[{"content":"\u003cp\u003eThe \u003cstrong\u003e2025 NSA Codebreaker Challenge\u003c/strong\u003e was my first Codebreaker, and I completed \u003cstrong\u003eall seven tasks\u003c/strong\u003e, becoming one of \u003cstrong\u003e82 students to finish the full challenge\u003c/strong\u003e. It was a chance to connect skills that I had often practiced separately: filesystem forensics, packet analysis, memory analysis, reverse engineering, cryptography, and application security.\u003c/p\u003e\n\u003cp\u003eThe challenge used a fictional investigation into suspicious activity on a military development network. Each task carried the investigation forward, so an answer was more than a flag—it supplied context for the next question.\u003c/p\u003e\n\u003cp\u003eI\u0026rsquo;ve turned my \u003ca href=\"https://github.com/XSS3cut10n3r/My-NSA-Codebreaker-2025\"\u003eCodebreaker repository\u003c/a\u003e into this series so that each task has its own post, with this page as the starting point.\u003c/p\u003e\n\u003ch3 id=\"read-the-series\"\u003eRead the series\u003c/h3\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth\u003eChallenge\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eFocus\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"/posts/nsa-codebreaker-2025-task-1/\"\u003e1: Getting Started\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eForensics\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"/posts/nsa-codebreaker-2025-task-2/\"\u003e2: The Hunt Continues\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eNetwork Forensics\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"/posts/nsa-codebreaker-2025-task-3/\"\u003e3: Digging Deeper\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eReverse Engineering\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"/posts/nsa-codebreaker-2025-task-4/\"\u003e4: Unpacking Insight\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eMalware Analysis\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"/posts/nsa-codebreaker-2025-task-5/\"\u003e5: Putting It All Together\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCryptanalysis\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"/posts/nsa-codebreaker-2025-task-6/\"\u003e6: Crossing the Channel\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eVulnerability Research\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"/posts/nsa-codebreaker-2025-task-7/\"\u003e7: Finale\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAndroid Security\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3 id=\"the-moments-that-stood-out\"\u003eThe moments that stood out\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTask 4 was my favorite.\u003c/strong\u003e The obfuscated Linux sample pushed me into malware analysis techniques I had not used before. Understanding the layers around the payload, observing its memory-backed behavior, and recognizing how an encrypted path was represented made the problem feel like a puzzle coming together.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eTask 6 changed the kind of reasoning I needed.\u003c/strong\u003e Instead of finding hidden code, I had to notice that an application integration was checking one permission boundary while acting on another. It showed how a subtle authorization mistake can matter more than complicated implementation.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eTask 7 brought the pieces together.\u003c/strong\u003e Reverse engineering the Android application meant following data from an input file through extraction and into the parts of the app that consumed it. The relationship between writable data and dynamically loaded code was the key security lesson.\u003c/p\u003e\n\u003ch3 id=\"what-i-would-do-differently\"\u003eWhat I would do differently\u003c/h3\u003e\n\u003cp\u003eI spent too much time early on trying possibilities before stepping back to understand the mechanism. In Task 2, systematic filtering would have exposed the conflicting DNS responses sooner than manually inspecting traffic.\u003c/p\u003e\n\u003cp\u003eI also learned to keep better notes. Some of my repository writeups are much more complete than others: \u003cstrong\u003eTask 3 records only the initial setup and completion, and Task 5\u0026rsquo;s solution is unfinished\u003c/strong\u003e. Their posts make those limits explicit rather than filling in details from guesswork.\u003c/p\u003e\n\u003cp\u003eThe habit I want to carry forward is simple: record the evidence, explain what it supports, and keep the next investigative question clear.\u003c/p\u003e\n\u003ch3 id=\"from-the-challenge-to-my-current-work\"\u003eFrom the challenge to my current work\u003c/h3\u003e\n\u003cp\u003eCompleting all seven tasks earned me a \u003cstrong\u003e$4,500 SANS Institute scholarship\u003c/strong\u003e in October 2025. The challenge also gave me practice connecting evidence across different technical domains.\u003c/p\u003e\n\u003cp\u003eI\u0026rsquo;m now an \u003cstrong\u003eAssociate Security Consultant at LRQA\u003c/strong\u003e, focused on \u003cstrong\u003eimplementing AI into penetration testing workflows\u003c/strong\u003e while contributing to mobile, web application, API, and infrastructure tests. Codebreaker\u0026rsquo;s lessons about methodical analysis and documentation remain relevant to that work.\u003c/p\u003e\n\u003cp\u003eStart with \u003ca href=\"/posts/nsa-codebreaker-2025-task-1/\"\u003eTask 1: Getting Started\u003c/a\u003e or choose a topic from the table above.\u003c/p\u003e\n","date":"2026-10-03","dateFormatted":"2026.10.03","excerpt":"\u003cp\u003eThe \u003cstrong\u003e2025 NSA Codebreaker Challenge\u003c/strong\u003e was my first Codebreaker, and I completed \u003cstrong\u003eall seven tasks\u003c/strong\u003e, becoming one of \u003cstrong\u003e82 students to finish the full challenge\u003c/strong\u003e. It was a chance to connect skills that I had …\u003c/p\u003e","featured":true,"mood":null,"permalink":"/posts/nsa-codebreaker-2025/","readingTime":3,"slug":"nsa-codebreaker-2025","subtitle":"Seven tasks spanning forensics, reverse engineering, cryptanalysis, and application security","summary":"\u003cp\u003eThe \u003cstrong\u003e2025 NSA Codebreaker Challenge\u003c/strong\u003e was my first Codebreaker, and I completed \u003cstrong\u003eall seven tasks\u003c/strong\u003e, becoming one of \u003cstrong\u003e82 students to finish the full challenge\u003c/strong\u003e. It was a chance to connect skills that I had often practiced separately: filesystem forensics, packet analysis, memory analysis, reverse engineering, cryptography, and application security.\u003c/p\u003e\n\u003cp\u003eThe challenge used a fictional investigation into suspicious activity on a military development network. Each task carried the investigation forward, so an answer was more than a flag—it supplied context for the next question.\u003c/p\u003e","tags":["NSA Codebreaker 2025","ctf","reflection"],"title":"NSA Codebreaker 2025: My First Full Challenge","url":"/posts/nsa-codebreaker-2025/","wordCount":480},{"content":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eThe final task supplied a \u003cstrong\u003ecustom Android APK\u003c/strong\u003e used to archive chat messages. It brought together application reverse engineering, archive handling, and reasoning about how data moves through a program.\u003c/p\u003e\n\u003ch3 id=\"starting-with-the-application\"\u003eStarting with the application\u003c/h3\u003e\n\u003cp\u003eI first reviewed the supplied dependency licenses. An old library looked like a promising lead, but my notes make clear that the decisive issue emerged from examining the application\u0026rsquo;s own handling of files.\u003c/p\u003e\n\u003cp\u003eThat was a useful correction to my initial approach. Dependency age can guide investigation, but it does not establish which behavior is responsible for a vulnerability.\u003c/p\u003e\n\u003ch3 id=\"the-underlying-security-problem\"\u003eThe underlying security problem\u003c/h3\u003e\n\u003cp\u003eAt a high level, the app failed to keep archive extraction reliably contained within its intended directory. It also dynamically loaded format-handling code from writable storage. Those behaviors created a dangerous relationship between \u003cstrong\u003euntrusted archived data\u003c/strong\u003e and \u003cstrong\u003eexecutable application components\u003c/strong\u003e.\u003c/p\u003e\n\u003cp\u003eThe impact depended on their interaction. File handling was not merely a storage concern once writable content could influence which code the application loaded.\u003c/p\u003e\n\u003ch3 id=\"validation-in-the-challenge-environment\"\u003eValidation in the challenge environment\u003c/h3\u003e\n\u003cp\u003eMy original notes record testing with an Android emulator and completing the final challenge. This post focuses on the root cause and lessons from that analysis, rather than reproducing the payload or delivery procedure.\u003c/p\u003e\n\u003ch3 id=\"defensive-implications\"\u003eDefensive implications\u003c/h3\u003e\n\u003cp\u003eArchive processing should resolve and validate extraction destinations, ensuring every output remains inside the intended directory. Applications should also prevent downloaded content from replacing trusted components.\u003c/p\u003e\n\u003cp\u003eDynamic code loading requires a separate trust decision: a writable cache is not inherently a trusted source of executable code. Keeping executable components separate from untrusted content, and verifying their provenance, reduces the risk that an input file can cross that boundary.\u003c/p\u003e\n\u003ch3 id=\"what-i-took-away\"\u003eWhat I took away\u003c/h3\u003e\n\u003cp\u003eTask 7 reinforced the value of tracing the full execution flow. A file\u0026rsquo;s name, extraction destination, overwrite behavior, and eventual use all mattered to the application\u0026rsquo;s security.\u003c/p\u003e\n\u003cp\u003eFinishing the challenge brought the investigation full circle—from a suspicious filesystem artifact to understanding how an application could turn untrusted content into execution.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eBased on my \u003ca href=\"https://github.com/XSS3cut10n3r/My-NSA-Codebreaker-2025/blob/main/task7.md\"\u003eTask 7 repository notes\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025-task-6/\"\u003e← Task 6\u003c/a\u003e · \u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003eSeries overview\u003c/a\u003e\u003c/p\u003e\n","date":"2026-10-03","dateFormatted":"2026.10.03","excerpt":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eThe final task supplied a \u003cstrong\u003ecustom Android APK\u003c/strong\u003e used to archive chat messages. It brought together application reverse engineering, archive handling, and reasoning about how data moves …\u003c/p\u003e","featured":false,"mood":null,"permalink":"/posts/nsa-codebreaker-2025-task-7/","readingTime":2,"slug":"nsa-codebreaker-2025-task-7","subtitle":"Archive handling and the boundary between data and code","summary":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eThe final task supplied a \u003cstrong\u003ecustom Android APK\u003c/strong\u003e used to archive chat messages. It brought together application reverse engineering, archive handling, and reasoning about how data moves through a program.\u003c/p\u003e\n\u003ch3 id=\"starting-with-the-application\"\u003eStarting with the application\u003c/h3\u003e\n\u003cp\u003eI first reviewed the supplied dependency licenses. An old library looked like a promising lead, but my notes make clear that the decisive issue emerged from examining the application\u0026rsquo;s own handling of files.\u003c/p\u003e","tags":["NSA Codebreaker 2025","ctf","android security"],"title":"NSA Codebreaker 2025 — Task 7: Finale","url":"/posts/nsa-codebreaker-2025-task-7/","wordCount":340},{"content":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eTask 6 shifted the investigation into a \u003cstrong\u003eMattermost environment\u003c/strong\u003e. The challenge supplied persistent application data and an account with access to a limited part of the system. The objective concerned reaching the channel used by the fictional adversary.\u003c/p\u003e\n\u003ch3 id=\"reviewing-the-custom-integration\"\u003eReviewing the custom integration\u003c/h3\u003e\n\u003cp\u003eI examined the provided bot plugins and found a flaw in the logic used to manage private negotiation channels. The relevant checks established that users belonged to the \u003cstrong\u003ecurrent channel\u003c/strong\u003e, but did not adequately establish their authority to access the \u003cstrong\u003edestination channel\u003c/strong\u003e.\u003c/p\u003e\n\u003cp\u003eThat distinction was the central finding. Validating that a user exists, or belongs somewhere in the application, does not establish permission to perform an operation on a different resource.\u003c/p\u003e\n\u003ch3 id=\"understanding-the-impact\"\u003eUnderstanding the impact\u003c/h3\u003e\n\u003cp\u003eThe provided PostgreSQL data helped me understand relationships among users and channels. My notes describe using those relationships to assess the reach of the authorization flaw in the challenge environment.\u003c/p\u003e\n\u003cp\u003eThe issue was in the supplied custom bot behavior. This writeup should not be read as a claim that ordinary Mattermost installations share the same flaw.\u003c/p\u003e\n\u003ch3 id=\"defensive-implications\"\u003eDefensive implications\u003c/h3\u003e\n\u003cp\u003eA channel-management integration needs to authorize the requested operation against the destination resource. Creating a channel and restoring an existing channel also deserve distinct checks: an archived private channel can retain a security boundary that should survive its archived state.\u003c/p\u003e\n\u003cp\u003eUseful regression cases would include requests by users who are valid members of the source channel but have no permission over the destination, including previously archived private channels. Changes to membership should be auditable so that unexpected access can be investigated.\u003c/p\u003e\n\u003ch3 id=\"what-i-took-away\"\u003eWhat I took away\u003c/h3\u003e\n\u003cp\u003eThis task was a different kind of puzzle from unpacking malware. The code could look reasonable line by line while still enforcing the wrong permission boundary.\u003c/p\u003e\n\u003cp\u003eThe broader lesson was to ask what each check actually proves. Source membership answered one question; the operation required an answer about destination access.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eBased on my \u003ca href=\"https://github.com/XSS3cut10n3r/My-NSA-Codebreaker-2025/blob/main/task6.md\"\u003eTask 6 repository notes\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025-task-5/\"\u003e← Task 5\u003c/a\u003e · \u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003eSeries overview\u003c/a\u003e · \u003ca href=\"/posts/nsa-codebreaker-2025-task-7/\"\u003eTask 7 →\u003c/a\u003e\u003c/p\u003e\n","date":"2026-10-03","dateFormatted":"2026.10.03","excerpt":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eTask 6 shifted the investigation into a \u003cstrong\u003eMattermost environment\u003c/strong\u003e. The challenge supplied persistent application data and an account with access to a limited part of the system. The …\u003c/p\u003e","featured":false,"mood":null,"permalink":"/posts/nsa-codebreaker-2025-task-6/","readingTime":2,"slug":"nsa-codebreaker-2025-task-6","subtitle":"A lesson in destination-specific authorization","summary":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eTask 6 shifted the investigation into a \u003cstrong\u003eMattermost environment\u003c/strong\u003e. The challenge supplied persistent application data and an account with access to a limited part of the system. The objective concerned reaching the channel used by the fictional adversary.\u003c/p\u003e\n\u003ch3 id=\"reviewing-the-custom-integration\"\u003eReviewing the custom integration\u003c/h3\u003e\n\u003cp\u003eI examined the provided bot plugins and found a flaw in the logic used to manage private negotiation channels. The relevant checks established that users belonged to the \u003cstrong\u003ecurrent channel\u003c/strong\u003e, but did not adequately establish their authority to access the \u003cstrong\u003edestination channel\u003c/strong\u003e.\u003c/p\u003e","tags":["NSA Codebreaker 2025","ctf","vulnerability research"],"title":"NSA Codebreaker 2025 — Task 6: Crossing the Channel","url":"/posts/nsa-codebreaker-2025-task-6/","wordCount":329},{"content":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"task-5---putting-it-all-together---cryptanalysis\"\u003eTask 5 - Putting It All Together - (Cryptanalysis)\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003eNSA analysts confirm that there is solid evidence that this binary was at least part of what had been installed on the military development network. Unfortunately, we do not yet have enough information to update NSA senior leadership on this threat. We need to move forward with this investigation!\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003eThe team is stumped - they need to identify something about who was controlling this malware. They look to you. \u0026ldquo;Do you have any ideas?\u0026rdquo;\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003chr\u003e\n\u003ch2 id=\"task\"\u003eTask\u003c/h2\u003e\n\u003cp\u003eSubmit the full URL to the adversary\u0026rsquo;s server\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"writeup\"\u003eWriteup\u003c/h2\u003e\n\u003cp\u003eEnter here\u0026hellip;\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025-task-4/\"\u003e← Task 4\u003c/a\u003e · \u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003eSeries overview\u003c/a\u003e · \u003ca href=\"/posts/nsa-codebreaker-2025-task-6/\"\u003eTask 6 →\u003c/a\u003e\u003c/p\u003e\n","date":"2026-10-03","dateFormatted":"2026.10.03","excerpt":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"task-5---putting-it-all-together---cryptanalysis\"\u003eTask 5 - Putting It All Together - (Cryptanalysis)\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003eNSA analysts confirm that there is solid evidence that this binary was at least part of what had been installed on the military …\u003c/p\u003e\u003c/blockquote\u003e","featured":false,"mood":null,"permalink":"/posts/nsa-codebreaker-2025-task-5/","readingTime":1,"slug":"nsa-codebreaker-2025-task-5","subtitle":"The investigative handoff from malware to infrastructure","summary":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"task-5---putting-it-all-together---cryptanalysis\"\u003eTask 5 - Putting It All Together - (Cryptanalysis)\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003eNSA analysts confirm that there is solid evidence that this binary was at least part of what had been installed on the military development network. Unfortunately, we do not yet have enough information to update NSA senior leadership on this threat. We need to move forward with this investigation!\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003eThe team is stumped - they need to identify something about who was controlling this malware. They look to you. \u0026ldquo;Do you have any ideas?\u0026rdquo;\u003c/p\u003e","tags":["NSA Codebreaker 2025","ctf","cryptanalysis"],"title":"NSA Codebreaker 2025 — Task 5: Putting It All Together","url":"/posts/nsa-codebreaker-2025-task-5/","wordCount":108},{"content":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"task-4---unpacking-insight---malware-analysis\"\u003eTask 4 - Unpacking Insight - (Malware Analysis)\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003eOnce back at NSA the team contacts the NSA liaison at FBI to see if they have any information about what was discovered in the configuration data. FBI informs us that the facility registered to host that domain is on a watchlist for suspected criminal activity. With this tip, the FBI acquires a warrant and raids the location. Inside the facility, the server is discovered along with a suspect. The suspect is known to the FBI as a low-level malware actor. During questioning, they disclose that they are providing a service to host malware for various cybercrime groups, but recently they were contacted by a much more secretive and sophisticated customer. While they don\u0026rsquo;t appear to know anything about who is paying for the service, they provide the FBI with the malware that was hosted.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003eBack at NSA, you are provided with a copy of the file. There is a lot of high level interest in uncovering who facilitated this attack. The file appears to be obfuscated.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003eYou are tasked to work on de-obfuscating the file and report back to the team.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003chr\u003e\n\u003ch2 id=\"downloads\"\u003eDownloads\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eobfuscated file\u003c/strong\u003e (\u003ccode\u003esuspicious\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"task\"\u003eTask\u003c/h2\u003e\n\u003cp\u003eSubmit the file path the malware uses to write a file.\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"writeup\"\u003eWriteup\u003c/h2\u003e\n\u003cp\u003eInitial file identification revealed the given sample to be a 64-bit Linux executable:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-bash\" data-lang=\"bash\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ file suspicious\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003esuspicious: ELF 64-bit LSB pie executable, x86-64, version \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e \u003cspan style=\"color:#f92672\"\u003e(\u003c/span\u003eSYSV\u003cspan style=\"color:#f92672\"\u003e)\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003edynamically linked, interpreter /lib64/ld-linux-x86-64.so.2,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eBuildID\u003cspan style=\"color:#f92672\"\u003e[\u003c/span\u003esha1\u003cspan style=\"color:#f92672\"\u003e]=\u003c/span\u003e3fc9729b05add2cba0bddd498f66c8b497060343,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#66d9ef\"\u003efor\u003c/span\u003e GNU/Linux 3.2.0, stripped\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThe binary was stripped, removing symbol information and making our static analysis a bit more challenging.\u003c/p\u003e\n\u003ch3 id=\"entropy-analysis\"\u003eEntropy Analysis\u003c/h3\u003e\n\u003cp\u003eTo identify potential obfuscation or packing, I performed entropy analysis on the binary using ImHex. The entropy graph revealed several sections with notably high entropy (approaching 1.0), indicating the presence of encrypted or compressed data:\u003c/p\u003e\n\u003cp align=\"center\"\u003e\n\u003cimg src=\"/images/codebreaker-2025/entropy.png\" alt=\"Entropy\"/\u003e\n\u003c/p\u003e\n\u003cp\u003eThe high entropy sections at addresses 0x186A0, 0x1D4C0, and 0x222E0 suggested the malware contained encrypted payloads that would be unpacked during runtime.\u003c/p\u003e\n\u003chr\u003e\n\u003ch3 id=\"discovering-anti-debug-mechanisms\"\u003eDiscovering Anti-Debug Mechanisms\u003c/h3\u003e\n\u003cp\u003eInitial attempts to run the binary under GDB revealed an anti-debugging trap:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-bash\" data-lang=\"bash\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ gdb ./suspicious\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#f92672\"\u003e(\u003c/span\u003egdb\u003cspan style=\"color:#f92672\"\u003e)\u003c/span\u003e run\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp align=\"center\"\u003e\n\u003cimg src=\"/images/codebreaker-2025/firstrun.png\" alt=\"First Run\"/\u003e\n\u003c/p\u003e\n\u003cp\u003eThe program immediately crashed with a SIGSEGV (segmentation fault) at address \u003ccode\u003e0x55555555765a\u003c/code\u003e. Examining the instruction at this location revealed:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-assembly\" data-lang=\"assembly\"\u003e0x55555555765a    mov    DWORD PTR ds:0x0, 0x0\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eThis instruction attempts to write to NULL (address 0x0), an intentional crash mechanism.\u003c/p\u003e\n\u003ch3 id=\"identifying-additional-anti-debug-functions\"\u003eIdentifying Additional Anti-Debug Functions\u003c/h3\u003e\n\u003cp\u003eHowever, simply NOPing out the crash instruction proved insufficient. Through static analysis in IDA, I examined the binary to understand the full anti-debug chain and discovered two additional protection mechanisms that needed to be bypassed.\u003c/p\u003e\n\u003ch4 id=\"mechanism-1-ptrace-detection-sub_3590\"\u003eMechanism 1: ptrace Detection (sub_3590)\u003c/h4\u003e\n\u003cp\u003eLocated at address \u003ccode\u003e0x3590\u003c/code\u003e, this function uses \u003ccode\u003eptrace(PTRACE_TRACEME)\u003c/code\u003e to detect debugger presence:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-c\" data-lang=\"c\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#66d9ef\"\u003e__int64\u003c/span\u003e \u003cspan style=\"color:#a6e22e\"\u003esub_3590\u003c/span\u003e()\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#66d9ef\"\u003e__int64\u003c/span\u003e result;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#66d9ef\"\u003eif\u003c/span\u003e ( \u003cspan style=\"color:#a6e22e\"\u003eptrace\u003c/span\u003e(PTRACE_TRACEME, \u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e, \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e, \u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e) \u003cspan style=\"color:#f92672\"\u003e!=\u003c/span\u003e \u003cspan style=\"color:#f92672\"\u003e-\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e \u003cspan style=\"color:#f92672\"\u003e||\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e       (result \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e (\u003cspan style=\"color:#66d9ef\"\u003eunsigned\u003c/span\u003e \u003cspan style=\"color:#66d9ef\"\u003eint\u003c/span\u003e)\u003cspan style=\"color:#f92672\"\u003e*\u003c/span\u003e\u003cspan style=\"color:#a6e22e\"\u003e__errno_location\u003c/span\u003e(), (_DWORD)result \u003cspan style=\"color:#f92672\"\u003e!=\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e) )\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#a6e22e\"\u003eptrace\u003c/span\u003e(PTRACE_DETACH, \u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e, \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e, \u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e);\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#66d9ef\"\u003ereturn\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e;  \u003cspan style=\"color:#75715e\"\u003e// No debugger\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  }\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#66d9ef\"\u003ereturn\u003c/span\u003e result;  \u003cspan style=\"color:#75715e\"\u003e// Debugger detected (returns non-zero)\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e}\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eWhen a process is already being traced by a debugger, \u003ccode\u003ePTRACE_TRACEME\u003c/code\u003e fails with \u003ccode\u003eerrno = EPERM (1)\u003c/code\u003e. The function returns a non-zero value if a debugger is detected, which triggers the anti-debug chain.\u003c/p\u003e\n\u003cp align=\"center\"\u003e\n\u003cimg src=\"/images/codebreaker-2025/sub_3590.png\" alt=\"sub_3590 in IDA\"/\u003e\n\u003c/p\u003e\n\u003ch4 id=\"mechanism-2-tracerpid-check-sub_3470\"\u003eMechanism 2: TracerPid Check (sub_3470)\u003c/h4\u003e\n\u003cp\u003eLocated at address \u003ccode\u003e0x3470\u003c/code\u003e, this function reads \u003ccode\u003e/proc/self/status\u003c/code\u003e to check the \u003ccode\u003eTracerPid\u003c/code\u003e field:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-c\" data-lang=\"c\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_BOOL8 \u003cspan style=\"color:#a6e22e\"\u003esub_3470\u003c/span\u003e()\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#75715e\"\u003e// Opens /proc/self/status\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#66d9ef\"\u003eif\u003c/span\u003e ( \u003cspan style=\"color:#f92672\"\u003e!\u003c/span\u003e(\u003cspan style=\"color:#66d9ef\"\u003eunsigned\u003c/span\u003e \u003cspan style=\"color:#66d9ef\"\u003eint\u003c/span\u003e)\u003cspan style=\"color:#a6e22e\"\u003esub_56A0\u003c/span\u003e(\u003cspan style=\"color:#f92672\"\u003e\u0026amp;\u003c/span\u003estream, \u003cspan style=\"color:#e6db74\"\u003e\u0026#34;r\u0026#34;\u003c/span\u003e, \u003cspan style=\"color:#e6db74\"\u003e\u0026#34;/proc/self/status\u0026#34;\u003c/span\u003e) )\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#66d9ef\"\u003ewhile\u003c/span\u003e ( \u003cspan style=\"color:#a6e22e\"\u003egetline\u003c/span\u003e(\u003cspan style=\"color:#f92672\"\u003e\u0026amp;\u003c/span\u003ehaystack, \u003cspan style=\"color:#f92672\"\u003e\u0026amp;\u003c/span\u003en, stream) \u003cspan style=\"color:#f92672\"\u003e!=\u003c/span\u003e \u003cspan style=\"color:#f92672\"\u003e-\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e )\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e      \u003cspan style=\"color:#66d9ef\"\u003eif\u003c/span\u003e ( \u003cspan style=\"color:#a6e22e\"\u003estrstr\u003c/span\u003e(haystack, \u003cspan style=\"color:#e6db74\"\u003e\u0026#34;TracerPid\u0026#34;\u003c/span\u003e) )\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e      {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#66d9ef\"\u003eif\u003c/span\u003e ( \u003cspan style=\"color:#a6e22e\"\u003estrtok\u003c/span\u003e(v0, delim) )\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e          v4 \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#a6e22e\"\u003estrtok\u003c/span\u003e(\u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e, delim);\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e          \u003cspan style=\"color:#66d9ef\"\u003eif\u003c/span\u003e ( v4 )\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e          {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            v2 \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#f92672\"\u003e*\u003c/span\u003ev4 \u003cspan style=\"color:#f92672\"\u003e!=\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e48\u003c/span\u003e;  \u003cspan style=\"color:#75715e\"\u003e// Returns true if TracerPid != \u0026#39;0\u0026#39;\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#75715e\"\u003e// ...\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e          }\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        }\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e      }\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    }\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  }\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#66d9ef\"\u003ereturn\u003c/span\u003e v2;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e}\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eWhen a debugger is attached, the \u003ccode\u003eTracerPid\u003c/code\u003e value in \u003ccode\u003e/proc/self/status\u003c/code\u003e is non-zero (the PID of the debugging process). This function returns true when debugging is detected.\u003c/p\u003e\n\u003cp align=\"center\"\u003e\n\u003cimg src=\"/images/codebreaker-2025/sub_3470.png\" alt=\"sub_3470 in IDA\"/\u003e\n\u003c/p\u003e\n\u003chr\u003e\n\u003ch3 id=\"anti-debug-bypass\"\u003eAnti-Debug Bypass\u003c/h3\u003e\n\u003cp\u003eTo enable full dynamic analysis, I created a simple Python script to patch all three anti-debug mechanisms:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-python\" data-lang=\"python\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#66d9ef\"\u003ewith\u003c/span\u003e open(\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;suspicious\u0026#39;\u003c/span\u003e, \u003cspan style=\"color:#e6db74\"\u003e\u0026#39;rb\u0026#39;\u003c/span\u003e) \u003cspan style=\"color:#66d9ef\"\u003eas\u003c/span\u003e f:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    data \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e bytearray(f\u003cspan style=\"color:#f92672\"\u003e.\u003c/span\u003eread())\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#75715e\"\u003e# Patch sub_3590 (ptrace check) to immediately return 0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eoffset \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e0x3590\u003c/span\u003e \u003cspan style=\"color:#f92672\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e4\u003c/span\u003e  \u003cspan style=\"color:#75715e\"\u003e# Skip endbr64 instruction\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003edata[offset:offset\u003cspan style=\"color:#f92672\"\u003e+\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e3\u003c/span\u003e] \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#e6db74\"\u003eb\u003c/span\u003e\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e\\x31\\xc0\\xc3\u003c/span\u003e\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;\u003c/span\u003e  \u003cspan style=\"color:#75715e\"\u003e# xor eax, eax; ret\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#75715e\"\u003e# Patch sub_3470 (TracerPid check) to immediately return 0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eoffset2 \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e0x3474\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003edata[offset2:offset2\u003cspan style=\"color:#f92672\"\u003e+\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e3\u003c/span\u003e] \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#e6db74\"\u003eb\u003c/span\u003e\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e\\x31\\xc0\\xc3\u003c/span\u003e\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;\u003c/span\u003e  \u003cspan style=\"color:#75715e\"\u003e# xor eax, eax; ret\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#75715e\"\u003e# Patch NULL pointer trap at 0x765a\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eoffset3 \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e0x765a\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003edata[offset3:offset3\u003cspan style=\"color:#f92672\"\u003e+\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e10\u003c/span\u003e] \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#e6db74\"\u003eb\u003c/span\u003e\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e\\x90\u003c/span\u003e\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#f92672\"\u003e*\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e10\u003c/span\u003e  \u003cspan style=\"color:#75715e\"\u003e# NOP sled\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#66d9ef\"\u003ewith\u003c/span\u003e open(\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;suspicious_patched3\u0026#39;\u003c/span\u003e, \u003cspan style=\"color:#e6db74\"\u003e\u0026#39;wb\u0026#39;\u003c/span\u003e) \u003cspan style=\"color:#66d9ef\"\u003eas\u003c/span\u003e f:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    f\u003cspan style=\"color:#f92672\"\u003e.\u003c/span\u003ewrite(data)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eprint(\u003cspan style=\"color:#e6db74\"\u003e\u0026#34;Patched all anti-debug checks\u0026#34;\u003c/span\u003e)\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThe patches work by:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eReplacing both detection functions with \u003ccode\u003exor eax, eax; ret\u003c/code\u003e to force them to always return 0 (no debugger detected)\u003c/li\u003e\n\u003cli\u003eNOPing out the NULL pointer trap to prevent the crash\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"dynamic-analysis-and-payload-extraction\"\u003eDynamic Analysis and Payload Extraction\u003c/h2\u003e\n\u003cp\u003eWith the anti-debug protections bypassed, I proceeded with dynamic analysis using GDB. Since the challenge specifically asks for \u0026ldquo;the file path the malware uses to write a file,\u0026rdquo; I set a catchpoint on the \u003ccode\u003ewrite\u003c/code\u003e system call to monitor all write operations:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-bash\" data-lang=\"bash\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ gdb ./suspicious_patched3\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#f92672\"\u003e(\u003c/span\u003egdb\u003cspan style=\"color:#f92672\"\u003e)\u003c/span\u003e catch syscall write\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eCatchpoint \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e \u003cspan style=\"color:#f92672\"\u003e(\u003c/span\u003esyscall \u003cspan style=\"color:#e6db74\"\u003e\u0026#39;write\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#f92672\"\u003e[\u003c/span\u003e1\u003cspan style=\"color:#f92672\"\u003e])\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#f92672\"\u003e(\u003c/span\u003egdb\u003cspan style=\"color:#f92672\"\u003e)\u003c/span\u003e run\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#f92672\"\u003e(\u003c/span\u003egdb\u003cspan style=\"color:#f92672\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#66d9ef\"\u003econtinue\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eUpon the first continue, I hit a write operation. To understand what was being written, I needed to examine the system call arguments. On x86-64 Linux, system calls pass arguments through registers according to the following convention:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003erdi\u003c/code\u003e = first argument\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ersi\u003c/code\u003e = second argument\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erdx\u003c/code\u003e = third argument\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFor the \u003ccode\u003ewrite\u003c/code\u003e system call specifically, the signature is \u003ccode\u003ewrite(int fd, const void *buf, size_t count)\u003c/code\u003e, which maps to:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003erdi\u003c/code\u003e = file descriptor (where to write)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ersi\u003c/code\u003e = buffer pointer (what to write)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erdx\u003c/code\u003e = byte count (how much to write)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eExamining these registers:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-gdb\" data-lang=\"gdb\"\u003e(gdb) info registers rdi rsi rdx\nrdi            0x3                 0x3\nrsi            0x555555590390      0x555555590390\nrdx            0xcee8              0xcee8\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eThis revealed the malware was writing to file descriptor 3, with 0xcee8 (52,968) bytes of data from memory address 0x555555590390. The large size suggested this was payload data rather than typical logging output.\u003c/p\u003e\n\u003cp\u003eTo identify what file descriptor 3 represented, I checked the process\u0026rsquo;s file descriptors while it was paused in the debugger:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-bash\" data-lang=\"bash\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#f92672\"\u003e(\u003c/span\u003egdb\u003cspan style=\"color:#f92672\"\u003e)\u003c/span\u003e shell ls -la /proc/\u003cspan style=\"color:#66d9ef\"\u003e$(\u003c/span\u003epgrep suspicious\u003cspan style=\"color:#66d9ef\"\u003e)\u003c/span\u003e/fd/\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003etotal \u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003edr-x------ \u003cspan style=\"color:#ae81ff\"\u003e2\u003c/span\u003e kali kali  \u003cspan style=\"color:#ae81ff\"\u003e4\u003c/span\u003e Nov \u003cspan style=\"color:#ae81ff\"\u003e20\u003c/span\u003e 21:01 .\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003edr-xr-xr-x \u003cspan style=\"color:#ae81ff\"\u003e9\u003c/span\u003e kali kali  \u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e Nov \u003cspan style=\"color:#ae81ff\"\u003e20\u003c/span\u003e 21:01 ..\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003elrwx------ \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e kali kali \u003cspan style=\"color:#ae81ff\"\u003e64\u003c/span\u003e Nov \u003cspan style=\"color:#ae81ff\"\u003e20\u003c/span\u003e 21:01 \u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e -\u0026gt; /dev/pts/0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003elrwx------ \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e kali kali \u003cspan style=\"color:#ae81ff\"\u003e64\u003c/span\u003e Nov \u003cspan style=\"color:#ae81ff\"\u003e20\u003c/span\u003e 21:01 \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e -\u0026gt; /dev/pts/0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003elrwx------ \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e kali kali \u003cspan style=\"color:#ae81ff\"\u003e64\u003c/span\u003e Nov \u003cspan style=\"color:#ae81ff\"\u003e20\u003c/span\u003e 21:01 \u003cspan style=\"color:#ae81ff\"\u003e2\u003c/span\u003e -\u0026gt; /dev/pts/0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003elrwx------ \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e kali kali \u003cspan style=\"color:#ae81ff\"\u003e64\u003c/span\u003e Nov \u003cspan style=\"color:#ae81ff\"\u003e20\u003c/span\u003e 21:01 \u003cspan style=\"color:#ae81ff\"\u003e3\u003c/span\u003e -\u0026gt; \u003cspan style=\"color:#e6db74\"\u003e\u0026#39;/memfd: (deleted)\u0026#39;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp align=\"center\"\u003e\n\u003c/p\u003e\n\u003cp\u003eFile descriptor 3 pointed to \u003ccode\u003e/memfd: (deleted)\u003c/code\u003e - a memory-backed file. This technique allows the malware to unpack a payload into memory without writing to disk, avoiding file-based detection. I extracted this data while the program was paused:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-gdb\" data-lang=\"gdb\"\u003e(gdb) dump binary memory /tmp/extracted.bin 0x555555590390 0x555555590390+0xcee8\n\u003c/code\u003e\u003c/pre\u003e\u003chr\u003e\n\u003ch3 id=\"analyzing-the-unpacked-payload\"\u003eAnalyzing the Unpacked Payload\u003c/h3\u003e\n\u003cp\u003eThe extracted payload was itself an ELF binary:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-bash\" data-lang=\"bash\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ file /tmp/extracted.bin\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/tmp/extracted.bin: ELF 64-bit LSB shared object, x86-64, version \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e \u003cspan style=\"color:#f92672\"\u003e(\u003c/span\u003eSYSV\u003cspan style=\"color:#f92672\"\u003e)\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003edynamically linked, BuildID\u003cspan style=\"color:#f92672\"\u003e[\u003c/span\u003esha1\u003cspan style=\"color:#f92672\"\u003e]=\u003c/span\u003e69d0667eed34a355fc78fbe68a7eed42897947c1, stripped\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eLoading this unpacked payload into IDA revealed the true functionality. The payload\u0026rsquo;s \u003ccode\u003erun()\u003c/code\u003e function showed an interesting pattern:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-c\" data-lang=\"c\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#66d9ef\"\u003eunsigned\u003c/span\u003e \u003cspan style=\"color:#66d9ef\"\u003e__int64\u003c/span\u003e \u003cspan style=\"color:#a6e22e\"\u003erun\u003c/span\u003e()\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  _BYTE v2[\u003cspan style=\"color:#ae81ff\"\u003e264\u003c/span\u003e]; \u003cspan style=\"color:#75715e\"\u003e// RC4 state\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  v3 \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#a6e22e\"\u003e__readfsqword\u003c/span\u003e(\u003cspan style=\"color:#ae81ff\"\u003e0x28u\u003c/span\u003e);\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#a6e22e\"\u003esub_7C8E\u003c/span\u003e(v2, \u003cspan style=\"color:#e6db74\"\u003e\u0026#34;skibidi\u0026#34;\u003c/span\u003e, \u003cspan style=\"color:#ae81ff\"\u003e7\u003c/span\u003e);  \u003cspan style=\"color:#75715e\"\u003e// Initialize RC4 with key \u0026#34;skibidi\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#66d9ef\"\u003eif\u003c/span\u003e ( (\u003cspan style=\"color:#66d9ef\"\u003eunsigned\u003c/span\u003e \u003cspan style=\"color:#66d9ef\"\u003e__int8\u003c/span\u003e)\u003cspan style=\"color:#a6e22e\"\u003esub_8574\u003c/span\u003e(v2) \u003cspan style=\"color:#f92672\"\u003e==\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f92672\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e (\u003cspan style=\"color:#66d9ef\"\u003eunsigned\u003c/span\u003e \u003cspan style=\"color:#66d9ef\"\u003e__int8\u003c/span\u003e)\u003cspan style=\"color:#a6e22e\"\u003esub_8666\u003c/span\u003e(v2) \u003cspan style=\"color:#f92672\"\u003e==\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f92672\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e (\u003cspan style=\"color:#66d9ef\"\u003eunsigned\u003c/span\u003e \u003cspan style=\"color:#66d9ef\"\u003e__int8\u003c/span\u003e)\u003cspan style=\"color:#a6e22e\"\u003esub_86F8\u003c/span\u003e() \u003cspan style=\"color:#f92672\"\u003e==\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f92672\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e (\u003cspan style=\"color:#66d9ef\"\u003eunsigned\u003c/span\u003e \u003cspan style=\"color:#66d9ef\"\u003e__int8\u003c/span\u003e)\u003cspan style=\"color:#a6e22e\"\u003esub_8771\u003c/span\u003e() \u003cspan style=\"color:#f92672\"\u003e==\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f92672\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e (\u003cspan style=\"color:#66d9ef\"\u003eunsigned\u003c/span\u003e \u003cspan style=\"color:#66d9ef\"\u003e__int8\u003c/span\u003e)\u003cspan style=\"color:#a6e22e\"\u003esub_8795\u003c/span\u003e(v2) \u003cspan style=\"color:#f92672\"\u003e==\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f92672\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e (\u003cspan style=\"color:#66d9ef\"\u003eunsigned\u003c/span\u003e \u003cspan style=\"color:#66d9ef\"\u003e__int8\u003c/span\u003e)\u003cspan style=\"color:#a6e22e\"\u003esub_8A0F\u003c/span\u003e(v2) \u003cspan style=\"color:#f92672\"\u003e==\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e )\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#a6e22e\"\u003esub_7F5D\u003c/span\u003e(v2);\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  }\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#66d9ef\"\u003ereturn\u003c/span\u003e v3 \u003cspan style=\"color:#f92672\"\u003e-\u003c/span\u003e \u003cspan style=\"color:#a6e22e\"\u003e__readfsqword\u003c/span\u003e(\u003cspan style=\"color:#ae81ff\"\u003e0x28u\u003c/span\u003e);\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e}\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp align=\"center\"\u003e\n\u003c/p\u003e\n\u003cp\u003eThe function initializes an RC4 cipher state with the key \u003ccode\u003e\u0026quot;skibidi\u0026quot;\u003c/code\u003e and then calls multiple check functions, each of which decrypts strings using the RC4 state.\u003c/p\u003e\n\u003chr\u003e\n\u003ch3 id=\"rc4-decryption-and-file-path-discovery\"\u003eRC4 Decryption and File Path Discovery\u003c/h3\u003e\n\u003cp\u003eEach check function followed a similar pattern, calling \u003ccode\u003esub_7EFF\u003c/code\u003e (the RC4 decryption routine) with encrypted data:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-c\" data-lang=\"c\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_BOOL8 \u003cspan style=\"color:#66d9ef\"\u003e__fastcall\u003c/span\u003e \u003cspan style=\"color:#a6e22e\"\u003esub_8574\u003c/span\u003e(\u003cspan style=\"color:#66d9ef\"\u003e__int64\u003c/span\u003e a1)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  _BYTE v3[\u003cspan style=\"color:#ae81ff\"\u003e32\u003c/span\u003e];\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  _BYTE v4[\u003cspan style=\"color:#ae81ff\"\u003e40\u003c/span\u003e];\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#a6e22e\"\u003esub_7EFF\u003c/span\u003e(v3, \u003cspan style=\"color:#f92672\"\u003e\u0026amp;\u003c/span\u003eunk_D580, \u003cspan style=\"color:#ae81ff\"\u003e38\u003c/span\u003e, a1);  \u003cspan style=\"color:#75715e\"\u003e// Decrypt 38 bytes from 0xD580\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  std\u003cspan style=\"color:#f92672\"\u003e::\u003c/span\u003efilesystem\u003cspan style=\"color:#f92672\"\u003e::\u003c/span\u003e__cxx11\u003cspan style=\"color:#f92672\"\u003e::\u003c/span\u003epath\u003cspan style=\"color:#f92672\"\u003e::\u003c/span\u003epath\u003cspan style=\"color:#f92672\"\u003e\u0026lt;\u003c/span\u003estd\u003cspan style=\"color:#f92672\"\u003e::\u003c/span\u003estring\u003cspan style=\"color:#f92672\"\u003e\u0026gt;\u003c/span\u003e(v4, v3);\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  v1 \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e std\u003cspan style=\"color:#f92672\"\u003e::\u003c/span\u003efilesystem\u003cspan style=\"color:#f92672\"\u003e::\u003c/span\u003e\u003cspan style=\"color:#a6e22e\"\u003eexists\u003c/span\u003e((std\u003cspan style=\"color:#f92672\"\u003e::\u003c/span\u003efilesystem \u003cspan style=\"color:#f92672\"\u003e*\u003c/span\u003e)v4);\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#66d9ef\"\u003ereturn\u003c/span\u003e v1 \u003cspan style=\"color:#f92672\"\u003e!=\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e}\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp align=\"center\"\u003e\n\u003cimg src=\"/images/codebreaker-2025/sub_8574.png\" alt=\"sub_8574\"/\u003e\n\u003c/p\u003e\n\u003cp\u003eThis function decrypts data from address \u003ccode\u003e0xD580\u003c/code\u003e and checks if that path exists on the filesystem. Examining the encrypted data in IDA:\u003c/p\u003e\n\u003cp align=\"center\"\u003e\n\u003cimg src=\"/images/codebreaker-2025/encrypted_data.png\" alt=\"Encrypted data at 0xD580\"/\u003e\n\u003c/p\u003e\n\u003cp\u003eThe encrypted bytes at \u003ccode\u003e0xD580\u003c/code\u003e (38 bytes):\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003eC7 16 75 C6 0F C7 14 36 16 AF 4C 1D 34 01 41 BA\nF9 22 B9 AC 42 A6 C7 07 00 09 F7 59 C9 E1 2E 63\n77 F3 A0 71 DB 1F\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eTo decrypt this, I implemented the following in Python:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-python\" data-lang=\"python\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#66d9ef\"\u003edef\u003c/span\u003e \u003cspan style=\"color:#a6e22e\"\u003erc4_init\u003c/span\u003e(key):\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#e6db74\"\u003e\u0026#34;\u0026#34;\u0026#34;RC4 Key Scheduling Algorithm (KSA)\u0026#34;\u0026#34;\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    S \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e list(range(\u003cspan style=\"color:#ae81ff\"\u003e256\u003c/span\u003e))\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    j \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#66d9ef\"\u003efor\u003c/span\u003e i \u003cspan style=\"color:#f92672\"\u003ein\u003c/span\u003e range(\u003cspan style=\"color:#ae81ff\"\u003e256\u003c/span\u003e):\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        j \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e (j \u003cspan style=\"color:#f92672\"\u003e+\u003c/span\u003e S[i] \u003cspan style=\"color:#f92672\"\u003e+\u003c/span\u003e key[i \u003cspan style=\"color:#f92672\"\u003e%\u003c/span\u003e len(key)]) \u003cspan style=\"color:#f92672\"\u003e%\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e256\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        S[i], S[j] \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e S[j], S[i]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#66d9ef\"\u003ereturn\u003c/span\u003e {\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;S\u0026#39;\u003c/span\u003e: S, \u003cspan style=\"color:#e6db74\"\u003e\u0026#39;i\u0026#39;\u003c/span\u003e: \u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e, \u003cspan style=\"color:#e6db74\"\u003e\u0026#39;j\u0026#39;\u003c/span\u003e: \u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#66d9ef\"\u003edef\u003c/span\u003e \u003cspan style=\"color:#a6e22e\"\u003erc4_keystream_byte\u003c/span\u003e(state):\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#e6db74\"\u003e\u0026#34;\u0026#34;\u0026#34;RC4 Pseudo-Random Generation Algorithm (PRGA)\u0026#34;\u0026#34;\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    S \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e state[\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;S\u0026#39;\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    state[\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;i\u0026#39;\u003c/span\u003e] \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e (state[\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;i\u0026#39;\u003c/span\u003e] \u003cspan style=\"color:#f92672\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e) \u003cspan style=\"color:#f92672\"\u003e%\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e256\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    state[\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;j\u0026#39;\u003c/span\u003e] \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e (state[\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;j\u0026#39;\u003c/span\u003e] \u003cspan style=\"color:#f92672\"\u003e+\u003c/span\u003e S[state[\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;i\u0026#39;\u003c/span\u003e]]) \u003cspan style=\"color:#f92672\"\u003e%\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e256\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    S[state[\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;i\u0026#39;\u003c/span\u003e]], S[state[\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;j\u0026#39;\u003c/span\u003e]] \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e S[state[\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;j\u0026#39;\u003c/span\u003e]], S[state[\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;i\u0026#39;\u003c/span\u003e]]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#66d9ef\"\u003ereturn\u003c/span\u003e S[(S[state[\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;i\u0026#39;\u003c/span\u003e]] \u003cspan style=\"color:#f92672\"\u003e+\u003c/span\u003e S[state[\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;j\u0026#39;\u003c/span\u003e]]) \u003cspan style=\"color:#f92672\"\u003e%\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e256\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#75715e\"\u003e# Key found in malware\u0026#39;s run() function at sub_7C8E call\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003erc4_state \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e rc4_init(\u003cspan style=\"color:#e6db74\"\u003eb\u003c/span\u003e\u003cspan style=\"color:#e6db74\"\u003e\u0026#34;skibidi\u0026#34;\u003c/span\u003e)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#75715e\"\u003e# Encrypted data from address 0xD580 (passed to sub_7EFF by sub_8574)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eciphertext \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e bytes\u003cspan style=\"color:#f92672\"\u003e.\u003c/span\u003efromhex(\u003cspan style=\"color:#e6db74\"\u003e\u0026#39;C71675C60FC7143616AF4C1D340141BAF922B9AC42A6C7070009F759C9E12E6377F3A071DB1F\u0026#39;\u003c/span\u003e)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#75715e\"\u003e# RC4 decryption: ciphertext XOR keystream = plaintext\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eplaintext \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e bytes([c \u003cspan style=\"color:#f92672\"\u003e^\u003c/span\u003e rc4_keystream_byte(rc4_state) \u003cspan style=\"color:#66d9ef\"\u003efor\u003c/span\u003e c \u003cspan style=\"color:#f92672\"\u003ein\u003c/span\u003e ciphertext])\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eprint(\u003cspan style=\"color:#e6db74\"\u003ef\u003c/span\u003e\u003cspan style=\"color:#e6db74\"\u003e\u0026#34;Decrypted: \u003c/span\u003e\u003cspan style=\"color:#e6db74\"\u003e{\u003c/span\u003eplaintext\u003cspan style=\"color:#f92672\"\u003e.\u003c/span\u003edecode()\u003cspan style=\"color:#e6db74\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#e6db74\"\u003e\u0026#34;\u003c/span\u003e)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#75715e\"\u003e# /opt/dafin/intel/ops_brief_redteam.pdf\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eIn RC4\u0026rsquo;s standard implementation, S represents the state array (a permutation of values 0-255), while i and j are indices used to traverse and manipulate this array. For further reading I highly recommend the Wikipedia page: \u003ca href=\"https://en.wikipedia.org/wiki/RC4\"\u003ehttps://en.wikipedia.org/wiki/RC4\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eRunning this script revealed the file path the malware uses:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003eDecrypted file path: /opt/dafin/intel/ops_brief_redteam.pdf\n\u003c/code\u003e\u003c/pre\u003e\u003cp align=\"center\"\u003e\n\u003cimg src=\"/images/codebreaker-2025/decrypted_path.png\" alt=\"Decrypted path\"/\u003e\n\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003eSuccess!\u003c/strong\u003e By bypassing multiple anti-debug protections, extracting the memory-mapped payload through dynamic analysis, and reverse engineering the RC4 encryption scheme with the key \u003ccode\u003eskibidi\u003c/code\u003e I successfully decrypted the hidden file path.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025-task-3/\"\u003e← Task 3\u003c/a\u003e · \u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003eSeries overview\u003c/a\u003e · \u003ca href=\"/posts/nsa-codebreaker-2025-task-5/\"\u003eTask 5 →\u003c/a\u003e\u003c/p\u003e\n","date":"2026-10-03","dateFormatted":"2026.10.03","excerpt":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"task-4---unpacking-insight---malware-analysis\"\u003eTask 4 - Unpacking Insight - (Malware Analysis)\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003eOnce back at NSA the team contacts the NSA liaison at FBI to see if they have any information about what was discovered in the …\u003c/p\u003e\u003c/blockquote\u003e","featured":false,"mood":null,"permalink":"/posts/nsa-codebreaker-2025-task-4/","readingTime":8,"slug":"nsa-codebreaker-2025-task-4","subtitle":"Understanding an obfuscated Linux sample","summary":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"task-4---unpacking-insight---malware-analysis\"\u003eTask 4 - Unpacking Insight - (Malware Analysis)\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003eOnce back at NSA the team contacts the NSA liaison at FBI to see if they have any information about what was discovered in the configuration data. FBI informs us that the facility registered to host that domain is on a watchlist for suspected criminal activity. With this tip, the FBI acquires a warrant and raids the location. Inside the facility, the server is discovered along with a suspect. The suspect is known to the FBI as a low-level malware actor. During questioning, they disclose that they are providing a service to host malware for various cybercrime groups, but recently they were contacted by a much more secretive and sophisticated customer. While they don\u0026rsquo;t appear to know anything about who is paying for the service, they provide the FBI with the malware that was hosted.\u003c/p\u003e","tags":["NSA Codebreaker 2025","ctf","malware analysis"],"title":"NSA Codebreaker 2025 — Task 4: Unpacking Insight","url":"/posts/nsa-codebreaker-2025-task-4/","wordCount":1569},{"content":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"task-3---digging-deeper---reverse-engineering\"\u003eTask 3 - Digging Deeper - (Reverse Engineering)\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003eThe network administrators confirm that the IP address you provided in your description is an edge router. DAFIN-SOC is asking you to dive deeper and reverse engineer this device. Fortunately, their team managed to pull a memory dump of the device.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003eScour the device\u0026rsquo;s memory dump and identify anomalous or malicious activity to find out what\u0026rsquo;s going on.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003eYour submission will be a list of IPs and domains, one per line. For example:\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e127.0.0.1 localhost\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e192.168.54.131 corp.internal\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e...\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"downloads\"\u003eDownloads\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMemory Dump\u003c/strong\u003e (\u003ccode\u003ememory.dump.gz\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eMetadata\u003c/strong\u003e (\u003ccode\u003eSystem.map.br\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eKernel Image\u003c/strong\u003e (\u003ccode\u003evmlinux.xz\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"task\"\u003eTask\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eSubmit a complete list of affected IPs and FQDNs, one per line.\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"writeup\"\u003eWriteup\u003c/h2\u003e\n\u003cp\u003eA reverse engineering task where we\u0026rsquo;re given a memory dump, the kernel symbol map, and the kernel image. The first step is to discover the malicious binary and the second step is to reverse engineer it. To start with, I set up volatility and the kernel images.\u003c/p\u003e\n\u003cp align=\"center\"\u003e\n\u003cimg src=\"/images/codebreaker-2025/badge3.png\" alt=\"Badge\" width=\"300\"/\u003e\n\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eSuccess!\u003c/strong\u003e Three down, four to go.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025-task-2/\"\u003e← Task 2\u003c/a\u003e · \u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003eSeries overview\u003c/a\u003e · \u003ca href=\"/posts/nsa-codebreaker-2025-task-4/\"\u003eTask 4 →\u003c/a\u003e\u003c/p\u003e\n","date":"2026-10-03","dateFormatted":"2026.10.03","excerpt":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"task-3---digging-deeper---reverse-engineering\"\u003eTask 3 - Digging Deeper - (Reverse Engineering)\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003eThe network administrators confirm that the IP address you provided in your description is an edge router. DAFIN-SOC is asking you to …\u003c/p\u003e\u003c/blockquote\u003e","featured":false,"mood":null,"permalink":"/posts/nsa-codebreaker-2025-task-3/","readingTime":1,"slug":"nsa-codebreaker-2025-task-3","subtitle":"Moving from network evidence to a router memory image","summary":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"task-3---digging-deeper---reverse-engineering\"\u003eTask 3 - Digging Deeper - (Reverse Engineering)\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003eThe network administrators confirm that the IP address you provided in your description is an edge router. DAFIN-SOC is asking you to dive deeper and reverse engineer this device. Fortunately, their team managed to pull a memory dump of the device.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003eScour the device\u0026rsquo;s memory dump and identify anomalous or malicious activity to find out what\u0026rsquo;s going on.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003eYour submission will be a list of IPs and domains, one per line. For example:\u003c/p\u003e","tags":["NSA Codebreaker 2025","ctf","reverse engineering"],"title":"NSA Codebreaker 2025 — Task 3: Digging Deeper","url":"/posts/nsa-codebreaker-2025-task-3/","wordCount":175},{"content":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"task-2---the-hunt-continues---network-forensics\"\u003eTask 2 - The Hunt Continues - (Network Forensics)\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003eWith your help, the team concludes that there was clearly a sophisticated piece of malware installed on that endpoint that was generating some network traffic. Fortunately, DAFIN-SOC also has an IDS which retained the recent network traffic in this segment.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003eDAFIN-SOC has provided a PCAP to analyze. Thoroughly evaluate the PCAP to identify potential malicious activity.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003chr\u003e\n\u003ch2 id=\"downloads\"\u003eDownloads\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ePCAP to analyze:\u003c/strong\u003e \u003ccode\u003etraffic.pcap\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"task\"\u003eTask\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eSubmit all the IP addresses that are assigned to the malicious device, one per line.\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"writeup\"\u003eWriteup\u003c/h2\u003e\n\u003cp\u003eUpon opening the PCAP in Wireshark, I was greeted by approximately 2,400 packets consisting primarily of IPv4 and ARP traffic.\u003c/p\u003e\n\u003cp align=\"center\"\u003e\n\u003cimg src=\"/images/codebreaker-2025/statistics.png\" alt=\"Statistics\"/\u003e\n\u003c/p\u003e\n\u003cp\u003eInitial reconnaissance revealed FTP traffic containing three router configuration backup files: \u003ccode\u003erouter1_backup.config\u003c/code\u003e, \u003ccode\u003erouter2_backup.config\u003c/code\u003e, and \u003ccode\u003erouter3_backup.config\u003c/code\u003e. Since FTP transmits data in cleartext, these configurations would be accessible if I could locate the correct TCP streams.\u003c/p\u003e\n\u003cp align=\"center\"\u003e\n\u003cimg src=\"/images/codebreaker-2025/ftpdata.png\" alt=\"FTPdata\"/\u003e\n\u003c/p\u003e\n\u003cp align=\"center\"\u003e\n\u003cimg src=\"/images/codebreaker-2025/tcpstream.png\" alt=\"TCPStream\"/\u003e\n\u003c/p\u003e\n\u003cp\u003eTo better understand the network topology, I used \u003ca href=\"https://github.com/Srinivas11789/PcapXray\"\u003ePcapXray\u003c/a\u003e to generate a network diagram showing the most active devices.\u003c/p\u003e\n\u003cp align=\"center\"\u003e\n\u003cimg src=\"/images/codebreaker-2025/network.png\" alt=\"Network\"/\u003e\n\u003c/p\u003e\n\u003cp\u003eWith three routers in play, I needed a methodical approach to identify which one was compromised. Rather than guessing based on traffic patterns alone, I decided to examine the DNS traffic for anomalies.\u003c/p\u003e\n\u003ch3 id=\"dns-traffic-analysis\"\u003eDNS Traffic Analysis\u003c/h3\u003e\n\u003cp\u003eI filtered for DNS traffic using the display filter \u003ccode\u003edns\u003c/code\u003e, which revealed 36 DNS packets. Narrowing this down to responses only (\u003ccode\u003edns.flags.response == 1\u003c/code\u003e) showed 19 response packets.\u003c/p\u003e\n\u003cp\u003eMost DNS responses originated from \u003ccode\u003e192.168.46.2\u003c/code\u003e (the legitimate DNS server), but I noticed something unusual: multiple responses with the same Transaction ID.\u003c/p\u003e\n\u003cp\u003eFiltering for Transaction ID \u003ccode\u003e0xc0c1\u003c/code\u003e revealed three DNS responses to the same query for \u003ccode\u003earchive.ubuntu.com\u003c/code\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eFrame 538\u003c/strong\u003e from \u003ccode\u003e192.168.2.254\u003c/code\u003e → Returned legitimate Ubuntu mirror IPs (91.189.91.83, etc.)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFrame 1703\u003c/strong\u003e from \u003ccode\u003e192.168.1.254\u003c/code\u003e → Returned legitimate Ubuntu mirror IPs (91.189.91.83, etc.)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFrame 2028\u003c/strong\u003e from \u003ccode\u003e192.168.3.254\u003c/code\u003e → Returned \u003cstrong\u003e203.0.113.108\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp align=\"center\"\u003e\n\u003cimg src=\"/images/codebreaker-2025/poisoned_router.png\" alt=\"Poisoned Router\"/\u003e\n\u003c/p\u003e\n\u003cp\u003eThe IP address \u003ccode\u003e203.0.113.108\u003c/code\u003e immediately raised a red flag. The \u003ccode\u003e203.0.113.0/24\u003c/code\u003e subnet is part of TEST-NET-3, a reserved documentation range defined in RFC 5737 that should never appear in production traffic. This was clearly a \u003cstrong\u003epoisoned DNS response\u003c/strong\u003e.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eRouter 3 (192.168.3.254)\u003c/strong\u003e had intercepted the DNS query and responded with a malicious IP address, attempting to redirect the client to an attacker-controlled server. This is a classic DNS spoofing attack where a man-in-the-middle device races to answer DNS queries before the legitimate server.\u003c/p\u003e\n\u003ch3 id=\"extracting-router-3-configuration\"\u003eExtracting Router 3 Configuration\u003c/h3\u003e\n\u003cp\u003eHaving identified \u003ccode\u003e192.168.3.254\u003c/code\u003e as the malicious device, I needed to enumerate all IP addresses assigned to it. I returned to the FTP traffic and extracted \u003ccode\u003erouter3_backup.config\u003c/code\u003e by following the appropriate TCP stream.\u003c/p\u003e\n\u003cp\u003eThe configuration file revealed three interfaces:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003econfig interface \u0026#39;loopback\u0026#39;\n    option device \u0026#39;lo\u0026#39;\n    option proto \u0026#39;static\u0026#39;\n    option ipaddr \u0026#39;127.7.5.3\u0026#39;\n    option netmask \u0026#39;255.0.0.0\u0026#39;\n\nconfig interface \u0026#39;lan\u0026#39;\n    option device \u0026#39;br-lan\u0026#39;\n    option proto \u0026#39;static\u0026#39;\n    option ipaddr \u0026#39;192.168.3.254\u0026#39;\n    option netmask \u0026#39;255.255.255.0\u0026#39;\n\nconfig interface \u0026#39;to_openwrt2\u0026#39;\n    option device \u0026#39;eth1\u0026#39;\n    option proto \u0026#39;static\u0026#39;\n    list ipaddr \u0026#39;192.168.5.1/28\u0026#39;\n\u003c/code\u003e\u003c/pre\u003e\u003cp align=\"center\"\u003e\n\u003cimg src=\"/images/codebreaker-2025/router3config.png\" alt=\"Router3 Config\"/\u003e\n\u003c/p\u003e\n\u003ch3 id=\"solution\"\u003eSolution\u003c/h3\u003e\n\u003cp\u003eThe malicious device (Router 3) had three IP addresses assigned:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e192.168.3.254\u003c/strong\u003e - LAN interface (\u003ccode\u003ebr-lan\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e192.168.5.1\u003c/strong\u003e - Connection to OpenWRT2 (\u003ccode\u003eeth1\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e127.7.5.3\u003c/strong\u003e - Loopback interface (\u003ccode\u003elo\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSubmitting all three addresses successfully completed the challenge.\u003c/p\u003e\n\u003cp\u003e\n\u003cimg src=\"/images/codebreaker-2025/badge2.png\" alt=\"Badge\" width=\"300\"/\u003e\n\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eSuccess!\u003c/strong\u003e Two down, five to go.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025-task-1/\"\u003e← Task 1\u003c/a\u003e · \u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003eSeries overview\u003c/a\u003e · \u003ca href=\"/posts/nsa-codebreaker-2025-task-3/\"\u003eTask 3 →\u003c/a\u003e\u003c/p\u003e\n","date":"2026-10-03","dateFormatted":"2026.10.03","excerpt":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"task-2---the-hunt-continues---network-forensics\"\u003eTask 2 - The Hunt Continues - (Network Forensics)\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003eWith your help, the team concludes that there was clearly a sophisticated piece of malware installed on that endpoint that was …\u003c/p\u003e\u003c/blockquote\u003e","featured":false,"mood":null,"permalink":"/posts/nsa-codebreaker-2025-task-2/","readingTime":3,"slug":"nsa-codebreaker-2025-task-2","subtitle":"Tracing inconsistent DNS responses back to a router","summary":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"task-2---the-hunt-continues---network-forensics\"\u003eTask 2 - The Hunt Continues - (Network Forensics)\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003eWith your help, the team concludes that there was clearly a sophisticated piece of malware installed on that endpoint that was generating some network traffic. Fortunately, DAFIN-SOC also has an IDS which retained the recent network traffic in this segment.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003eDAFIN-SOC has provided a PCAP to analyze. Thoroughly evaluate the PCAP to identify potential malicious activity.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003chr\u003e\n\u003ch2 id=\"downloads\"\u003eDownloads\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ePCAP to analyze:\u003c/strong\u003e \u003ccode\u003etraffic.pcap\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"task\"\u003eTask\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eSubmit all the IP addresses that are assigned to the malicious device, one per line.\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"writeup\"\u003eWriteup\u003c/h2\u003e\n\u003cp\u003eUpon opening the PCAP in Wireshark, I was greeted by approximately 2,400 packets consisting primarily of IPv4 and ARP traffic.\u003c/p\u003e","tags":["NSA Codebreaker 2025","ctf","network forensics"],"title":"NSA Codebreaker 2025 — Task 2: The Hunt Continues","url":"/posts/nsa-codebreaker-2025-task-2/","wordCount":512},{"content":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"task-1---getting-started-forensics\"\u003eTask 1 - Getting Started (Forensics)\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003eYou arrive on site and immediately get to work. The DAFIN-SOC team quickly briefs you on the situation. They have noticed numerous anomalous behaviors, such as: tools randomly failing tests and anti-virus flagging on seemingly clean workstations. They have narrowed in on one machine they would like NSA to thoroughly evaluate.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003eThey have provided a zipped EXT2 image from this development machine. Help DAFIN-SOC perform a forensic analysis on this - looking for any suspicious artifacts.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003chr\u003e\n\u003ch2 id=\"downloads\"\u003eDownloads\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ezipped EXT2 image:\u003c/strong\u003e \u003ccode\u003eimage.ext2.zip\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"task\"\u003eTask\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eProvide the SHA-1 hash of the suspicious artifact.\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"writeup\"\u003eWriteup\u003c/h2\u003e\n\u003cp\u003eI started by mounting the EXT2 image in read-only mode so I could safely explore its contents.\u003c/p\u003e\n\u003cp\u003e\n\u003cimg src=\"/images/codebreaker-2025/mount.png\" alt=\"Mount\"/\u003e\n\u003c/p\u003e\n\u003cp\u003eThe first place I looked was the root user’s \u003ccode\u003e.bash_history\u003c/code\u003e, since that often tells the story of what happened on the system. The history revealed a \u003cstrong\u003epattern\u003c/strong\u003e: lots of local network probing (using \u003ccode\u003ecurl\u003c/code\u003e, \u003ccode\u003ewget\u003c/code\u003e, \u003ccode\u003enc\u003c/code\u003e, \u003ccode\u003enetstat\u003c/code\u003e, etc.), checks against DNS, and even repeated calls to \u003ccode\u003ehttp://localhost/app/test\u003c/code\u003e. Mixed in were commands to mount \u003ccode\u003e/dev/sdb1\u003c/code\u003e to \u003ccode\u003e/mnt/usb\u003c/code\u003e and edits to the crontab. In other words, whoever was on this box was hammering on a local web service, staging files via USB, and attempting persistence through cron.\u003c/p\u003e\n\u003cp\u003e\n\u003cimg src=\"/images/codebreaker-2025/bash_history.png\" alt=\"BashHistory\"/\u003e\n\u003c/p\u003e\n\u003cp\u003eWith \u003ccode\u003e/app/test\u003c/code\u003e as a pivot point, I ran a \u003ccode\u003egrep\u003c/code\u003e-ed through the filesystem. This led me to an odd discovery:\u003c/p\u003e\n\u003cp\u003e\n\u003cimg src=\"/images/codebreaker-2025/grep.png\" alt=\"Grep\"/\u003e\n\u003c/p\u003e\n\u003cp\u003e/etc/terminfo/s/nsuvzemaow\u003c/p\u003e\n\u003cp\u003eThis terminfo file references \u003ccode\u003e/app/www\u003c/code\u003e. That\u0026rsquo;s a red flag - terminfo directories are supposed to store compiled terminal capability files, not random application paths. The filename itself looked odd too.\u003c/p\u003e\n\u003cp\u003eTo confirm, I calculated the SHA-1 hash of the file:\u003c/p\u003e\n\u003cp\u003e0068e0c3cba711e775fa374b201d5d04ffcef96c\u003c/p\u003e\n\u003cp\u003e\n\u003cimg src=\"/images/codebreaker-2025/badge1.png\" alt=\"Badge\" width=\"300\"/\u003e\n\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eSuccess!\u003c/strong\u003e My first ever NSA Codebreaker challenge complete.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003eSeries overview\u003c/a\u003e · \u003ca href=\"/posts/nsa-codebreaker-2025-task-2/\"\u003eTask 2 →\u003c/a\u003e\u003c/p\u003e\n","date":"2026-10-03","dateFormatted":"2026.10.03","excerpt":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"task-1---getting-started-forensics\"\u003eTask 1 - Getting Started (Forensics)\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003eYou arrive on site and immediately get to work. The DAFIN-SOC team quickly briefs you on the situation. They have noticed numerous anomalous …\u003c/p\u003e\u003c/blockquote\u003e","featured":false,"mood":null,"permalink":"/posts/nsa-codebreaker-2025-task-1/","readingTime":2,"slug":"nsa-codebreaker-2025-task-1","subtitle":"Finding a suspicious artifact in an EXT2 image","summary":"\u003cp\u003e\u003ca href=\"/posts/nsa-codebreaker-2025/\"\u003e← Series overview\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"task-1---getting-started-forensics\"\u003eTask 1 - Getting Started (Forensics)\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003eYou arrive on site and immediately get to work. The DAFIN-SOC team quickly briefs you on the situation. They have noticed numerous anomalous behaviors, such as: tools randomly failing tests and anti-virus flagging on seemingly clean workstations. They have narrowed in on one machine they would like NSA to thoroughly evaluate.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003eThey have provided a zipped EXT2 image from this development machine. Help DAFIN-SOC perform a forensic analysis on this - looking for any suspicious artifacts.\u003c/p\u003e","tags":["NSA Codebreaker 2025","ctf","forensics"],"title":"NSA Codebreaker 2025 — Task 1: Getting Started","url":"/posts/nsa-codebreaker-2025-task-1/","wordCount":278},{"content":"\u003cdiv style=\"display: flex; flex-wrap: wrap; align-items: center; gap: 2rem; margin-bottom: 2rem;\"\u003e\n  \u003cimg src=\"/images/tomi.jpg\" alt=\"Tomi Bodwell Mamic\" style=\"border-radius: 15px; width: 250px; max-width: 100%; height: 250px; object-fit: cover; flex-shrink: 0;\"\u003e\n  \u003ch1 style=\"margin: 0; font-size: 2.5rem; flex: 1 1 250px;\"\u003eHey! I'm Tomi, an Associate Security Consultant at LRQA and an Applied Cybersecurity student.\u003c/h1\u003e\n\u003c/div\u003e\n\u003ch3 id=\"what-im-working-on-at-lrqa\"\u003eWhat I\u0026rsquo;m Working On at LRQA\u003c/h3\u003e\n\u003cp\u003eI\u0026rsquo;m currently working at \u003cstrong\u003eLRQA in Birmingham, UK\u003c/strong\u003e, as an \u003cstrong\u003eAssociate Security Consultant\u003c/strong\u003e, with a focus on \u003cstrong\u003eimplementing AI into penetration testing workflows\u003c/strong\u003e. My work includes developing vulnerability knowledge bases (VKBs) for local AI penetration testing tooling to help streamline testing automation.\u003c/p\u003e\n\u003cp\u003eI also participate in \u003cstrong\u003emobile, web application, API, and infrastructure penetration tests\u003c/strong\u003e, from the kick-off call through delivery. I\u0026rsquo;m interested in how AI can support the practical work of security consultants, alongside the technical judgment needed to assess findings.\u003c/p\u003e\n\u003ch3 id=\"education--certifications\"\u003eEducation \u0026amp; Certifications\u003c/h3\u003e\n\u003cp\u003eI\u0026rsquo;m pursuing a \u003cstrong\u003eBachelor of Science in Applied Cybersecurity at the SANS Technology Institute\u003c/strong\u003e, with a \u003cstrong\u003e4.0 GPA\u003c/strong\u003e and expected graduation in \u003cstrong\u003eJune 2027\u003c/strong\u003e. I previously studied at \u003cstrong\u003ethe University of Texas at Austin\u003c/strong\u003e and \u003cstrong\u003eSanta Monica College\u003c/strong\u003e, earning a 4.0 GPA at both, with University Honors and highest honors respectively.\u003c/p\u003e\n\u003cp\u003eMy GIAC certifications include:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eGFACT\u003c/strong\u003e — Foundational Cybersecurity Technologies\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGSEC\u003c/strong\u003e — Security Essentials\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGCIH\u003c/strong\u003e — Certified Incident Handler\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGPYC\u003c/strong\u003e — Python Coder\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eI\u0026rsquo;m also working toward \u003cstrong\u003eGCFA — Certified Forensic Analyst\u003c/strong\u003e.\u003c/p\u003e\n\u003ch3 id=\"projects--competitions\"\u003eProjects \u0026amp; Competitions\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eFireplace\u003c/strong\u003e: I\u0026rsquo;m building an open-source chat app with \u003cstrong\u003eFlutter\u003c/strong\u003e and working on implementing \u003cstrong\u003eend-to-end encryption\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNSA Codebreaker Challenge 2026\u003c/strong\u003e: The \u003cstrong\u003e12th student to complete the full challenge\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eSANS Core NetWars 12, Amsterdam 2026\u003c/strong\u003e: \u003cstrong\u003e2nd place\u003c/strong\u003e, qualifying for the \u003cstrong\u003eSANS Tournament of Champions in Washington, DC\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNational Cyber League Spring 2026\u003c/strong\u003e: My team placed \u003cstrong\u003e1st out of 170 teams in the experienced bracket\u003c/strong\u003e. I completed all web application exploitation and cryptography challenges for the team.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNational Cyber League Fall 2025\u003c/strong\u003e: \u003cstrong\u003e2nd out of 617 in the experienced individual bracket\u003c/strong\u003e, completing all challenges.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNSA Codebreaker Challenge 2025\u003c/strong\u003e: One of \u003cstrong\u003e82 students to complete the full challenge\u003c/strong\u003e, covering network and memory forensics, reverse engineering, cryptography, and a custom Android application exploit.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eI received \u003cstrong\u003etwo $4,500 SANS Institute scholarships in 2025\u003c/strong\u003e, recognizing my National Cyber League performance and completion of all seven NSA Codebreaker tasks.\u003c/p\u003e\n\u003ch3 id=\"skills--other-experience\"\u003eSkills \u0026amp; Other Experience\u003c/h3\u003e\n\u003cp\u003eMy interests span \u003cstrong\u003epenetration testing, cryptography, digital and memory forensics, threat detection, and incident response\u003c/strong\u003e. I work with \u003cstrong\u003ePython, PowerShell, and SQL\u003c/strong\u003e, and tools including \u003cstrong\u003eNmap, Wireshark, Metasploit, Netcat, and SQLmap\u003c/strong\u003e, across Linux, Windows, Active Directory, containers, virtualization, and cloud environments.\u003c/p\u003e\n\u003cp\u003eOutside cybersecurity, I\u0026rsquo;ve contributed to research at UT Austin: using \u003cstrong\u003eR\u003c/strong\u003e to investigate genetic selection trends in a high-altitude adaptation study with the \u003cstrong\u003eChildebayeva Lab\u003c/strong\u003e, and presenting soil microbiome research at the \u003cstrong\u003eUniversity of Wisconsin–Madison\u003c/strong\u003e. My time as a \u003cstrong\u003eUT RecSports lifeguard\u003c/strong\u003e also gave me experience with emergency response drills and maintaining CPR, AED, and First Aid certifications.\u003c/p\u003e\n\u003ch3 id=\"get-in-touch\"\u003eGet in Touch\u003c/h3\u003e\n\u003cp\u003eI\u0026rsquo;m always interested in connecting with people working on \u003cstrong\u003eAI in penetration testing, security research, and secure application development\u003c/strong\u003e.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"/files/BodwellMamicResume.pdf\"\u003eDownload My Resume\u003c/a\u003e\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEmail: \u003ca href=\"mailto:contact@xss3cut10n3r.com\"\u003econtact@xss3cut10n3r.com\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eGitHub: \u003ca href=\"https://github.com/XSS3cut10n3r\"\u003egithub.com/XSS3cut10n3r\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eLinkedIn: \u003ca href=\"https://linkedin.com/in/tomibodwellmamic\"\u003elinkedin.com/in/tomibodwellmamic\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n","date":"2025-10-27","dateFormatted":"2025.10.27","excerpt":"\u003cdiv style=\"display: flex; flex-wrap: wrap; align-items: center; gap: 2rem; margin-bottom: 2rem;\"\u003e\n  \u003cimg src=\"/images/tomi.jpg\" alt=\"Tomi Bodwell Mamic\" style=\"border-radius: 15px; width: 250px; max-width: 100%; height: 250px; object-fit: cover; flex-shrink: 0;\"\u003e\n  \u003ch1 style=\"margin: 0; font-size: 2.5rem; flex: 1 1 250px;\"\u003eHey! I'm Tomi, an Associate Security Consultant at LRQA and an Applied Cybersecurity student.\u003c/h1\u003e\n\u003c/div\u003e\n\u003ch3 id=\"what-im-working-on-at-lrqa\"\u003eWhat I\u0026rsquo;m Working On at LRQA\u003c/h3\u003e\n\u003cp\u003eI\u0026rsquo;m currently working at \u003cstrong\u003eLRQA in Birmingham, UK\u003c/strong\u003e, as an …\u003c/p\u003e","featured":true,"mood":null,"permalink":"/posts/hireme/","readingTime":3,"slug":"hireme","subtitle":"My work, projects, and journey in cybersecurity","summary":"\u003cdiv style=\"display: flex; flex-wrap: wrap; align-items: center; gap: 2rem; margin-bottom: 2rem;\"\u003e\n  \u003cimg src=\"/images/tomi.jpg\" alt=\"Tomi Bodwell Mamic\" style=\"border-radius: 15px; width: 250px; max-width: 100%; height: 250px; object-fit: cover; flex-shrink: 0;\"\u003e\n  \u003ch1 style=\"margin: 0; font-size: 2.5rem; flex: 1 1 250px;\"\u003eHey! I'm Tomi, an Associate Security Consultant at LRQA and an Applied Cybersecurity student.\u003c/h1\u003e\n\u003c/div\u003e\n\u003ch3 id=\"what-im-working-on-at-lrqa\"\u003eWhat I\u0026rsquo;m Working On at LRQA\u003c/h3\u003e\n\u003cp\u003eI\u0026rsquo;m currently working at \u003cstrong\u003eLRQA in Birmingham, UK\u003c/strong\u003e, as an \u003cstrong\u003eAssociate Security Consultant\u003c/strong\u003e, with a focus on \u003cstrong\u003eimplementing AI into penetration testing workflows\u003c/strong\u003e. My work includes developing vulnerability knowledge bases (VKBs) for local AI penetration testing tooling to help streamline testing automation.\u003c/p\u003e","tags":["career","about"],"title":"About Me: Cybersecurity, LRQA \u0026 AI","url":"/posts/hireme/","wordCount":464},{"content":"\u003cp\u003eCryptography challenges are one of the most common categories in Capture the Flag (CTF) competitions. This guide provides a focused overview of essential algorithms, how to recognize them, common weaknesses exploited in CTFs, and practical resources for practice.\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"common-ctf-crypto-patterns\"\u003eCommon CTF Crypto Patterns\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFlags often follow formats like \u003ccode\u003eCTF{...}\u003c/code\u003e, which can help in known-plaintext scenarios.\u003c/li\u003e\n\u003cli\u003eKey reuse across ciphertexts can allow XOR analysis.\u003c/li\u003e\n\u003cli\u003eSmall RSA exponents (\u003ccode\u003ee = 3\u003c/code\u003e) can lead to direct root extraction if the plaintext is small.\u003c/li\u003e\n\u003cli\u003eSmall primes allow for easy factorization of RSA moduli.\u003c/li\u003e\n\u003cli\u003ePadding issues in AES frequently lead to oracle-style attacks.\u003c/li\u003e\n\u003cli\u003eImages encrypted with ECB will show visible repeated patterns.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"tools\"\u003eTools\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://gchq.github.io/CyberChef/\"\u003eCyberChef\u003c/a\u003e - versatile tool for conversions, encodings, and ciphers.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.cachesleuth.com/multidecoder/\"\u003eCacheSleuth MultiDecoder\u003c/a\u003e - automated format and cipher detection. Easily my favorite tool.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.dcode.fr/en\"\u003edCode\u003c/a\u003e - classical cipher solvers and crypto utilities.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/RsaCtfTool/RsaCtfTool\"\u003eRsaCtfTool\u003c/a\u003e - specialized RSA attack tool.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"core-algorithms\"\u003eCore Algorithms\u003c/h2\u003e\n\u003ch3 id=\"rsa\"\u003eRSA\u003c/h3\u003e\n\u003cp\u003eRSA is an asymmetric encryption algorithm based on modular arithmetic with large primes.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eKey structure\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePublic key: \u003ccode\u003e(n, e)\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003ePrivate key: \u003ccode\u003ed\u003c/code\u003e, where \u003ccode\u003eed ≡ 1 (mod φ(n))\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eEncryption: \u003ccode\u003ec = m^e mod n\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eDecryption: \u003ccode\u003em = c^d mod n\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eClues in challenges\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eLarge integer values, often labeled \u003ccode\u003en\u003c/code\u003e, \u003ccode\u003ee\u003c/code\u003e, \u003ccode\u003ed\u003c/code\u003e, \u003ccode\u003ep\u003c/code\u003e, \u003ccode\u003eq\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eSmall exponents such as \u003ccode\u003ee = 3\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eModulus values that are not very large (easy to factor).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eCommon attacks\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFactoring \u003ccode\u003en\u003c/code\u003e into \u003ccode\u003ep\u003c/code\u003e and \u003ccode\u003eq\u003c/code\u003e when too small.\u003c/li\u003e\n\u003cli\u003eBroadcast attack when the same message is sent to multiple recipients with small \u003ccode\u003ee\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eWiener’s attack if the private key \u003ccode\u003ed\u003c/code\u003e is too small.\u003c/li\u003e\n\u003cli\u003eCommon modulus attacks when the same \u003ccode\u003en\u003c/code\u003e is reused across different keys.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eTooling\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/RsaCtfTool/RsaCtfTool\"\u003eRsaCtfTool\u003c/a\u003e automates many known attacks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch3 id=\"aes\"\u003eAES\u003c/h3\u003e\n\u003cp\u003eAES is a symmetric cipher often encountered in ECB or CBC mode.\u003c/p\u003e\n\u003ch4 id=\"aes-ecb-electronic-codebook\"\u003eAES-ECB (Electronic Codebook)\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eEncrypts each block independently.\u003c/li\u003e\n\u003cli\u003eEasy to spot because identical plaintext blocks lead to identical ciphertext blocks.\u003c/li\u003e\n\u003cli\u003eOften leaks patterns in images or structured data.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"aes-cbc-cipher-block-chaining\"\u003eAES-CBC (Cipher Block Chaining)\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eEach block is XORed with the previous ciphertext block before encryption.\u003c/li\u003e\n\u003cli\u003eRequires an initialization vector (IV).\u003c/li\u003e\n\u003cli\u003eCiphertexts are usually a multiple of the block size.\u003c/li\u003e\n\u003cli\u003eChallenges may involve padding oracle attacks or IV reuse.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"example\"\u003eExample\u003c/h4\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-python\" data-lang=\"python\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eSBOX \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e [\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#ae81ff\"\u003e0x63\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x7c\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x77\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x7b\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xf2\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x6b\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x6f\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xc5\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x30\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x01\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x67\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x2b\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xfe\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xd7\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xab\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x76\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#ae81ff\"\u003e0xca\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x82\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xc9\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x7d\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xfa\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x59\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x47\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xf0\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xad\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xd4\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xa2\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xaf\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x9c\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xa4\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x72\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xc0\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#ae81ff\"\u003e0xb7\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xfd\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x93\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x26\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x36\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x3f\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xf7\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xcc\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x34\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xa5\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xe5\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xf1\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x71\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xd8\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x31\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x15\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#ae81ff\"\u003e0x04\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xc7\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x23\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xc3\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x18\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x96\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x05\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x9a\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x07\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x12\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x80\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xe2\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xeb\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x27\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xb2\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x75\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#ae81ff\"\u003e0x09\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x83\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x2c\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x1a\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x1b\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x6e\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x5a\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xa0\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x52\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x3b\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xd6\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xb3\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x29\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xe3\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x2f\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x84\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#ae81ff\"\u003e0x53\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xd1\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x00\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xed\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x20\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xfc\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xb1\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x5b\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x6a\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xcb\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xbe\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x39\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x4a\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x4c\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x58\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xcf\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#ae81ff\"\u003e0xd0\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xef\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xaa\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xfb\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x43\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x4d\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x33\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x85\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x45\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xf9\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x02\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x7f\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x50\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x3c\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x9f\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xa8\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#ae81ff\"\u003e0x51\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xa3\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x40\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x8f\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x92\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x9d\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x38\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xf5\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xbc\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xb6\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xda\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x21\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x10\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xff\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xf3\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xd2\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#ae81ff\"\u003e0xcd\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x0c\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x13\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xec\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x5f\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x97\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x44\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x17\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xc4\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xa7\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x7e\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x3d\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x64\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x5d\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x19\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x73\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#ae81ff\"\u003e0x60\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x81\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x4f\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xdc\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x22\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x2a\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x90\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x88\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x46\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xee\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xb8\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x14\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xde\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x5e\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x0b\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xdb\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#ae81ff\"\u003e0xe0\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x32\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x3a\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x0a\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x49\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x06\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x24\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x5c\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xc2\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xd3\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xac\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x62\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x91\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x95\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xe4\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x79\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#ae81ff\"\u003e0xe7\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xc8\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x37\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x6d\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x8d\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xd5\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x4e\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xa9\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x6c\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x56\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xf4\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xea\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x65\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x7a\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xae\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x08\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#ae81ff\"\u003e0xba\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x78\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x25\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x2e\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x1c\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xa6\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xb4\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xc6\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xe8\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xdd\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x74\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x1f\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x4b\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xbd\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x8b\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x8a\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#ae81ff\"\u003e0x70\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x3e\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xb5\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x66\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x48\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x03\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xf6\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x0e\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x61\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x35\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x57\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xb9\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x86\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xc1\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x1d\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x9e\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#ae81ff\"\u003e0xe1\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xf8\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x98\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x11\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x69\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xd9\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x8e\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x94\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x9b\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x1e\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x87\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xe9\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xce\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x55\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x28\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xdf\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#ae81ff\"\u003e0x8c\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xa1\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x89\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x0d\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xbf\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xe6\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x42\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x68\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x41\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x99\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x2d\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x0f\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xb0\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x54\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0xbb\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x16\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eRCON \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e [\u003cspan style=\"color:#ae81ff\"\u003e0x01\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x02\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x04\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x08\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x10\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x20\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x40\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x80\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x1B\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e0x36\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#66d9ef\"\u003edef\u003c/span\u003e \u003cspan style=\"color:#a6e22e\"\u003esub_bytes\u003c/span\u003e(s): \u003cspan style=\"color:#66d9ef\"\u003ereturn\u003c/span\u003e [SBOX[b] \u003cspan style=\"color:#66d9ef\"\u003efor\u003c/span\u003e b \u003cspan style=\"color:#f92672\"\u003ein\u003c/span\u003e s]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#66d9ef\"\u003edef\u003c/span\u003e \u003cspan style=\"color:#a6e22e\"\u003eshift_rows\u003c/span\u003e(s):\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#66d9ef\"\u003ereturn\u003c/span\u003e [\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        s[\u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e], s[\u003cspan style=\"color:#ae81ff\"\u003e5\u003c/span\u003e], s[\u003cspan style=\"color:#ae81ff\"\u003e10\u003c/span\u003e], s[\u003cspan style=\"color:#ae81ff\"\u003e15\u003c/span\u003e],\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        s[\u003cspan style=\"color:#ae81ff\"\u003e4\u003c/span\u003e], s[\u003cspan style=\"color:#ae81ff\"\u003e9\u003c/span\u003e], s[\u003cspan style=\"color:#ae81ff\"\u003e14\u003c/span\u003e], s[\u003cspan style=\"color:#ae81ff\"\u003e3\u003c/span\u003e],\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        s[\u003cspan style=\"color:#ae81ff\"\u003e8\u003c/span\u003e], s[\u003cspan style=\"color:#ae81ff\"\u003e13\u003c/span\u003e], s[\u003cspan style=\"color:#ae81ff\"\u003e2\u003c/span\u003e], s[\u003cspan style=\"color:#ae81ff\"\u003e7\u003c/span\u003e],\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        s[\u003cspan style=\"color:#ae81ff\"\u003e12\u003c/span\u003e], s[\u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e], s[\u003cspan style=\"color:#ae81ff\"\u003e6\u003c/span\u003e], s[\u003cspan style=\"color:#ae81ff\"\u003e11\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    ]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#66d9ef\"\u003edef\u003c/span\u003e \u003cspan style=\"color:#a6e22e\"\u003extime\u003c/span\u003e(a): \u003cspan style=\"color:#66d9ef\"\u003ereturn\u003c/span\u003e ((a\u003cspan style=\"color:#f92672\"\u003e\u0026lt;\u0026lt;\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e)\u003cspan style=\"color:#f92672\"\u003e^\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e0x1B\u003c/span\u003e)\u003cspan style=\"color:#f92672\"\u003e\u0026amp;\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e0xFF\u003c/span\u003e \u003cspan style=\"color:#66d9ef\"\u003eif\u003c/span\u003e a\u003cspan style=\"color:#f92672\"\u003e\u0026amp;\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e0x80\u003c/span\u003e \u003cspan style=\"color:#66d9ef\"\u003eelse\u003c/span\u003e (a\u003cspan style=\"color:#f92672\"\u003e\u0026lt;\u0026lt;\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#66d9ef\"\u003edef\u003c/span\u003e \u003cspan style=\"color:#a6e22e\"\u003emix_single_column\u003c/span\u003e(col):\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    t \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e col[\u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e]\u003cspan style=\"color:#f92672\"\u003e^\u003c/span\u003ecol[\u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e]\u003cspan style=\"color:#f92672\"\u003e^\u003c/span\u003ecol[\u003cspan style=\"color:#ae81ff\"\u003e2\u003c/span\u003e]\u003cspan style=\"color:#f92672\"\u003e^\u003c/span\u003ecol[\u003cspan style=\"color:#ae81ff\"\u003e3\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    u \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e col[\u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e]; col[\u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e]\u003cspan style=\"color:#f92672\"\u003e^=\u003c/span\u003et\u003cspan style=\"color:#f92672\"\u003e^\u003c/span\u003extime(col[\u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e]\u003cspan style=\"color:#f92672\"\u003e^\u003c/span\u003ecol[\u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e])\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    col[\u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e]\u003cspan style=\"color:#f92672\"\u003e^=\u003c/span\u003et\u003cspan style=\"color:#f92672\"\u003e^\u003c/span\u003extime(col[\u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e]\u003cspan style=\"color:#f92672\"\u003e^\u003c/span\u003ecol[\u003cspan style=\"color:#ae81ff\"\u003e2\u003c/span\u003e])\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    col[\u003cspan style=\"color:#ae81ff\"\u003e2\u003c/span\u003e]\u003cspan style=\"color:#f92672\"\u003e^=\u003c/span\u003et\u003cspan style=\"color:#f92672\"\u003e^\u003c/span\u003extime(col[\u003cspan style=\"color:#ae81ff\"\u003e2\u003c/span\u003e]\u003cspan style=\"color:#f92672\"\u003e^\u003c/span\u003ecol[\u003cspan style=\"color:#ae81ff\"\u003e3\u003c/span\u003e])\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    col[\u003cspan style=\"color:#ae81ff\"\u003e3\u003c/span\u003e]\u003cspan style=\"color:#f92672\"\u003e^=\u003c/span\u003et\u003cspan style=\"color:#f92672\"\u003e^\u003c/span\u003extime(col[\u003cspan style=\"color:#ae81ff\"\u003e3\u003c/span\u003e]\u003cspan style=\"color:#f92672\"\u003e^\u003c/span\u003eu)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#66d9ef\"\u003edef\u003c/span\u003e \u003cspan style=\"color:#a6e22e\"\u003emix_columns\u003c/span\u003e(s):\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#66d9ef\"\u003efor\u003c/span\u003e i \u003cspan style=\"color:#f92672\"\u003ein\u003c/span\u003e range(\u003cspan style=\"color:#ae81ff\"\u003e4\u003c/span\u003e): mix_single_column(s[i\u003cspan style=\"color:#f92672\"\u003e*\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e4\u003c/span\u003e:(i\u003cspan style=\"color:#f92672\"\u003e+\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e)\u003cspan style=\"color:#f92672\"\u003e*\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e4\u003c/span\u003e])\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#66d9ef\"\u003ereturn\u003c/span\u003e s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#66d9ef\"\u003edef\u003c/span\u003e \u003cspan style=\"color:#a6e22e\"\u003eadd_round_key\u003c/span\u003e(s,k): \u003cspan style=\"color:#66d9ef\"\u003ereturn\u003c/span\u003e [a\u003cspan style=\"color:#f92672\"\u003e^\u003c/span\u003eb \u003cspan style=\"color:#66d9ef\"\u003efor\u003c/span\u003e a,b \u003cspan style=\"color:#f92672\"\u003ein\u003c/span\u003e zip(s,k)]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#66d9ef\"\u003edef\u003c/span\u003e \u003cspan style=\"color:#a6e22e\"\u003ekey_expansion\u003c/span\u003e(key):\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    Nk, Nr \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e4\u003c/span\u003e, \u003cspan style=\"color:#ae81ff\"\u003e10\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    w \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e [list(key[i:i\u003cspan style=\"color:#f92672\"\u003e+\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e4\u003c/span\u003e]) \u003cspan style=\"color:#66d9ef\"\u003efor\u003c/span\u003e i \u003cspan style=\"color:#f92672\"\u003ein\u003c/span\u003e range(\u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e16\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e4\u003c/span\u003e)]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#66d9ef\"\u003efor\u003c/span\u003e i \u003cspan style=\"color:#f92672\"\u003ein\u003c/span\u003e range(Nk, \u003cspan style=\"color:#ae81ff\"\u003e4\u003c/span\u003e\u003cspan style=\"color:#f92672\"\u003e*\u003c/span\u003e(Nr\u003cspan style=\"color:#f92672\"\u003e+\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e)):\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        temp \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e w[i\u003cspan style=\"color:#f92672\"\u003e-\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e][:]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#66d9ef\"\u003eif\u003c/span\u003e i\u003cspan style=\"color:#f92672\"\u003e%\u003c/span\u003eNk\u003cspan style=\"color:#f92672\"\u003e==\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            temp \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e temp[\u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e:]\u003cspan style=\"color:#f92672\"\u003e+\u003c/span\u003etemp[:\u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            temp \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e [SBOX[b] \u003cspan style=\"color:#66d9ef\"\u003efor\u003c/span\u003e b \u003cspan style=\"color:#f92672\"\u003ein\u003c/span\u003e temp]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            temp[\u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e] \u003cspan style=\"color:#f92672\"\u003e^=\u003c/span\u003e RCON[i\u003cspan style=\"color:#f92672\"\u003e//\u003c/span\u003eNk \u003cspan style=\"color:#f92672\"\u003e-\u003c/span\u003e \u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        w\u003cspan style=\"color:#f92672\"\u003e.\u003c/span\u003eappend([a\u003cspan style=\"color:#f92672\"\u003e^\u003c/span\u003eb \u003cspan style=\"color:#66d9ef\"\u003efor\u003c/span\u003e a,b \u003cspan style=\"color:#f92672\"\u003ein\u003c/span\u003e zip(w[i\u003cspan style=\"color:#f92672\"\u003e-\u003c/span\u003eNk],temp)])\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#66d9ef\"\u003ereturn\u003c/span\u003e [sum(w[\u003cspan style=\"color:#ae81ff\"\u003e4\u003c/span\u003e\u003cspan style=\"color:#f92672\"\u003e*\u003c/span\u003ei:\u003cspan style=\"color:#ae81ff\"\u003e4\u003c/span\u003e\u003cspan style=\"color:#f92672\"\u003e*\u003c/span\u003ei\u003cspan style=\"color:#f92672\"\u003e+\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e4\u003c/span\u003e],[]) \u003cspan style=\"color:#66d9ef\"\u003efor\u003c/span\u003e i \u003cspan style=\"color:#f92672\"\u003ein\u003c/span\u003e range(Nr\u003cspan style=\"color:#f92672\"\u003e+\u003c/span\u003e\u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e)]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#66d9ef\"\u003edef\u003c/span\u003e \u003cspan style=\"color:#a6e22e\"\u003eaes_encrypt_block\u003c/span\u003e(block,key):\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    state \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e list(block)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    round_keys \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e key_expansion(list(key))\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    state \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e add_round_key(state, round_keys[\u003cspan style=\"color:#ae81ff\"\u003e0\u003c/span\u003e])\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#66d9ef\"\u003efor\u003c/span\u003e r \u003cspan style=\"color:#f92672\"\u003ein\u003c/span\u003e range(\u003cspan style=\"color:#ae81ff\"\u003e1\u003c/span\u003e,\u003cspan style=\"color:#ae81ff\"\u003e10\u003c/span\u003e):\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        state \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e sub_bytes(state)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        state \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e shift_rows(state)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        state \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e mix_columns(state)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        state \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e add_round_key(state, round_keys[r])\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    state \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e sub_bytes(state)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    state \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e shift_rows(state)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    state \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e add_round_key(state, round_keys[\u003cspan style=\"color:#ae81ff\"\u003e10\u003c/span\u003e])\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#66d9ef\"\u003ereturn\u003c/span\u003e bytes(state)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eplaintext \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#e6db74\"\u003eb\u003c/span\u003e\u003cspan style=\"color:#e6db74\"\u003e\u0026#34;ABCDEFGHIJKLMNOP\u0026#34;\u003c/span\u003e    \u003cspan style=\"color:#75715e\"\u003e# 16 bytes\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ekey       \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#e6db74\"\u003eb\u003c/span\u003e\u003cspan style=\"color:#e6db74\"\u003e\u0026#34;thisisasecretkey\u0026#34;\u003c/span\u003e   \u003cspan style=\"color:#75715e\"\u003e# 16 bytes (AES-128)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecipher    \u003cspan style=\"color:#f92672\"\u003e=\u003c/span\u003e aes_encrypt_block(plaintext, key)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eprint(cipher\u003cspan style=\"color:#f92672\"\u003e.\u003c/span\u003ehex())\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003ch2 id=\"further-practice\"\u003eFurther Practice\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.hackthebox.com/\"\u003eHackTheBox\u003c/a\u003e - their labs have a ton of modern crypto challenges but they\u0026rsquo;re quite hard!\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://ctftime.org/\"\u003eCTFtime.org\u003c/a\u003e - event listings, writeups, and past problems.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://cryptohack.org/\"\u003eCryptoHack\u003c/a\u003e - puzzle-based platform for learning cryptography step by step.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://picoctf.org/\"\u003epicoCTF\u003c/a\u003e - beginner-friendly competitions with accessible crypto challenges.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://overthewire.org/wargames/krypton/\"\u003eOverTheWire Krypton\u003c/a\u003e - practice classical cryptography problems.\u003c/li\u003e\n\u003c/ul\u003e\n","date":"2025-08-27","dateFormatted":"2025.08.27","excerpt":"\u003cp\u003eCryptography challenges are one of the most common categories in Capture the Flag (CTF) competitions. This guide provides a focused overview of essential algorithms, how to recognize them, common …\u003c/p\u003e","featured":false,"mood":null,"permalink":"/posts/crypto-cheatsheet/","readingTime":3,"slug":"crypto-cheatsheet","subtitle":"A useful cryptography cheatsheet","summary":"\u003cp\u003eCryptography challenges are one of the most common categories in Capture the Flag (CTF) competitions. This guide provides a focused overview of essential algorithms, how to recognize them, common weaknesses exploited in CTFs, and practical resources for practice.\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"common-ctf-crypto-patterns\"\u003eCommon CTF Crypto Patterns\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFlags often follow formats like \u003ccode\u003eCTF{...}\u003c/code\u003e, which can help in known-plaintext scenarios.\u003c/li\u003e\n\u003cli\u003eKey reuse across ciphertexts can allow XOR analysis.\u003c/li\u003e\n\u003cli\u003eSmall RSA exponents (\u003ccode\u003ee = 3\u003c/code\u003e) can lead to direct root extraction if the plaintext is small.\u003c/li\u003e\n\u003cli\u003eSmall primes allow for easy factorization of RSA moduli.\u003c/li\u003e\n\u003cli\u003ePadding issues in AES frequently lead to oracle-style attacks.\u003c/li\u003e\n\u003cli\u003eImages encrypted with ECB will show visible repeated patterns.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"tools\"\u003eTools\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://gchq.github.io/CyberChef/\"\u003eCyberChef\u003c/a\u003e - versatile tool for conversions, encodings, and ciphers.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.cachesleuth.com/multidecoder/\"\u003eCacheSleuth MultiDecoder\u003c/a\u003e - automated format and cipher detection. Easily my favorite tool.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.dcode.fr/en\"\u003edCode\u003c/a\u003e - classical cipher solvers and crypto utilities.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/RsaCtfTool/RsaCtfTool\"\u003eRsaCtfTool\u003c/a\u003e - specialized RSA attack tool.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"core-algorithms\"\u003eCore Algorithms\u003c/h2\u003e\n\u003ch3 id=\"rsa\"\u003eRSA\u003c/h3\u003e\n\u003cp\u003eRSA is an asymmetric encryption algorithm based on modular arithmetic with large primes.\u003c/p\u003e","tags":["crypto","cheatsheet","ctf"],"title":"Crypto Cheatsheet for CTFs","url":"/posts/crypto-cheatsheet/","wordCount":595},{"content":"\u003cp\u003eOften when uploading a reverse shell on a webserver we are dealing with non-interactive shell. This means it doesn\u0026rsquo;t prompt us for user input or display output in real-time in a traditional terminal window.\u003c/p\u003e\n\u003cp\u003eThe biggest problem with a non-interactive shell is that you can\u0026rsquo;t run \u003ccode\u003esu\u003c/code\u003e or \u003ccode\u003esudo\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eUseful ways to upgrade your shell to an interactive one:\u003c/strong\u003e\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-python\" data-lang=\"python\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003epython \u003cspan style=\"color:#f92672\"\u003e-\u003c/span\u003ec \u003cspan style=\"color:#e6db74\"\u003e\u0026#39;import pty; pty.spawn(\u0026#34;/bin/sh\u0026#34;)\u0026#39;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eWhen to use it:\u003c/strong\u003e Almost always the first go-to if Python is available on the target. After spawning, run Ctrl-Z and then stty raw -echo; fg on your local terminal to fully fix arrow keys and job control.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-console\" data-lang=\"console\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eecho \u0026#39;os.system(\u0026#39;/bin/bash\u0026#39;)\u0026#39;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eWhen to use it:\u003c/strong\u003e When you can inject Python code but can’t directly execute shell commands.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-console\" data-lang=\"console\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/bin/sh -i\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eor\u003c/strong\u003e\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-console\" data-lang=\"console\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/bin/bash -i\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eWhen to use it:\u003c/strong\u003e Works on minimal systems where Python or Perl might not be installed. Note the -i flag forces the terminal to be interactive.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-console\" data-lang=\"console\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eperl -e \u0026#39;exec \u0026#34;/bin/sh\u0026#34;;\u0026#39;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eWhen to use it:\u003c/strong\u003e When Python isn’t available, but Perl is. This takes advantage of Perl’s exec function.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-console\" data-lang=\"console\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:!bash\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eWhen to use it:\u003c/strong\u003e If you can edit files on the system and Vim is installed. This is often used in “local shell escape” scenarios.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-console\" data-lang=\"console\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eSHELL=/bin/bash script -q /dev/null\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eWhen to use it:\u003c/strong\u003e This command is very reliable if \u003ccode\u003escript\u003c/code\u003e is installed. \u003ccode\u003eScript\u003c/code\u003e spawns a fully interactive shell session, which fixes TTY issues\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-console\" data-lang=\"console\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003estty raw -echo \u0026amp;\u0026amp; fg\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eWhen to use it:\u003c/strong\u003e This resets your terminal to raw mode and resumes the background shell. You should use it when your shell has been suspended with Ctrl + Z.\u003c/p\u003e\n\u003ch2 id=\"cheatsheet\"\u003eCheatsheet\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eStart by checking available interpreters:\u003c/strong\u003e\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-console\" data-lang=\"console\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewhich python3 python perl bash sh\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eFix terminal controls after an upgrade:\u003c/strong\u003e\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-console\" data-lang=\"console\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eCtrl+Z\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#960050;background-color:#1e0010\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003estty raw -echo\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#960050;background-color:#1e0010\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003efg\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#960050;background-color:#1e0010\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereset\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eTip:\u003c/strong\u003e Try Ctrl + C, Ctrl + Z, and Tab completion to make sure the shell is fully interactive.\u003c/p\u003e\n\u003c/blockquote\u003e\n","date":"2025-08-26","dateFormatted":"2025.08.26","excerpt":"\u003cp\u003eOften when uploading a reverse shell on a webserver we are dealing with non-interactive shell. This means it doesn\u0026rsquo;t prompt us for user input or display output in real-time in a traditional …\u003c/p\u003e","featured":false,"mood":null,"permalink":"/posts/interactive-shells/","readingTime":2,"slug":"interactive-shells","subtitle":"Cheatsheet for obtaining fully-interactive shells","summary":"\u003cp\u003eOften when uploading a reverse shell on a webserver we are dealing with non-interactive shell. This means it doesn\u0026rsquo;t prompt us for user input or display output in real-time in a traditional terminal window.\u003c/p\u003e\n\u003cp\u003eThe biggest problem with a non-interactive shell is that you can\u0026rsquo;t run \u003ccode\u003esu\u003c/code\u003e or \u003ccode\u003esudo\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eUseful ways to upgrade your shell to an interactive one:\u003c/strong\u003e\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-python\" data-lang=\"python\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003epython \u003cspan style=\"color:#f92672\"\u003e-\u003c/span\u003ec \u003cspan style=\"color:#e6db74\"\u003e\u0026#39;import pty; pty.spawn(\u0026#34;/bin/sh\u0026#34;)\u0026#39;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eWhen to use it:\u003c/strong\u003e Almost always the first go-to if Python is available on the target. After spawning, run Ctrl-Z and then stty raw -echo; fg on your local terminal to fully fix arrow keys and job control.\u003c/p\u003e","tags":["linux","cheatsheet","privesc"],"title":"Gaining Interactive Shells","url":"/posts/interactive-shells/","wordCount":305},{"content":"\u003ch3 id=\"中國人\"\u003e中國人\u003c/h3\u003e\n\u003cp\u003e你好！我是一名对网络安全充满热情的人，尤其对渗透测试和道德黑客很感兴趣。我计划在这里记录自己的学习过程，分享在安全、技术和实践方面的心得与体会。希望这个网站能成为我整理经验、总结知识的地方，同时与大家一起在这个领域不断成长。\u003c/p\u003e\n\u003ch3 id=\"русский\"\u003eРусский\u003c/h3\u003e\n\u003cp\u003eПривет! Я человек, увлеченный кибербезопасностью, особенно меня интересуют тестирование на проникновение и этичный хакеринг. Я планирую здесь документировать свой процесс обучения и делиться своими знаниями и наблюдениями в области безопасности, технологий и лучших практик. Надеюсь, что этот сайт станет для меня местом, где можно систематизировать опыт, аккумулировать знания и расти в этой области вместе с другими.\u003c/p\u003e\n\u003ch3 id=\"english\"\u003eEnglish\u003c/h3\u003e\n\u003cp\u003eHello! I’m an individual with a strong interest in cybersecurity. I’m particularly drawn to penetration testing and ethical hacking, and I plan to document my learning journey here. My goal is to explore and share knowledge about security, techniques, and best practices, all in a safe and responsible manner. This website will serve as a place to catalog insights, experiences, and resources as I continue to grow in this field.\u003c/p\u003e\n","date":"2025-08-26","dateFormatted":"2025.08.26","excerpt":"\u003ch3 id=\"中國人\"\u003e中國人\u003c/h3\u003e\n\u003cp\u003e你好！我是一名对网络安全充满热情的人，尤其对渗透测试和道德黑客很感兴趣。我计划在这里记录自己的学习过程，分享在安全、技术和实践方面的心得与体会。希望这个网站能成为我整理经验、总结知识的地方，同时与大家一起在这个领域不断成长。\u003c/p\u003e\n\u003ch3 id=\"русский\"\u003eРусский\u003c/h3\u003e\n\u003cp\u003eПривет! Я человек, увлеченный кибербезопасностью, особенно меня интересуют …\u003c/p\u003e","featured":true,"mood":null,"permalink":"/posts/my-first-post/","readingTime":1,"slug":"my-first-post","subtitle":"简短介绍 - Краткий обзор - A brief overview","summary":"\u003ch3 id=\"中國人\"\u003e中國人\u003c/h3\u003e\n\u003cp\u003e你好！我是一名对网络安全充满热情的人，尤其对渗透测试和道德黑客很感兴趣。我计划在这里记录自己的学习过程，分享在安全、技术和实践方面的心得与体会。希望这个网站能成为我整理经验、总结知识的地方，同时与大家一起在这个领域不断成长。\u003c/p\u003e\n\u003ch3 id=\"русский\"\u003eРусский\u003c/h3\u003e\n\u003cp\u003eПривет! Я человек, увлеченный кибербезопасностью, особенно меня интересуют тестирование на проникновение и этичный хакеринг. Я планирую здесь документировать свой процесс обучения и делиться своими знаниями и наблюдениями в области безопасности, технологий и лучших практик. Надеюсь, что этот сайт станет для меня местом, где можно систематизировать опыт, аккумулировать знания и расти в этой области вместе с другими.\u003c/p\u003e\n\u003ch3 id=\"english\"\u003eEnglish\u003c/h3\u003e\n\u003cp\u003eHello! I’m an individual with a strong interest in cybersecurity. I’m particularly drawn to penetration testing and ethical hacking, and I plan to document my learning journey here. My goal is to explore and share knowledge about security, techniques, and best practices, all in a safe and responsible manner. This website will serve as a place to catalog insights, experiences, and resources as I continue to grow in this field.\u003c/p\u003e","tags":null,"title":"Whoami","url":"/posts/my-first-post/","wordCount":130}]