App - Système

Cette série d’épreuve vous confronte aux vulnérabilités applicatives principalement liées aux erreurs de programmation aboutissant à des corruptions de zones mémoire.

Les identifiants de connexion sont fournis pour les différents challenges. Le but est d’obtenir des droits supplémentaires en exploitant des faiblesses de programmes et ainsi obtenir un mot de passe permettant de valider chaque épreuve sur le portail.

Prérequis :
- Maitriser un débogueur, par exemple GDB ;
- Avoir des bases en langage assembleur (notamment x86) ;
- Connaitre le langage C.

 75 Challenges

Résultats Nom Validations Nombre de points  Explications sur les scores Difficulté  Difficulté Auteur Note  Notation Solution
pas_valide LinKern MIPSel - Vulnerable ioctl 1% 36 100 pickle 1
pas_valide LinKern x86 - Null pointer dereference 1% 373 90 franb 1
pas_valide LinKern x64 - code réentrant 1% 130 100 franb 1
pas_valide ELF ARM - Use After Free 1% 82 110 pickle 1
pas_valide LinKern x64 - SLUB off-by-one 1% 36 115 Tosh 1
pas_valide LinKern ARM - Stack Overflow 1% 48 110 pickle 1
pas_valide LinKern x64 - Race condition 1% 234 95 franb 1
pas_valide WinKern x64 - Use After Free 1% 10 120 __syscall, Synacktiv 1
pas_valide ELF ARM - Heap Overflow 1% 38 120 pickle 2
pas_valide WinKern x64 - Stack buffer overflow avancé - ROP 1% 18 120 __syscall, Synacktiv 2
pas_valide ELF ARM - Heap buffer overflow - Wilderness 1% 30 120 pickle 2
pas_valide PE32+ Format string bug 1% 61 45 Ech0 2
pas_valide ELF x64 - Blind ROP 1% 73 135 franb 2
pas_valide ELF ARM - Heap format string bug 1% 65 105 franb 2
pas_valide ELF ARM - Heap Off-by-One 1% 49 115 pickle 2
pas_valide PE32+ Basic ROP 1% 33 75 Ech0 2
pas_valide ELF ARM - Format String bug 1% 76 110 pickle 2
pas_valide ELF x86 - Use After Free - basic 1% 1058 25 Esad 2
pas_valide ELF x86 - Information leakage with Stack Smashing Protector 1% 717 60 Arod 3
pas_valide ELF x64 - Browser exploit - Intro 1% 64 70 pickle 3
pas_valide ELF MIPS - URLEncoded Format String bug 1% 21 100 pickle 3
pas_valide ELF x64 - Remote heap buffer overflow - fastbin 1% 229 80 franb 3
pas_valide ELF ARM - Shellcode alphanumérique 1% 35 100 pickle 3
pas_valide ELF MIPS - Format String Glitch 1% 44 60 pickle, martin 3
pas_valide ELF x64 - Off-by-one bug 1% 114 110 NeedToLearn 3
pas_valide ELF x64 - Heap feng-shui 1% 56 110 laxa 3
pas_valide ELF x86 - Stack buffer overflow - ret2dl_resolve 1% 169 50 kikko 3
pas_valide ELF x64 - Remote Heap buffer overflow 2 1% 105 130 Tosh, Fritz 3
pas_valide ELF x64 - Seccomp Whitelist 1% 47 120 pickle 3
pas_valide LinKern x64 - RowHammer 1% 53 115 pickle 3
pas_valide ELF x64 - Remote Heap buffer overflow 1 1% 139 115 Tosh 3
pas_valide ELF MIPS - Basic ROP 1% 100 40 dagger 3
pas_valide ELF MIPS - Stack buffer overflow - No NX 1% 332 25 franb 4
pas_valide ELF x86 - Remote stack buffer overflow - Hardened 1% 124 115 franb 4
pas_valide ELF ARM - Basic ROP 1% 532 40 pickle 4
pas_valide ELF x86 - Remote BSS buffer overflow 1% 689 75 Tosh 4
pas_valide ELF x86 - Out of bounds attack - French Paradox 1% 92 70 sbrk 4
pas_valide ELF ARM - Race condition 1% 108 70 pickle 4
pas_valide ELF x86 - Bug Hunting - Plusieurs problèmes 1% 80 50 sbrk 4
pas_valide ELF x86 - Stack buffer and integer overflow 1% 1646 50 Lu33Y 4
pas_valide LinKern ARM - syscall vulnérable 1% 111 85 pickle 4
pas_valide LinKern x86 - basic ROP 1% 191 110 franb 5
pas_valide ELF x86 - Hardened binary 3 1% 303 100 sm0k 5
pas_valide ELF x64 - Browser exploit - BitString 1% 27 135 pickle 5
pas_valide ELF x86 - Stack buffer overflow basic 3 2% 3658 25 Lyes 5
pas_valide LinKern x86 - Buffer overflow basic 1 1% 374 85 franb 5
pas_valide ELF x86 - Remote Format String bug 1% 848 75 Tosh 5
pas_valide ELF ARM - Stack Spraying 1% 187 30 pickle 5
pas_valide ELF x86 - Stack buffer overflow basic 5 1% 1503 50 Lu33Y 5
pas_valide ELF x64 - Logic bug 1% 150 50 sbrk 5
pas_valide PE32 - Stack buffer overflow avancé 1% 133 35 Ech0 5
pas_valide ELF x86 - Stack buffer overflow basic 4 2% 2290 30 Lu33Y 5
pas_valide ELF x86 - Blind ROP 1% 103 120 franb 6
pas_valide ELF ARM - Stack buffer overflow - basic 1% 1046 25 pickle 6
pas_valide ELF x86 - Blind remote format string bug 1% 257 80 Lyes 6
pas_valide Linkern x64 - Memory exploration 1% 84 120 franb 6
pas_valide ELF x86 - Hardened binary 7 1% 203 115 Tosh 7
pas_valide ELF x86 - Format string bug basic 2 2% 3661 20 Lyes 7
pas_valide ELF x86 - BSS buffer overflow 2% 3481 30 Lu33Y 7
pas_valide ELF x86 - Stack buffer overflow basic 6 2% 2137 30 TiWim 7
pas_valide ELF x86 - Format string bug basic 1 4% 7303 15 Lu33Y 7
pas_valide ELF x64 - Sigreturn Oriented Programming 1% 207 105 Arod 7
pas_valide ELF x86 - Stack buffer overflow basic 2 6% 11263 10 Lyes 7
pas_valide PE32 - Stack buffer overflow basic 1% 795 10 Ech0 7
pas_valide ELF x86 - Stack buffer overflow - C++ vtables 1% 681 40 sebbb 7
pas_valide ELF x86 - Hardened binary 6 1% 240 115 sm0k 8
pas_valide ELF x86 - Hardened binary 1 1% 616 100 sm0k 8
pas_valide ELF x86 - Format String Bug Basic 3 1% 964 35 Lyes 8
pas_valide ELF x64 - Stack buffer overflow - basic 3% 5570 20 Arod 9
pas_valide ELF x86 - Hardened binary 2 1% 490 100 sm0k 9
pas_valide ELF x86 - Hardened binary 5 1% 260 110 sm0k 9
pas_valide ELF x86 - Stack buffer overflow basic 1 8% 15757 5 Lyes 9
pas_valide ELF x64 - Stack buffer overflow - avancé 1% 999 55 Arod 10
pas_valide ELF x86 - Hardened binary 4 1% 340 100 sm0k 10
pas_valide ELF x86 - Race condition 3% 4960 20 Lu33Y 11