gt;

&lt;h3 id=&quot;how-do-i-make-iclickrickroll&quot;&gt;How do I make iClickRickroll?&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/qu3b411/clickfix/releases/tag/iclickrickroll-lab-v1&quot;&gt;Get the prepared lab&lt;/a&gt;&lt;/strong&gt; from the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;qu3b411/clickfix&lt;/code&gt; release. It contains a &lt;strong&gt;live infected Windows VM&lt;/strong&gt; with its saved RAM state, an isolated emulator, the controller, two ISOs, and the harness. Preserving that state is why this is a VM-folder release rather than an OVA or instructions to infect a fresh guest. The encrypted archive is 21.3 GiB, expands to about 118.6 GB before disposable run clones, and is split into twelve assets for GitHub’s per-file limit. Read the &lt;a href=&quot;https://github.com/qu3b411/clickfix/blob/main/iclickrickroll/MALWARE-WARNING.txt&quot;&gt;warning&lt;/a&gt; and inspect the &lt;a href=&quot;https://github.com/qu3b411/clickfix/blob/main/iclickrickroll/setup-lab.sh&quot;&gt;guided setup script&lt;/a&gt; before running it. Do not pipe a fetched script straight into a shell.&lt;/p&gt;

&lt;div class=&quot;language-sh highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;git clone https://github.com/qu3b411/clickfix.git
&lt;span class=&quot;nb&quot;&gt;cd &lt;/span&gt;clickfix
bash iclickrickroll/setup-lab.sh
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;The terminal guide asks before downloading the twelve parts, verifies each SHA-256 and the joined ZIP, and asks again before extraction and import. You type &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;IAcknowledgeMaliciousContent&lt;/code&gt; once; it is both the acknowledgement and the ZIP password, passed to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;unzip&lt;/code&gt; without placing it in process arguments. After verifying the extracted files, the guide offers the Debian/Ubuntu packages listed in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;packages.json&lt;/code&gt; and imports both baselines into &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;iclickrickroll-research/&lt;/code&gt; beside the clone. On the dedicated Linux/VirtualBox host, run the command it prints:&lt;/p&gt;

&lt;div class=&quot;language-sh highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nb&quot;&gt;cd&lt;/span&gt; ../iclickrickroll-research/iclickrickroll-lab/reproducible-lab
make iclickrickroll
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;The harness checks the shipped &lt;strong&gt;single VirtualBox internal network&lt;/strong&gt;, the absence of NAT/bridged/host-only adapters, and emulator forwarding disabled. It starts disposable clones of the baselines and brings up the local controller. Type &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;send-rick&lt;/code&gt; in the C2 pane. The command waits for the resident implant’s next beacon; that delay is normal. On receipt, the fixed task opens Edge fullscreen on the &lt;strong&gt;locally served&lt;/strong&gt; Creative Commons concert video. The emulator redirects the sample’s hardcoded C2 address to the controller &lt;strong&gt;inside the lab&lt;/strong&gt;. It has no route to the real endpoint. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;make clean&lt;/code&gt; removes the run clones. The &lt;a href=&quot;https://github.com/qu3b411/clickfix/blob/main/iclickrickroll/README.md&quot;&gt;full lab instructions&lt;/a&gt; cover manual acquisition, prerequisites, hashes, and handling limits.&lt;/p&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;to-the-malware-author&quot;&gt;To the Malware Author&lt;/h2&gt;

&lt;p&gt;Your fake verification page appeared after a search ad redirect and a community GPT. I cannot tell who controlled the ad, or whom you intended to catch. The chain reached my browser, and I saved the page instead of running the command.&lt;/p&gt;

&lt;p&gt;The MSI hid its product with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ARPSYSTEMCOMPONENT=1&lt;/code&gt;, launched &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DeElevate64.exe&lt;/code&gt;, and side-loaded through &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DeElevator64.dll → I++u.dll&lt;/code&gt;. The latter read a 341,523-byte graft from a NuGet-looking ZIP and passed its decoded code to a callback loader. I got the XOR loop wrong on the first pass. All three state registers changed on every byte; once I accounted for that, the graft decoded cleanly.&lt;/p&gt;

&lt;p&gt;The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.raw&lt;/code&gt; container held 1,128 records, including a delayed persistence script in record 4 and an x64 stager in record 1118. In my runs, your de-elevation wrapper’s “Syntax error” dialog kept the host process alive long enough for the delayed Run-key and scheduled-task writes. Closing it early stopped that path. The dialog was doing more for persistence than the installer label suggested.&lt;/p&gt;

&lt;p&gt;Your implant then tried to reach &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;45.140.205.28&lt;/code&gt; and registered with my local listener instead. Its 26-field profile arrived over a protocol with a 120-byte arithmetic header, 88-byte descriptors, and XOR-coded fields. I changed decoded flag &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0x56bc&lt;/code&gt; between &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;01&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;00&lt;/code&gt; and watched the client change its reconnect behavior in both directions. I then sent a fixed type-1 shell task; it spawned &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cmd.exe&lt;/code&gt; and returned my marker with the shell PID in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0x5975&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;The first probe opened a local page. In the prepared lab, the same task path opened Edge on the locally served Rick Astley video. I did not touch your server, see your real tasking, or exercise the other task types. The network had no route to you.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;You tried to get me to paste your command. I got your implant to run one of mine.&lt;/strong&gt;&lt;/p&gt;
</description>
        <pubDate>Thu, 08 Oct 2026 00:00:00 +0000</pubDate>
        <link>https://blog.jacobmohrbutter.com//clickfix/</link>
        <link href="https://blog.jacobmohrbutter.com/clickfix/"/>
        <guid isPermaLink="true">https://blog.jacobmohrbutter.com/clickfix/</guid>
      </item>
    
      <item>
        <title>Kernelcon-2019 CTF writeups</title>
        <description>&lt;p&gt;Kernelcon 2020 is a litle less then 5 months away and my newest challenges are well into their development life cycle. However this post is not about 2020; Instead I will be taking you, the reader, through the CTF writeups for the ctf’s I developed for 2019!&lt;/p&gt;

&lt;h1 id=&quot;setting-up-for-the-ctfs&quot;&gt;Setting Up for the CTF’s&lt;/h1&gt;
&lt;h2 id=&quot;getting-the-challenges&quot;&gt;Getting the Challenges&lt;/h2&gt;
&lt;p&gt;All of these challenges were built to run on a Debian build Linux distro!. From a Linux terminal, run the following commands to pull down the repository!&lt;/p&gt;

&lt;pre&gt;&lt;code class=&quot;language-Console&quot;&gt;Qu3b411@host:~/$ mkdir kernelcon-2019-ctf-qu3b411
Qu3b411@host:~/$ cd kernelcon-2019-ctf-qu3b411
Qu3b411@host:~/kernelcon-2019-ctf-qu3b411$ git init
Initialized empty Git repository in /home/Qu3b411/kernelcon-2019-ctf-qu3b411/.git/
Qu3b411@host:~/kernelcon-2019-ctf-qu3b411$ git clone https://github.com/qu3b411/kernelcon-CTF-2019-solutions
Cloning into &apos;kernelcon-CTF-2019-solutions&apos;...
remote: Enumerating objects: 51, done.
remote: Counting objects: 100% (51/51), done.
remote: Compressing objects: 100% (49/49), done.
remote: Total 51 (delta 5), reused 43 (delta 1), pack-reused 0
Unpacking objects: 100% (51/51), done.
Qu3b411@host:~/kernelcon-2019-ctf-qu3b411$ cd kernelcon-CTF-2019-solution  
Qu3b411@host:~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions$ ls -l
total 24
drwxrwxr-x 4 qu3b411 qu3b411 4096 Oct 30 11:09  ah-ah-ah,-You-didnt-say-the-magic-word
drwxrwxr-x 4 qu3b411 qu3b411 4096 Oct 30 11:09  I-did-a-test-run-on-this-thing-it-took-me-twenty-minutes
-rw-rw-r-- 1 qu3b411 qu3b411 1068 Oct 30 11:09  LICENSE
-rw-rw-r-- 1 qu3b411 qu3b411  348 Oct 30 11:09  README.md
drwxrwxr-x 4 qu3b411 qu3b411 4096 Oct 30 11:09  we-used-the-complete-DNA-of-a-frog-to-fill-in-the-holes-and-complete-the-code
drwxrwxr-x 2 host host 4096 Oct 30 11:09 &apos;you-did-it-you-crazy-son-of-a-****-you-did-it&apos;
Qu3b411@host:~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions$ 
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;Now you have all of CTF’s that I wrote for kernelcon. Next you will need to get Ida-pro free.&lt;/p&gt;

&lt;h2 id=&quot;installing-ida&quot;&gt;Installing IDA&lt;/h2&gt;

&lt;p&gt;install &lt;a href=&quot;https://www.hex-rays.com/products/ida/support/download_freeware.shtml&quot;&gt;IDA-PRO 7.0 freeware&lt;/a&gt; onto your Linux machine!&lt;/p&gt;
&lt;pre&gt;&lt;code class=&quot;language-Console&quot;&gt;
Qu3b411@host:~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions$ pushd ~/Downloads
~/Downloads ~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions$
Qu3b411@host:~/Downloads$ wget https://out7.hex-rays.com/files/idafree70_linux.run
--2019-10-30 11:44:04--  https://out7.hex-rays.com/files/idafree70_linux.run
Resolving out7.hex-rays.com (out7.hex-rays.com)... 85.17.87.13
Connecting to out7.hex-rays.com (out7.hex-rays.com)|85.17.87.13|:443... connected.
HTTP request sent, awaiting response... 200 OK
Length: 47645071 (45M)
Saving to: ‘idafree70_linux.run.2’

idafree70_linux.run.2                    5%[==&amp;gt;                                                                          ]   2.32M  71.9KB/s    eta 9m 43s ^
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Let the download take place! Once complete your going to want to run the installer and follow the prompt leaving the default installation location as is!&lt;/p&gt;
&lt;pre&gt;&lt;code class=&quot;language-Console&quot;&gt;
Qu3b411@host:~/Downloads$ chmod +x ./idafree70.linux.run
Qu3b411@host:~/Downloads$ ./idafree70_linux.run --mode text
----------------------------------------------------------------------------
Welcome to the IDA Free Setup Wizard.

----------------------------------------------------------------------------
Please read the following License Agreement. You must accept the terms of this 
agreement before continuing with the installation.

Press [Enter] to continue:
IDA Pro Freeware 7.0

This free version of IDA Pro is licensed to you for non-commercial
use (at home for personal purposes). Commercial use requires a normal
IDA Pro license. This license restriction supersedes other provisions
in the standard IDA Pro license below.

The IDA Pro computer programs, hereafter described as &quot;the software&quot;
are licensed, not sold, to you by Hex-Rays SA pursuant to the
terms and conditions of this Agreement. Hex-Rays SA reserves any
right not expressly granted to you. You own the media on which the
software is delivered but Hex-Rays SA retains ownership of all
copies of the software itself. The software is protected by copyright
law.

Each copy of the software can only be used by a single user at a time.
Each license permits the user to install the software on personal laptop
and home computer, provided that no other user uses the software on those
computers.

This license also allows you to make as many copies of the installation media
as you need for backup or installation purposes.

Press [Enter] to continue:
Restrictions

You may not distribute copies of the software to another party or
electronically transfer the software from one computer to another if
one computer belongs to another party.

You may not modify, adapt, translate, rent, lease, resell, distribute,
or create derivative works based upon the software or any part
thereof.

Limited Warranty and Disclaimers

The software is provided &quot;as is&quot; without warranty of any kind.
Hex-Rays SA expressly disclaims all implied warranties, included
but not limited to the implied warranties of merchantability and
fitness for a particular purpose. Hex-Rays SA does not guarantee
the software or any accompanying materials in terms of their
correctness, accuracy, reliability, or otherwise. The entire risk as
to the results and performance of the software and written materials
is assumed by you.

Complete Statement of Warranty

Press [Enter] to continue:
The limited warranty provided in preceding paragraphs are the only
warranties of any kind made by Hex-Rays SA on this product. No
oral or written information or advice given by Hex-Rays SA, its
dealers, distributors, agents or employees shall create a warranty or
in any way increase the scope of this warranty, and you may not rely
on any such information or advice. This warranty gives you specific
legal rights. You may have other rights, which vary from country to
country.

Limitation of Liability.

In no event will Hex-Rays SA or its employees be liable to you
for any consequential, incidental, or indirect damages arising out of
the use or the inability to use the software or accompanying written
material. This includes damages for loss of business profits, business
interruption and loss of business information. The liability of
Hex-Rays SA for actual damages for any cause whatsoever is
limited to the money paid for the software that caused the damages.

Termination

This license is effective until terminated. It will terminate
immediately without notice if you fail to comply with any of its
Press [Enter] to continue:
provisions. Upon termination you must destroy the software and all
copies thereof. You may terminate this license at any time by
destroying the software and all copies thereof.

Disputes

Disputes related to this agreement will be dealt with in the district court of
Liège, Belgium.

Press [Enter] to continue:

Do you accept this license? [y/n]: y

----------------------------------------------------------------------------
Please specify the directory where IDA Free will be installed.

Installation Directory [/home/host/idafree-7.0]: 

----------------------------------------------------------------------------
Setup is now ready to begin installing IDA Free on your computer.

Do you want to continue? [Y/n]: y

----------------------------------------------------------------------------
Please wait while Setup installs IDA Free on your computer.

 Installing
 0% ______________ 50% ______________ 100%
 #########################################

----------------------------------------------------------------------------
Setup has finished installing IDA Free on your computer.
&lt;/code&gt;&lt;/pre&gt;
&lt;h1 id=&quot;the-challenges&quot;&gt;The Challenges&lt;/h1&gt;
&lt;p&gt;These challenges were themed after Jurassic Park and some of these challenges cannot be solved without understanding the refrences so keep that in mind! Now that you have the tools set up I would encourage you to actually attempt to solve the challenges yourself!,&lt;/p&gt;

&lt;h2 id=&quot;ah-ah-ah-you-didnt-say-the-magic-word&quot;&gt;Ah Ah Ah, You Didn’t Say the magic Word!&lt;/h2&gt;

&lt;p&gt;For this challenge you must watch the &lt;a href=&quot;https://www.youtube.com/watch?v=RfiQYRn7fBg&quot;&gt;video&lt;/a&gt; that was provided during the CTF, without it there is no way to solve the challenge!&lt;/p&gt;

&lt;p&gt;In your Console do the following:&lt;/p&gt;

&lt;pre&gt;&lt;code class=&quot;language-Console&quot;&gt;

Qu3b411@host:~/Downloads$ pdpd; cd ./ah-ah-ah,-You-didnt-say-the-magic-word/challenge/
Qu3b411@host:~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions/ah-ah-ah,-You-didnt-say-the-magic-word/challenge$ls -l
total 40
-rw-rw-r-- 1 qu3b411 qu3b411   169 Oct 30 11:09 ReadMe.md
-rwxrwxr-x 1 qu3b411 qu3b411 17112 Oct 30 11:09 YouDidntSayTheMagicWord
Qu3b411@host:~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions/ah-ah-ah,-You-didnt-say-the-magic-word/challenge$./YouDidntSayTheMagicWord
Jurassic Park, System Security Interface
Version 4.0.5, Alpha E
Ready...
&amp;gt; 
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Notice the Simularity between the video and the provided interface. This was Intentional. When you run this, you must copy the input from the video.&lt;/p&gt;

&lt;pre&gt;&lt;code class=&quot;language-Console&quot;&gt;Jurassic Park, System Security Interface
Version 4.0.5, Alpha E
Ready...
&amp;gt; access security
access: PERMISSION DENIED.
&amp;gt; access security grid 
access: PERMISSION DENIED.
&amp;gt; access main security grid
access: PERMISSION DENIED....and...
YOU DIDN&apos;T CHANGE THE MAGIC PARAMATER!
YOU DIDN&apos;T CHANGE THE MAGIC PARAMATER!
YOU DIDN&apos;T CHANGE THE MAGIC PARAMATER!
YOU DIDN&apos;T CHANGE THE MAGIC PARAMATER!
YOU DIDN&apos;T CHANGE THE MAGIC PARAMATER!
YOU DIDN&apos;T CHANGE THE MAGIC PARAMATER!
YOU DIDN&apos;T CHANGE THE MAGIC PARAMATER!
YOU DIDN&apos;T CHANGE THE MAGIC PARAMATER!
^C
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Hit ctrl+C to stop the loop from printing the warning message. Obviously we are going to have to change a function paramater. This means its time to start reversing the binary! Run IDA against the binary!&lt;/p&gt;

&lt;pre&gt;&lt;code class=&quot;language-Console&quot;&gt;Qu3b411@host:~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions/ah-ah-ah,-You-didnt-say-the-magic-word/challenge$~/idafree-7.0/ida64 ./YouDidntSayTheMagicWord
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;When presented with the following popup window select ok.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/Ahahah1.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Then you will get the following options. Leave them in their default configuration and select ok.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/Ahahah2.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;By default, you should be presented with the Control Flow Diagram as such:&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/ahahah3.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Locate the function call to CruleAndUnusualExit.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/ahahah4.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;put your cursor over the  &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mov edi,0&lt;/code&gt; instruction and click, a cursor will appear where clicked! then go to&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;&apos;edit&amp;gt;Patch program&amp;gt;Assemble...&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/ahahah5.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;A small window will appear letting you edit the program, change the &lt;strong&gt;Instruction&lt;/strong&gt; Field from &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mov edi, 0&lt;/code&gt; to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mov edi, 1&lt;/code&gt; and click &lt;strong&gt;ok&lt;/strong&gt;!&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/ahahah6.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;now click &lt;strong&gt;Cancel&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/ahahah7.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Apply the patch to the input file by navigating to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Edit&amp;gt;Patch program&amp;gt;Apply patches to input file...&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/ahahah8.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;When presented with the following screen click ok!&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/ahahah9.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Navigate back to your Console window and hit CTRL+c and ida will close leaving you in the terminal! then execute the following command to get the Kernel!&lt;/p&gt;
&lt;pre&gt;&lt;code class=&quot;language-Console&quot;&gt;Qu3b411@host:~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions/ah-ah-ah,-You-didnt-say-the-magic-word/challenge$ ./YouDidntSayTheMagicWord 
Jurassic Park, System Security Interface
Version 4.0.5, Alpha E
Ready...
&amp;gt; access security
access: PERMISSION DENIED.
&amp;gt; access security grid
access: PERMISSION DENIED.
&amp;gt; access main security grid
kernel{74f2880d7deff82f118d2a412dc360c5}
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Congratulations the flag is &lt;strong&gt;kernel{74f2880d7deff82f118d2a412dc360c5}&lt;/strong&gt;.&lt;/p&gt;

&lt;h2 id=&quot;we-used-the-complete-dna-of-a-frog-to-fill-in-the-holes-and-complete-the-code&quot;&gt;We used the complete DNA of a frog to fill in the holes and complete the code.&lt;/h2&gt;

&lt;p&gt;Issue the following command in your console window to navigate to this challenge directory.&lt;/p&gt;

&lt;pre&gt;&lt;code class=&quot;language-Console&quot;&gt;Qu3b411@host:~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions/ah-ah-ah,-You-didnt-say-the-magic-word/challenge$ cd ../../we-used-the-complete-DNA-of-a-frog-to-fill-in-the-holes-and-complete-the-code/challenge/
Qu3b411@host:~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions/we-used-the-complete-DNA-of-a-frog-to-fill-in-the-holes-and-complete-the-code/challenge$ ls -l
total 28
-rwxrwxr-x 1 qu3b411 qu3b411 22936 Oct 30 11:09 DNASequence
-rw-rw-r-- 1 qu3b411 qu3b411   820 Oct 30 11:09 ReadMe.md
Qu3b411@host:~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions/we-used-the-complete-DNA-of-a-frog-to-fill-in-the-holes-and-complete-the-code/challenge$ ./DNASequence
You did not correct the dna strand, your baby dino is a mutated freek of nature.
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Their is no input, so lets start disassembling the code and see whats happening,&lt;/p&gt;
&lt;pre&gt;&lt;code class=&quot;language-Console&quot;&gt;Qu3b411@host:~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions/we-used-the-complete-DNA-of-a-frog-to-fill-in-the-holes-and-complete-the-code/challenge$  ~/idafree-7.0/ida64 ./DNASequence 
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;When presented with the following screen you dont have to change any settings, just click ok to continue loading the file.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/DNA1.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;in the function list you will notice several 3 letter combinations. these functions return a numerical representation of that string! you will also notice &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;HoleInDNA&lt;/code&gt;,&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DinoDnaSeq&lt;/code&gt;,andFrogD&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;naSeq&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/DNA2.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;By this point the problem should be clear to you based on the name of this Challenge “We used the complete DNA of a frog to fill in the holes and complete the code”! Its not my style to give red herrings and bad clues… I like a challenge that forces one to tackle the problem in a straight out technical manner. Lets take a look inside of the DinoDnaSeq and the FrogDnaSeq and see what’s going on!&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/DNA3.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;all throughout the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DinoDnaSeq&lt;/code&gt; we see calls to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;HoleInDNA&lt;/code&gt;; these calls, as you may have noticed, adversly effect the control flow of the Assembly. You can’t just change the function call. It just wont work the way you want it to.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/DNA4.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;However if you look at the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;FrogDnaSeq&lt;/code&gt; you may notice a nice clean control flow that would be a lot easier to manipulate, for this solution that’s exactly what I’m going to do, but first we have to construct a table to track the function calls. That table might look something like this!&lt;/p&gt;

&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;Dino start&lt;/th&gt;
      &lt;th&gt;Frog&lt;/th&gt;
      &lt;th&gt;Dino Fix&lt;/th&gt;
      &lt;th&gt;ARG&lt;/th&gt;
      &lt;th&gt; &lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;GUC&lt;/td&gt;
      &lt;td&gt;UAC&lt;/td&gt;
      &lt;td&gt;GUC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;CCU&lt;/td&gt;
      &lt;td&gt;CGU&lt;/td&gt;
      &lt;td&gt;CCU&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;GCU&lt;/td&gt;
      &lt;td&gt;GCC&lt;/td&gt;
      &lt;td&gt;GCU&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;UGU&lt;/td&gt;
      &lt;td&gt;ACU&lt;/td&gt;
      &lt;td&gt;UGU&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;HoleInDNA&lt;/td&gt;
      &lt;td&gt;GUC&lt;/td&gt;
      &lt;td&gt;GUC&lt;/td&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;ACA&lt;/td&gt;
      &lt;td&gt;ACA&lt;/td&gt;
      &lt;td&gt;ACA&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;AAU&lt;/td&gt;
      &lt;td&gt;AAU&lt;/td&gt;
      &lt;td&gt;AAU&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;GUA&lt;/td&gt;
      &lt;td&gt;GUA&lt;/td&gt;
      &lt;td&gt;GUA&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;HoleInDNA&lt;/td&gt;
      &lt;td&gt;GGG&lt;/td&gt;
      &lt;td&gt;GGG&lt;/td&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;UUU&lt;/td&gt;
      &lt;td&gt;UGU&lt;/td&gt;
      &lt;td&gt;UUU&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;GAC&lt;/td&gt;
      &lt;td&gt;GAG&lt;/td&gt;
      &lt;td&gt;GAC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;CGU&lt;/td&gt;
      &lt;td&gt;GUA&lt;/td&gt;
      &lt;td&gt;CGU&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;GCC&lt;/td&gt;
      &lt;td&gt;GCA&lt;/td&gt;
      &lt;td&gt;GCC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;ACU&lt;/td&gt;
      &lt;td&gt;AGU&lt;/td&gt;
      &lt;td&gt;ACU&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;GUA&lt;/td&gt;
      &lt;td&gt;CCA&lt;/td&gt;
      &lt;td&gt;GUA&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;AAA&lt;/td&gt;
      &lt;td&gt;GAA&lt;/td&gt;
      &lt;td&gt;AAA&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;CGG&lt;/td&gt;
      &lt;td&gt;CGC&lt;/td&gt;
      &lt;td&gt;CGG&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;GCU&lt;/td&gt;
      &lt;td&gt;UUU&lt;/td&gt;
      &lt;td&gt;GCU&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;UCC&lt;/td&gt;
      &lt;td&gt;CUC&lt;/td&gt;
      &lt;td&gt;UCC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;CGC&lt;/td&gt;
      &lt;td&gt;CGU&lt;/td&gt;
      &lt;td&gt;CGC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;HoleInDNA&lt;/td&gt;
      &lt;td&gt;AGC&lt;/td&gt;
      &lt;td&gt;AGC&lt;/td&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;ACG&lt;/td&gt;
      &lt;td&gt;UGC&lt;/td&gt;
      &lt;td&gt;ACG&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;AGG&lt;/td&gt;
      &lt;td&gt;GCA&lt;/td&gt;
      &lt;td&gt;AGG&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;CUA&lt;/td&gt;
      &lt;td&gt;UAU&lt;/td&gt;
      &lt;td&gt;CUA&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;CAC&lt;/td&gt;
      &lt;td&gt;GCA&lt;/td&gt;
      &lt;td&gt;CAC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;GGG&lt;/td&gt;
      &lt;td&gt;AGA&lt;/td&gt;
      &lt;td&gt;GGG&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;CAU&lt;/td&gt;
      &lt;td&gt;AAA&lt;/td&gt;
      &lt;td&gt;CAU&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;HoleInDNA&lt;/td&gt;
      &lt;td&gt;CUA&lt;/td&gt;
      &lt;td&gt;CUA&lt;/td&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;UCU&lt;/td&gt;
      &lt;td&gt;ACA&lt;/td&gt;
      &lt;td&gt;UCU&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;CAU&lt;/td&gt;
      &lt;td&gt;AGC&lt;/td&gt;
      &lt;td&gt;CAU&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;GUG&lt;/td&gt;
      &lt;td&gt;UGA&lt;/td&gt;
      &lt;td&gt;GUG&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;UGA&lt;/td&gt;
      &lt;td&gt;GCU&lt;/td&gt;
      &lt;td&gt;UGA&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;GCA&lt;/td&gt;
      &lt;td&gt;CUC&lt;/td&gt;
      &lt;td&gt;GCA&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;CCC&lt;/td&gt;
      &lt;td&gt;CGA&lt;/td&gt;
      &lt;td&gt;CCC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;HoleInDNA&lt;/td&gt;
      &lt;td&gt;AGC&lt;/td&gt;
      &lt;td&gt;AGC&lt;/td&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;UCC&lt;/td&gt;
      &lt;td&gt;UUG&lt;/td&gt;
      &lt;td&gt;UCC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;UUC&lt;/td&gt;
      &lt;td&gt;GUC&lt;/td&gt;
      &lt;td&gt;UUC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;AGG&lt;/td&gt;
      &lt;td&gt;CGU&lt;/td&gt;
      &lt;td&gt;AGG&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;AUU&lt;/td&gt;
      &lt;td&gt;AAA&lt;/td&gt;
      &lt;td&gt;AUU&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;GUC&lt;/td&gt;
      &lt;td&gt;GGC&lt;/td&gt;
      &lt;td&gt;GUC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;ACG&lt;/td&gt;
      &lt;td&gt;CCA&lt;/td&gt;
      &lt;td&gt;ACG&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;HoleInDNA&lt;/td&gt;
      &lt;td&gt;CUU&lt;/td&gt;
      &lt;td&gt;CUU&lt;/td&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;GCA&lt;/td&gt;
      &lt;td&gt;ACA&lt;/td&gt;
      &lt;td&gt;GCA&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;CGC&lt;/td&gt;
      &lt;td&gt;CAA&lt;/td&gt;
      &lt;td&gt;CGC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;UCU&lt;/td&gt;
      &lt;td&gt;UUC&lt;/td&gt;
      &lt;td&gt;UCU&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;UAC&lt;/td&gt;
      &lt;td&gt;GUG&lt;/td&gt;
      &lt;td&gt;UAC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;GGA&lt;/td&gt;
      &lt;td&gt;GCA&lt;/td&gt;
      &lt;td&gt;GGA&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;AUA&lt;/td&gt;
      &lt;td&gt;AGA&lt;/td&gt;
      &lt;td&gt;AUA&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;CGA&lt;/td&gt;
      &lt;td&gt;AAG&lt;/td&gt;
      &lt;td&gt;CGA&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;GUC&lt;/td&gt;
      &lt;td&gt;UCG&lt;/td&gt;
      &lt;td&gt;GUC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;ACG&lt;/td&gt;
      &lt;td&gt;GCU&lt;/td&gt;
      &lt;td&gt;ACG&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;CCC&lt;/td&gt;
      &lt;td&gt;GCC&lt;/td&gt;
      &lt;td&gt;CCC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;CGU&lt;/td&gt;
      &lt;td&gt;UCG&lt;/td&gt;
      &lt;td&gt;CGU&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;ACC&lt;/td&gt;
      &lt;td&gt;UAA&lt;/td&gt;
      &lt;td&gt;ACC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;ACG&lt;/td&gt;
      &lt;td&gt;AUU&lt;/td&gt;
      &lt;td&gt;ACG&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;HoleInDNA&lt;/td&gt;
      &lt;td&gt;GUA&lt;/td&gt;
      &lt;td&gt;GUA&lt;/td&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;ACC&lt;/td&gt;
      &lt;td&gt;CCG&lt;/td&gt;
      &lt;td&gt;ACC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;GUG&lt;/td&gt;
      &lt;td&gt;CAC&lt;/td&gt;
      &lt;td&gt;GUG&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;CUC&lt;/td&gt;
      &lt;td&gt;GUG&lt;/td&gt;
      &lt;td&gt;CUC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;AGU&lt;/td&gt;
      &lt;td&gt;GGU&lt;/td&gt;
      &lt;td&gt;AGU&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;UCC&lt;/td&gt;
      &lt;td&gt;CAC&lt;/td&gt;
      &lt;td&gt;UCC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;HoleInDNA&lt;/td&gt;
      &lt;td&gt;GCA&lt;/td&gt;
      &lt;td&gt;GCA&lt;/td&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;GGA&lt;/td&gt;
      &lt;td&gt;AUG&lt;/td&gt;
      &lt;td&gt;GGA&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;UGC&lt;/td&gt;
      &lt;td&gt;CCU&lt;/td&gt;
      &lt;td&gt;UGC&lt;/td&gt;
      &lt;td&gt;0&lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;Which means it’s time to start patching the program up; First let’s patch up the main program to call the correct function. For this solution we will actually be calling &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;FrogDnaSeq&lt;/code&gt;. You must find the call to DinoDnaSeq, once located,highlight it and select &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Edit&amp;gt;Patch program&amp;gt;Assemble...&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/DNA5.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;The following window appears, you can then edit the function call, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;call DinoDnaSeq&lt;/code&gt; should be changed to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;call FrogDnaSeq&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/DNA_6.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;It’s now time to start editing the FrogDnaSeq function. To do this traverse the table and edit the function calls in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;FrogDnaSeq&lt;/code&gt; to their respective values, as dictated by the table we constructed previously. Keep in mind it is important to change the function paramaters to correspond to where the DNA was inherited from!&lt;/p&gt;

&lt;p&gt;The register used to pass the paramater to the function call is &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;edi&lt;/code&gt; ,the value being passed to the function will always occur immediatly before the call itself!&lt;/p&gt;

&lt;p&gt;Let’s walk through the first function call together. Start by highlighting &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mov edi, 0&lt;/code&gt; and selecting &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Edit&amp;gt;Patch program&amp;gt; Assemble&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/DNA7.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Modify the instruction from &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mov edi,1&lt;/code&gt; to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mov edi,0&lt;/code&gt; and select &lt;strong&gt;ok&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/DNA8.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Next modify the function call itself, Start by highlighting &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;call UAC&lt;/code&gt; and then select &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Edit&amp;gt;Patch program&amp;gt;Assemble...&lt;/code&gt; 
&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/DNA9.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;In the Instructions Field modify &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;call UAC&lt;/code&gt; to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;call GUC&lt;/code&gt; and press &lt;strong&gt;OK&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/DNA10.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Hit &lt;strong&gt;Cancel&lt;/strong&gt; on the proceeding screen, then repeat these steps modifying each function call to the corresponding value on the provided table. Remember that calls to HoleInDNA are voids that can be ignored, skip over that function call and move to the next… &lt;strong&gt;Do not modify&lt;/strong&gt; the paramater being passed to HoleInDna.&lt;/p&gt;

&lt;p&gt;Once you have applied the patches to the binary go to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Edit&amp;gt;Patch program&amp;gt;Apply patches to input&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/DNA11.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;the following window will appear, click &lt;strong&gt;ok&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/Qu3b411/qu3b411.github.io/master/assets/DNA12.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Navigate back to your console and hit CTRL+c to terminate ida, then run the modified binary&lt;/p&gt;

&lt;pre&gt;&lt;code class=&quot;language-Console&quot;&gt;Qu3b411@host:~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions/we-used-the-complete-DNA-of-a-frog-to-fill-in-the-holes-and-complete-the-code/challenge$ ./DNASequence
Kernel{64bdfb39f4d8e2624c8ee42604c0150e}
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Congratulations, You now have the Second ctf flag!&lt;/p&gt;

&lt;h2 id=&quot;i-did-a-test-run-on-this-thing-it-took-me-twenty-minutes&quot;&gt;I did a test run on this thing it took me twenty minutes&lt;/h2&gt;

&lt;p&gt;This is the last one to be solved during KernelCon, This is a Misc challenge that does not require any reverse engineering. instead one must execute a timing attack against the password input, so lets get started!
in your console window execute the following commands&lt;/p&gt;

&lt;pre&gt;&lt;code class=&quot;language-Console&quot;&gt;Qu3b411@host:~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions/we-used-the-complete-DNA-of-a-frog-to-fill-in-the-holes-and-complete-the-code/challenge$ cd ../../I-did-a-test-run-on-this-thing-it-took-me-twenty-minutes/challange
Qu3b411@host:~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions//I-did-a-test-run-on-this-thing-it-took-me-twenty-minutes/challange$ chmod +x ./VulnerableLogin
Login: 
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The hint given during this challenge was &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;{0-9},{a-f},k,r,n,l,&apos;}&apos;,&apos;{&apos;&lt;/code&gt;. This should have tipped off those whom were observent that the input to the login was the kernel flag!&lt;/p&gt;

&lt;p&gt;In the Console do the following.&lt;/p&gt;

&lt;pre&gt;&lt;code class=&quot;language-Console&quot;&gt;Qu3b411@host:~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions//I-did-a-test-run-on-this-thing-it-took-me-twenty-minutes/challange$ vim TimingAttack.pl
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You will then create a perl script, hit &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;i&lt;/code&gt; to enter insertion mode in the vim console, write the following script&lt;/p&gt;

&lt;div class=&quot;language-perl highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;c1&quot;&gt;#!/usr/bin/env perl&lt;/span&gt;

&lt;span class=&quot;k&quot;&gt;use&lt;/span&gt; &lt;span class=&quot;nn&quot;&gt;Time::&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;HiRes&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;;&lt;/span&gt;

&lt;span class=&quot;k&quot;&gt;my&lt;/span&gt; &lt;span class=&quot;nv&quot;&gt;$str&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;&apos;&lt;/span&gt;&lt;span class=&quot;s1&quot;&gt;kernel{&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;&apos;;&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;#Populate the base string with &apos;Kernel{&apos; to reduce characters in the attack space!&lt;/span&gt;

&lt;span class=&quot;c1&quot;&gt;# the hash value occupies 32 bytes in the flag!&lt;/span&gt;
&lt;span class=&quot;k&quot;&gt;for&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;my&lt;/span&gt; &lt;span class=&quot;nv&quot;&gt;$x&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;nv&quot;&gt;$x&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;&amp;lt;&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;32&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;nv&quot;&gt;$x&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;++&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;p&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;k&quot;&gt;my&lt;/span&gt; &lt;span class=&quot;nv&quot;&gt;@char&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;# an array to store the character that has the longest time return, this array also stores the time return&lt;/span&gt;
  &lt;span class=&quot;k&quot;&gt;for&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;my&lt;/span&gt; &lt;span class=&quot;nv&quot;&gt;$n&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;((&apos;&lt;/span&gt;&lt;span class=&quot;s1&quot;&gt;a&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;&apos;&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;..&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;&apos;&lt;/span&gt;&lt;span class=&quot;s1&quot;&gt;f&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;&apos;),(&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;..&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;9&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;))&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;#iterate over the characters a-f0-9&lt;/span&gt;
  &lt;span class=&quot;p&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;k&quot;&gt;my&lt;/span&gt; &lt;span class=&quot;nv&quot;&gt;$t&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;nn&quot;&gt;Timer::HiRes::&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;gettimeofday&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;()];&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;#get the current system time&lt;/span&gt;
    &lt;span class=&quot;nb&quot;&gt;system&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&quot;&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;echo &lt;/span&gt;&lt;span class=&quot;si&quot;&gt;$str$n&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt; |./VulnerableLogin &amp;gt;&amp;gt; /dev/null&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;&quot;);&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;# run the program with the password being built through the timing attack, redirect all output to /dev/null!&lt;/span&gt;
    &lt;span class=&quot;nv&quot;&gt;$t&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;nn&quot;&gt;Timer::HiRes::&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;tv_interval&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$t&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;);&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;# record the execution time back into t.&lt;/span&gt;
    &lt;span class=&quot;k&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;!&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;char&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;#if char is not defined, define it&lt;/span&gt;
    &lt;span class=&quot;p&quot;&gt;{&lt;/span&gt;
      &lt;span class=&quot;nv&quot;&gt;@char&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$n&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$t&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;);&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;#save character, return time in that order&lt;/span&gt;
    &lt;span class=&quot;p&quot;&gt;}&lt;/span&gt;
    &lt;span class=&quot;k&quot;&gt;elsif&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$t&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;nv&quot;&gt;$char&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;])&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;# if the execution time is greater then the prior time then retest the character&lt;/span&gt;
    &lt;span class=&quot;p&quot;&gt;{&lt;/span&gt;
       &lt;span class=&quot;k&quot;&gt;my&lt;/span&gt; &lt;span class=&quot;nv&quot;&gt;$t&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;nn&quot;&gt;Timer::HiRes::&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;gettimeofday&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;()];&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;#get the current system time&lt;/span&gt;
       &lt;span class=&quot;nb&quot;&gt;system&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&quot;&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;echo &lt;/span&gt;&lt;span class=&quot;si&quot;&gt;$str$n&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt; |./VulnerableLogin &amp;gt;&amp;gt; /dev/null&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;&quot;);&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;# run the program with the password being built through the timing attack, redirect all output to /dev/null!&lt;/span&gt;
       &lt;span class=&quot;nv&quot;&gt;$t&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;nn&quot;&gt;Timer::HiRes::&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;tv_interval&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$t&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;);&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;# record the execution time back into t.&lt;/span&gt;
       &lt;span class=&quot;k&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$t&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;nv&quot;&gt;$char&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;])&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;# if it is not a false positive&lt;/span&gt;
       &lt;span class=&quot;p&quot;&gt;{&lt;/span&gt;
         &lt;span class=&quot;nv&quot;&gt;@char&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$n&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$t&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;);&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;#save character, return time in that order&lt;/span&gt;
       &lt;span class=&quot;p&quot;&gt;}&lt;/span&gt;
    &lt;span class=&quot;p&quot;&gt;}&lt;/span&gt;
  &lt;span class=&quot;p&quot;&gt;}&lt;/span&gt;
  &lt;span class=&quot;nv&quot;&gt;$str&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.=&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;si&quot;&gt;$char&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;[0]&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;&quot;;&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;#append the character to the login string&lt;/span&gt;
  &lt;span class=&quot;k&quot;&gt;print&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;si&quot;&gt;$str&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\n&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;&quot;;&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;# print the character to view the progress  of your attack!&lt;/span&gt;
&lt;span class=&quot;p&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;k&quot;&gt;print&lt;/span&gt; &lt;span class=&quot;nv&quot;&gt;$str&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\n&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;&quot;;&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;#print the flag with closing bracket&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;Hit the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;esc&lt;/code&gt; button then type &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;:wq!&lt;/code&gt; into your console followed by hitting enter, you will return back to the console screen. you can now run the script, let it run, it will take some time to get the flag!&lt;/p&gt;

&lt;pre&gt;&lt;code class=&quot;language-Console&quot;&gt;Qu3b411@host:~/kernelcon-2019-ctf-qu3b411/kernelcon-CTF-2019-solutions//I-did-a-test-run-on-this-thing-it-took-me-twenty-minutes/challange$ perl TimingAttack.pl
kernel{e
kernel{e2
kernel{e2c
kernel{e2c7
kernel{e2c7b
kernel{e2c7bf
kernel{e2c7bf3
kernel{e2c7bf33
kernel{e2c7bf336
kernel{e2c7bf3367
kernel{e2c7bf33676
kernel{e2c7bf336767
kernel{e2c7bf3367678
kernel{e2c7bf33676782
kernel{e2c7bf336767828
kernel{e2c7bf3367678289
kernel{e2c7bf33676782893
kernel{e2c7bf336767828931
kernel{e2c7bf336767828931c
kernel{e2c7bf336767828931c7
kernel{e2c7bf336767828931c77
kernel{e2c7bf336767828931c775
kernel{e2c7bf336767828931c7750
kernel{e2c7bf336767828931c7750c
kernel{e2c7bf336767828931c7750cf
kernel{e2c7bf336767828931c7750cfe
kernel{e2c7bf336767828931c7750cfe3
kernel{e2c7bf336767828931c7750cfe31
kernel{e2c7bf336767828931c7750cfe31d
kernel{e2c7bf336767828931c7750cfe31de
kernel{e2c7bf336767828931c7750cfe31de8
kernel{e2c7bf336767828931c7750cfe31de81
kernel{e2c7bf336767828931c7750cfe31de81}
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Congratulations You now have the third and final kernel flag!&lt;/p&gt;

&lt;h1 id=&quot;i-look-forward-to-seeing-everyone-at-kernelcon-2020&quot;&gt;I look forward to seeing everyone at &lt;a href=&quot;https://kernelcon.org/&quot;&gt;KernelCon 2020&lt;/a&gt;&lt;/h1&gt;

&lt;p&gt;Thank you for reading through my blog post. Be sure to register for the Con so you can see the new CTF’s that I have been working on throughout the year.&lt;/p&gt;
</description>
        <pubDate>Wed, 30 Oct 2019 00:00:00 +0000</pubDate>
        <link>https://blog.jacobmohrbutter.com//Kernelcon-2019</link>
        <link href="https://blog.jacobmohrbutter.com/Kernelcon-2019"/>
        <guid isPermaLink="true">https://blog.jacobmohrbutter.com/Kernelcon-2019</guid>
      </item>
    
  </channel>
</rss>
