Blog

All posts

CTF

Flare-On 6 CTF WriteUp (Part 6)

This is the sixth part of the Flare-On 6 CTF WriteUp Series. 6 - bmphide The challenge reads Tyler Dean hiked up Mt. Elbert (Colorado's tallest mountain) at 2am to

11 min read Read →
CTF

Flare-On 6 CTF WriteUp (Part 5)

This is the fifth part of the Flare-On 6 CTF WriteUp series. 5 - Demo The challenge reads Someone on the Flare team tried to impress us with their demoscene skills. It

5 min read Read →
Flare-on

Flare-On 6 CTF WriteUp (Part 4)

This is the fourth part of the FlareOn 6 CTF WriteUp series. 4 - Dnschess The challenge reads > Some suspicious network traffic led us to this unauthorized chess program running on an

7 min read Read →
Flare-on

Flare-On 6 CTF WriteUp (Part 2)

This is the second part of the Flare-On 6 CTF WriteUp series. 2 - Overlong The challenge reads > The secret of this next challenge is cleverly hidden. However, with the right

4 min read Read →
Post

Flare-On 6 CTF WriteUp (Part 1)

Flare-On is a CTF style reverse engineering challenge organized by the FLARE team at FireEye Labs annually. There are a series of 12 challenges with increasing difficulty. This year the challenges

4 min read Read →
exploitation

Demystifying "Return-to-Zero-Protection" on ARM

Many of the techniques of x86 exploitation like Return-to-Libc doesn't map one-to-one with ARM. Here, we are going to explore Return-to-Libc and why it fails on ARM. We also show an alternate technique - Return to Zero Protection which overcomes all the limitations of ret2libc as applied to ARM.

9 min read Read →