<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" 
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
>
<channel xml:lang="fr">
<title>Root Me : plateforme d'apprentissage d&#233;di&#233;e au Hacking et &#224; la S&#233;curit&#233; de l'Information</title>
<link>https://www.root-me.org/</link>
<description>Root Me est une plateforme permettant &#224; chacun de tester et d'am&#233;liorer ses connaissances dans le domaine de la s&#233;curit&#233; informatique et du hacking &#224; travers la publication de challenges, de solutions, d'articles.</description>
<language>fr</language>
<generator>SPIP - www.spip.net</generator>
<image>
<title>Root Me : plateforme d'apprentissage d&#233;di&#233;e au Hacking et &#224; la S&#233;curit&#233; de l'Information</title>
<url>https://www.root-me.org/local/cache-vignettes/L144xH144/siteon0-9a1b1.svg?1757799377</url>
<link>https://www.root-me.org/</link>
<height>144</height>
<width>144</width>
</image>
<item xml:lang="fr">
<title>ELF x64 - Advanced blind format string exploitation</title>
<link>https://www.root-me.org/fr/Challenges/App-Systeme/ELF-x64-Advanced-blind-format-string-exploitation</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Systeme/ELF-x64-Advanced-blind-format-string-exploitation</guid>
<dc:date>2024-07-11T09:59:14Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
nobodyisnobody
</dc:creator>
<dc:subject>Tr&#232;s difficile</dc:subject>
<description>
&lt;p&gt;Comme les mauvaises nouvelles, &lt;br class=&#034;autobr&#034; /&gt;
Les challenges de blind format string reviennent r&#233;guli&#232;rement dans les CTFs.&lt;br class=&#034;autobr&#034; /&gt;
Un classique donc..&lt;br class=&#034;autobr&#034; /&gt;
Celui ci est une tentative de renouveler un peu le genre..&lt;br class=&#034;autobr&#034; /&gt;
Avec quelques protections en plus...&lt;/p&gt;
&lt;h5&gt;Configuration de l'environnement&lt;/h5&gt;
&lt;table class=&#034;ts&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;PIE&lt;/td&gt; &lt;td&gt;Position Independent Executable&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;RelRO&lt;/td&gt; &lt;td&gt;Read Only relocations&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;NX&lt;/td&gt; &lt;td&gt;Pile non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;Heap exec&lt;/td&gt; &lt;td&gt;Tas non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;ASLR&lt;/td&gt; &lt;td&gt;Distribution al&#233;atoire de l'espace d'adressage&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SF&lt;/td&gt; &lt;td&gt;Source Fortification&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SRC&lt;/td&gt; &lt;td&gt;Acc&#232;s au code source&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;&lt;h5&gt;Param&#232;tres de connexion au challenge&lt;/h5&gt; &lt;table class=&#034;txs mauto&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;H&#244;te&lt;/td&gt;&lt;td&gt;challenge03.root-me.org&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Protocole&lt;/td&gt;&lt;td&gt;TCP&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Port&lt;/td&gt;&lt;td&gt;0&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;Acc&#232;s SSH&lt;/td&gt; &lt;td&gt; &lt;a href=&#034;ssh://-ch:-ch@challenge03.root-me.org:2223&#034; title=&#034;Acc&#232;s SSH&#034;&gt;ssh -p 2223 -ch@challenge03.root-me.org&lt;/a&gt; &lt;a target=&#034;_blank&#034; href=&#034;http://webssh.root-me.org/?location=WebSSH_&amp;ssh=ssh://-ch:-ch@challenge03&#034; title=&#034;WebSSH&#034;&gt;&lt;img src='https://www.root-me.org/squelettes/img/webssh.png?1454749832' alt='' width='16' height='14' /&gt; WebSSH&lt;/a&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Nom d'utilisateur&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Mot de passe&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;br/&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Systeme/" rel="directory"&gt;App - Syst&#232;me&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>ELF x64 - Heap Hop</title>
<link>https://www.root-me.org/fr/Challenges/App-Systeme/ELF-x64-Heap-Hop</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Systeme/ELF-x64-Heap-Hop</guid>
<dc:date>2024-07-11T09:59:07Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
nobodyisnobody
</dc:creator>
<dc:subject>Tr&#232;s difficile</dc:subject>
<description>
&lt;p&gt;Certaines techniques de heap &#034;House of ...&#034; fonctionnent encore, m&#234;me sur une libc r&#233;cente comme la 2.38.&lt;/p&gt;
&lt;p&gt;N'h&#233;sitez pas &#224; explorer le code source de la libc pour passer les diff&#233;rents checks...&lt;/p&gt;
&lt;h5&gt;Configuration de l'environnement&lt;/h5&gt;
&lt;table class=&#034;ts&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;PIE&lt;/td&gt; &lt;td&gt;Position Independent Executable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;RelRO&lt;/td&gt; &lt;td&gt;Read Only relocations&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;NX&lt;/td&gt; &lt;td&gt;Pile non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;Heap exec&lt;/td&gt; &lt;td&gt;Tas non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;ASLR&lt;/td&gt; &lt;td&gt;Distribution al&#233;atoire de l'espace d'adressage&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SF&lt;/td&gt; &lt;td&gt;Source Fortification&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SRC&lt;/td&gt; &lt;td&gt;Acc&#232;s au code source&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;&lt;h5&gt;Param&#232;tres de connexion au challenge&lt;/h5&gt; &lt;table class=&#034;txs mauto&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;H&#244;te&lt;/td&gt;&lt;td&gt;challenge03.root-me.org&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Protocole&lt;/td&gt;&lt;td&gt;TCP&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Port&lt;/td&gt;&lt;td&gt;0&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;Acc&#232;s SSH&lt;/td&gt; &lt;td&gt; &lt;a href=&#034;ssh://-ch:-ch@challenge03.root-me.org:2223&#034; title=&#034;Acc&#232;s SSH&#034;&gt;ssh -p 2223 -ch@challenge03.root-me.org&lt;/a&gt; &lt;a target=&#034;_blank&#034; href=&#034;http://webssh.root-me.org/?location=WebSSH_&amp;ssh=ssh://-ch:-ch@challenge03&#034; title=&#034;WebSSH&#034;&gt;&lt;img src='https://www.root-me.org/squelettes/img/webssh.png?1454749832' alt='' width='16' height='14' /&gt; WebSSH&lt;/a&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Nom d'utilisateur&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Mot de passe&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;br/&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Systeme/" rel="directory"&gt;App - Syst&#232;me&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>ELF x64 - Syscall chaining</title>
<link>https://www.root-me.org/fr/Challenges/App-Systeme/ELF-x64-Syscall-chaining</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Systeme/ELF-x64-Syscall-chaining</guid>
<dc:date>2024-07-11T09:59:02Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
Njörd
</dc:creator>
<dc:subject>Difficile</dc:subject>
<description>
&lt;p&gt;Votre ami vous a contact&#233; pour que vous l'aidiez &#224; exploiter ce binaire et &#224; lire le flag contenu dans un fichier. Il pense cependant que ce n'est pas possible car un filtre seccomp emp&#234;che d'obtenir un shell et que le programme ne permet pas de cha&#238;ner les appels syst&#232;mes. Prouvez-lui qu'il a tort en r&#233;cup&#233;rant le flag.&lt;/p&gt;
&lt;h5&gt;Configuration de l'environnement&lt;/h5&gt;
&lt;table class=&#034;ts&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;PIE&lt;/td&gt; &lt;td&gt;Position Independent Executable&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;RelRO&lt;/td&gt; &lt;td&gt;Read Only relocations&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;NX&lt;/td&gt; &lt;td&gt;Pile non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;Heap exec&lt;/td&gt; &lt;td&gt;Tas non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;ASLR&lt;/td&gt; &lt;td&gt;Distribution al&#233;atoire de l'espace d'adressage&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SF&lt;/td&gt; &lt;td&gt;Source Fortification&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SRC&lt;/td&gt; &lt;td&gt;Acc&#232;s au code source&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;&lt;h5&gt;Param&#232;tres de connexion au challenge&lt;/h5&gt; &lt;table class=&#034;txs mauto&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;H&#244;te&lt;/td&gt;&lt;td&gt;challenge03.root-me.org&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Protocole&lt;/td&gt;&lt;td&gt;TCP&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Port&lt;/td&gt;&lt;td&gt;0&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;Acc&#232;s SSH&lt;/td&gt; &lt;td&gt; &lt;a href=&#034;ssh://-ch:-ch@challenge03.root-me.org:2223&#034; title=&#034;Acc&#232;s SSH&#034;&gt;ssh -p 2223 -ch@challenge03.root-me.org&lt;/a&gt; &lt;a target=&#034;_blank&#034; href=&#034;http://webssh.root-me.org/?location=WebSSH_&amp;ssh=ssh://-ch:-ch@challenge03&#034; title=&#034;WebSSH&#034;&gt;&lt;img src='https://www.root-me.org/squelettes/img/webssh.png?1454749832' alt='' width='16' height='14' /&gt; WebSSH&lt;/a&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Nom d'utilisateur&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Mot de passe&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;br/&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Systeme/" rel="directory"&gt;App - Syst&#232;me&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>ELF x64 - Stack buffer overflow - Stack pivot</title>
<link>https://www.root-me.org/fr/Challenges/App-Systeme/ELF-x64-Stack-buffer-overflow-Stack-pivot</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Systeme/ELF-x64-Stack-buffer-overflow-Stack-pivot</guid>
<dc:date>2024-07-11T09:58:56Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
spikeroot
</dc:creator>
<dc:subject>Moyen</dc:subject>
<description>
&lt;p&gt;Une ligne d'&#233;coute vient d'&#234;tre mise en place pour venir en aide &#224; tout apprenti hacker qui en ressentirait le besoin. Malheureusement, les op&#233;rateurs ne semblent pas vraiment &#224; l'&#233;coute et la ligne coupe un peu rapidement lorsque l'utilisateur fait part de ses ressentis...&lt;/p&gt;
&lt;p&gt;Lisez le mot de passe de validation dans le fichier .passwd.&lt;/p&gt;
&lt;h5&gt;Configuration de l'environnement&lt;/h5&gt;
&lt;table class=&#034;ts&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;PIE&lt;/td&gt; &lt;td&gt;Position Independent Executable&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;RelRO&lt;/td&gt; &lt;td&gt;Read Only relocations&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;NX&lt;/td&gt; &lt;td&gt;Pile non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;Heap exec&lt;/td&gt; &lt;td&gt;Tas non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;ASLR&lt;/td&gt; &lt;td&gt;Distribution al&#233;atoire de l'espace d'adressage&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SF&lt;/td&gt; &lt;td&gt;Source Fortification&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SRC&lt;/td&gt; &lt;td&gt;Acc&#232;s au code source&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;&lt;h5&gt;Param&#232;tres de connexion au challenge&lt;/h5&gt; &lt;table class=&#034;txs mauto&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;H&#244;te&lt;/td&gt;&lt;td&gt;challenge03.root-me.org&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Protocole&lt;/td&gt;&lt;td&gt;SSH&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Port&lt;/td&gt;&lt;td&gt;2223&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;Acc&#232;s SSH&lt;/td&gt; &lt;td&gt; &lt;a href=&#034;ssh://-ch:-ch@challenge03.root-me.org:2223&#034; title=&#034;Acc&#232;s SSH&#034;&gt;ssh -p 2223 -ch@challenge03.root-me.org&lt;/a&gt; &lt;a target=&#034;_blank&#034; href=&#034;http://webssh.root-me.org/?location=WebSSH_&amp;ssh=ssh://-ch:-ch@challenge03&#034; title=&#034;WebSSH&#034;&gt;&lt;img src='https://www.root-me.org/squelettes/img/webssh.png?1454749832' alt='' width='16' height='14' /&gt; WebSSH&lt;/a&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Nom d'utilisateur&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Mot de passe&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;br/&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Systeme/" rel="directory"&gt;App - Syst&#232;me&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>ELF x64 - Blind SROP</title>
<link>https://www.root-me.org/fr/Challenges/App-Systeme/ELF-x64-Blind-SROP</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Systeme/ELF-x64-Blind-SROP</guid>
<dc:date>2023-12-28T09:58:29Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
s1m
</dc:creator>
<dc:subject>Tr&#232;s difficile</dc:subject>
<description>
&lt;p&gt;Vous n'avez aucune information sur ce binaire. A vous d'en savoir plus et de l'exploiter. R&#233;cup&#233;rez le mot de passe de validation dans le fichier .passwd.&lt;/p&gt;
&lt;h5&gt;Configuration de l'environnement&lt;/h5&gt;
&lt;table class=&#034;ts&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;PIE&lt;/td&gt; &lt;td&gt;Position Independent Executable&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;RelRO&lt;/td&gt; &lt;td&gt;Read Only relocations&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;NX&lt;/td&gt; &lt;td&gt;Pile non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;Heap exec&lt;/td&gt; &lt;td&gt;Tas non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;ASLR&lt;/td&gt; &lt;td&gt;Distribution al&#233;atoire de l'espace d'adressage&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SF&lt;/td&gt; &lt;td&gt;Source Fortification&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;SSP&lt;/td&gt; &lt;td&gt;Stack-Smashing Protection&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SRC&lt;/td&gt; &lt;td&gt;Acc&#232;s au code source&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;&lt;h5&gt;Param&#232;tres de connexion au challenge&lt;/h5&gt; &lt;table class=&#034;txs mauto&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;H&#244;te&lt;/td&gt;&lt;td&gt;challenge03.root-me.org&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Protocole&lt;/td&gt;&lt;td&gt;TCP&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Port&lt;/td&gt;&lt;td&gt;0&lt;/td&gt;&lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;br/&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Systeme/" rel="directory"&gt;App - Syst&#232;me&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>ELF ARM64 - Multithreading</title>
<link>https://www.root-me.org/fr/Challenges/App-Systeme/ELF-ARM64-Multithreading</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Systeme/ELF-ARM64-Multithreading</guid>
<dc:date>2023-02-13T15:00:01Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
franb
</dc:creator>
<dc:subject>Tr&#232;s difficile</dc:subject>
<description>
&lt;h5&gt;Configuration de l'environnement&lt;/h5&gt;
&lt;table class=&#034;ts&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;PIE&lt;/td&gt; &lt;td&gt;Position Independent Executable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;RelRO&lt;/td&gt; &lt;td&gt;Read Only relocations&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;NX&lt;/td&gt; &lt;td&gt;Pile non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;Heap exec&lt;/td&gt; &lt;td&gt;Tas non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;ASLR&lt;/td&gt; &lt;td&gt;Distribution al&#233;atoire de l'espace d'adressage&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SF&lt;/td&gt; &lt;td&gt;Source Fortification&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;SSP&lt;/td&gt; &lt;td&gt;Stack-Smashing Protection&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SRC&lt;/td&gt; &lt;td&gt;Acc&#232;s au code source&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Un serveur utilisant le multi threads plut&#244;t que le fork et donc utilisant les mutex. Encore faut-il penser &#224; tout.&lt;/p&gt;
&lt;h5&gt;Param&#232;tres de connexion au challenge&lt;/h5&gt; &lt;table class=&#034;txs mauto&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;H&#244;te&lt;/td&gt;&lt;td&gt;challenge04.root-me.org&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Protocole&lt;/td&gt;&lt;td&gt;TCP&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Port&lt;/td&gt;&lt;td&gt;0&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;Acc&#232;s SSH&lt;/td&gt; &lt;td&gt; &lt;a href=&#034;ssh://-ch:-ch@challenge04.root-me.org:2224&#034; title=&#034;Acc&#232;s SSH&#034;&gt;ssh -p 2224 -ch@challenge04.root-me.org&lt;/a&gt; &lt;a target=&#034;_blank&#034; href=&#034;http://webssh.root-me.org/?location=WebSSH_&amp;ssh=ssh://-ch:-ch@challenge04&#034; title=&#034;WebSSH&#034;&gt;&lt;img src='https://www.root-me.org/squelettes/img/webssh.png?1454749832' alt='' width='16' height='14' /&gt; WebSSH&lt;/a&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Nom d'utilisateur&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Mot de passe&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;br/&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Systeme/" rel="directory"&gt;App - Syst&#232;me&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>ELF RISC-V - Intro - let's do the ROP</title>
<link>https://www.root-me.org/fr/Challenges/App-Systeme/ELF-RISC-V-Intro-let-s-do-the-ROP</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Systeme/ELF-RISC-V-Intro-let-s-do-the-ROP</guid>
<dc:date>2023-02-13T14:59:55Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
nobodyisnobody
</dc:creator>
<dc:subject>Moyen</dc:subject>
<description>
&lt;h5&gt;Configuration de l'environnement&lt;/h5&gt;
&lt;table class=&#034;ts&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;PIE&lt;/td&gt; &lt;td&gt;Position Independent Executable&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;RelRO&lt;/td&gt; &lt;td&gt;Read Only relocations&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;NX&lt;/td&gt; &lt;td&gt;Pile non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;Heap exec&lt;/td&gt; &lt;td&gt;Tas non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;ASLR&lt;/td&gt; &lt;td&gt;Distribution al&#233;atoire de l'espace d'adressage&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SF&lt;/td&gt; &lt;td&gt;Source Fortification&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;SSP&lt;/td&gt; &lt;td&gt;Stack-Smashing Protection&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SRC&lt;/td&gt; &lt;td&gt;Acc&#232;s au code source&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Une introduction &#224; l'architecture RISC-V.&lt;br class=&#034;autobr&#034; /&gt;
Buffer Overflow Basique&lt;br class=&#034;autobr&#034; /&gt;
Un petit canary est sur votre chemin..Faites attention..&lt;/p&gt;
&lt;h5&gt;Param&#232;tres de connexion au challenge&lt;/h5&gt; &lt;table class=&#034;txs mauto&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;H&#244;te&lt;/td&gt;&lt;td&gt;challenge03.root-me.org&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Protocole&lt;/td&gt;&lt;td&gt;TCP&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Port&lt;/td&gt;&lt;td&gt;0&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;Acc&#232;s SSH&lt;/td&gt; &lt;td&gt; &lt;a href=&#034;ssh://-ch:-ch@challenge03.root-me.org:2223&#034; title=&#034;Acc&#232;s SSH&#034;&gt;ssh -p 2223 -ch@challenge03.root-me.org&lt;/a&gt; &lt;a target=&#034;_blank&#034; href=&#034;http://webssh.root-me.org/?location=WebSSH_&amp;ssh=ssh://-ch:-ch@challenge03&#034; title=&#034;WebSSH&#034;&gt;&lt;img src='https://www.root-me.org/squelettes/img/webssh.png?1454749832' alt='' width='16' height='14' /&gt; WebSSH&lt;/a&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Nom d'utilisateur&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Mot de passe&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;br/&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Systeme/" rel="directory"&gt;App - Syst&#232;me&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>ELF x64 - Basic heap overflow</title>
<link>https://www.root-me.org/fr/Challenges/App-Systeme/ELF-x64-Basic-heap-overflow</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Systeme/ELF-x64-Basic-heap-overflow</guid>
<dc:date>2023-02-13T14:59:48Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
sourcePerrier
</dc:creator>
<dc:subject>Facile</dc:subject>
<description>
&lt;h5&gt;Configuration de l'environnement&lt;/h5&gt;
&lt;table class=&#034;ts&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;PIE&lt;/td&gt; &lt;td&gt;Position Independent Executable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;RelRO&lt;/td&gt; &lt;td&gt;Read Only relocations&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;NX&lt;/td&gt; &lt;td&gt;Pile non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;Heap exec&lt;/td&gt; &lt;td&gt;Tas non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;ASLR&lt;/td&gt; &lt;td&gt;Distribution al&#233;atoire de l'espace d'adressage&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SF&lt;/td&gt; &lt;td&gt;Source Fortification&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;SSP&lt;/td&gt; &lt;td&gt;Stack-Smashing Protection&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SRC&lt;/td&gt; &lt;td&gt;Acc&#232;s au code source&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;h5&gt;Param&#232;tres de connexion au challenge&lt;/h5&gt; &lt;table class=&#034;txs mauto&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;H&#244;te&lt;/td&gt;&lt;td&gt;challenge03.root-me.org&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Protocole&lt;/td&gt;&lt;td&gt;SSH&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Port&lt;/td&gt;&lt;td&gt;2223&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;Acc&#232;s SSH&lt;/td&gt; &lt;td&gt; &lt;a href=&#034;ssh://-ch:-ch@challenge03.root-me.org:2223&#034; title=&#034;Acc&#232;s SSH&#034;&gt;ssh -p 2223 -ch@challenge03.root-me.org&lt;/a&gt; &lt;a target=&#034;_blank&#034; href=&#034;http://webssh.root-me.org/?location=WebSSH_&amp;ssh=ssh://-ch:-ch@challenge03&#034; title=&#034;WebSSH&#034;&gt;&lt;img src='https://www.root-me.org/squelettes/img/webssh.png?1454749832' alt='' width='16' height='14' /&gt; WebSSH&lt;/a&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Nom d'utilisateur&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Mot de passe&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;br/&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Systeme/" rel="directory"&gt;App - Syst&#232;me&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>ELF ARM64 - Heap Underflow</title>
<link>https://www.root-me.org/fr/Challenges/App-Systeme/ELF-ARM64-Heap-Underflow</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Systeme/ELF-ARM64-Heap-Underflow</guid>
<dc:date>2023-02-13T14:58:59Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
nobodyisnobody
</dc:creator>
<dc:subject>Tr&#232;s difficile</dc:subject>
<description>
&lt;h5&gt;Configuration de l'environnement&lt;/h5&gt;
&lt;table class=&#034;ts&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;PIE&lt;/td&gt; &lt;td&gt;Position Independent Executable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;RelRO&lt;/td&gt; &lt;td&gt;Read Only relocations&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;NX&lt;/td&gt; &lt;td&gt;Pile non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;Heap exec&lt;/td&gt; &lt;td&gt;Tas non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;ASLR&lt;/td&gt; &lt;td&gt;Distribution al&#233;atoire de l'espace d'adressage&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SF&lt;/td&gt; &lt;td&gt;Source Fortification&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;SSP&lt;/td&gt; &lt;td&gt;Stack-Smashing Protection&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SRC&lt;/td&gt; &lt;td&gt;Acc&#232;s au code source&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Exploitation d'une vulnerabilit&#233; heap sur plateforme AARCH64.&lt;/p&gt;
&lt;p&gt;Un seccomp interdit execve, il vous faudra donc passer par un ROP..&lt;/p&gt;
&lt;h5&gt;Param&#232;tres de connexion au challenge&lt;/h5&gt; &lt;table class=&#034;txs mauto&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;H&#244;te&lt;/td&gt;&lt;td&gt;challenge04.root-me.org&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Protocole&lt;/td&gt;&lt;td&gt;SSH&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Port&lt;/td&gt;&lt;td&gt;2224&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;Acc&#232;s SSH&lt;/td&gt; &lt;td&gt; &lt;a href=&#034;ssh://-ch:-ch@challenge04.root-me.org:2224&#034; title=&#034;Acc&#232;s SSH&#034;&gt;ssh -p 2224 -ch@challenge04.root-me.org&lt;/a&gt; &lt;a target=&#034;_blank&#034; href=&#034;http://webssh.root-me.org/?location=WebSSH_&amp;ssh=ssh://-ch:-ch@challenge04&#034; title=&#034;WebSSH&#034;&gt;&lt;img src='https://www.root-me.org/squelettes/img/webssh.png?1454749832' alt='' width='16' height='14' /&gt; WebSSH&lt;/a&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Nom d'utilisateur&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Mot de passe&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;br/&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Systeme/" rel="directory"&gt;App - Syst&#232;me&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>ELF x64 - Buggy VM</title>
<link>https://www.root-me.org/fr/Challenges/App-Systeme/ELF-x64-Buggy-VM</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Systeme/ELF-x64-Buggy-VM</guid>
<dc:date>2022-06-10T14:41:35Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
NonStandardModel
</dc:creator>
<dc:subject>Difficile</dc:subject>
<description>
&lt;p&gt;There is a bug in this VM.&#160;Can you exploit it&#160;?&lt;/p&gt;
&lt;h5&gt;Configuration de l'environnement&lt;/h5&gt;
&lt;table class=&#034;ts&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;PIE&lt;/td&gt; &lt;td&gt;Position Independent Executable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;RelRO&lt;/td&gt; &lt;td&gt;Read Only relocations&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;NX&lt;/td&gt; &lt;td&gt;Pile non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;Heap exec&lt;/td&gt; &lt;td&gt;Tas non ex&#233;cutable&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;ASLR&lt;/td&gt; &lt;td&gt;Distribution al&#233;atoire de l'espace d'adressage&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SF&lt;/td&gt; &lt;td&gt;Source Fortification&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;SSP&lt;/td&gt; &lt;td&gt;Stack-Smashing Protection&lt;/td&gt; &lt;td class=&#034;gras rouge&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/valide.svg?1566650190' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;valide.svg?1566650190&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt; &lt;td&gt;SRC&lt;/td&gt; &lt;td&gt;Acc&#232;s au code source&lt;/td&gt; &lt;td class=&#034;gras vert&#034;&gt; &lt;img src='https://www.root-me.org/squelettes/img/pas_valide.svg?1566650180' width=&#034;12&#034; height=&#034;12&#034; alt=&#034;pas_valide.svg?1566650180&#034; /&gt;&#160;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;&lt;h5&gt;Param&#232;tres de connexion au challenge&lt;/h5&gt; &lt;table class=&#034;txs mauto&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;H&#244;te&lt;/td&gt;&lt;td&gt;challenge03.root-me.org&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Protocole&lt;/td&gt;&lt;td&gt;SSH&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Port&lt;/td&gt;&lt;td&gt;2223&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;Acc&#232;s SSH&lt;/td&gt; &lt;td&gt; &lt;a href=&#034;ssh://-ch:-ch@challenge03.root-me.org:2223&#034; title=&#034;Acc&#232;s SSH&#034;&gt;ssh -p 2223 -ch@challenge03.root-me.org&lt;/a&gt; &lt;a target=&#034;_blank&#034; href=&#034;http://webssh.root-me.org/?location=WebSSH_&amp;ssh=ssh://-ch:-ch@challenge03&#034; title=&#034;WebSSH&#034;&gt;&lt;img src='https://www.root-me.org/squelettes/img/webssh.png?1454749832' alt='' width='16' height='14' /&gt; WebSSH&lt;/a&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Nom d'utilisateur&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Mot de passe&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;br/&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Systeme/" rel="directory"&gt;App - Syst&#232;me&lt;/a&gt;
</description>
</item>
</channel>
</rss>
