Zardus
@zardus
Retired DEFCON CTF org. Shellphish Captain Emeritus. ASU Prof. angr hacker. pwn.college sensei. Looking for students/interns!
Hello hackers! I accidentally came into possession of this DEF CON hat. Is this yours? If so, let me know! Let’s get this hat home!
The DEF CON Academy is open! Come in, use our laptops, and LEARN TO HACK with awesome mentors. Swag alert: first 3 new hackers to finish an intro module in Web, Crypto, Network, or Binary hacking will win an exclusive limited edition @pwncollege white belt! See you in Hall 4!
We can use this: for every implementation step that Juvenal's agents carry out, Juvenal spawns several (fresh-context) validation agents that check the work for different properties. Anything missing gets punted back to the implementer, dozens of times if necessary.
Juvenal's plan creation is intense: it'll draft a high level workflow, iteratively refine it, split it into concrete steps, and keep iterating on this until everything makes sense. This can take as long an entire day of *just planning*, then it gets to implementing...
The Port phase does the main heavy lifting of actually porting the library. My "one size fits all" attempts for this all failed in the face of C library uniqueness, and so this uses an extensive planning step that produces and executes complex library-specific porting workflows.
Next, Setup prepares the code for porting. This step includes ensuring that existing test cases use public library APIs when possible (to make them applicable to the rust port), and adding new testcases (both directly exercising the library and doing so through dependent apps).
Anyways, let's port some C libraries to rust! Step 1: Recon retrieves the original source (via Ubuntu's source packages; more on this later) and existing CVEs (to keep track of previous non-memory bugs). Not too complex; just three simple prompts.
Aside from hacking mentors, we also have a series of talks! We'll have two daily "hack with us" sessions with either small presentations or challenge walkthroughs and a mentoring session for those interested in academia, industry, etc. Check out the schedule on HackerTracker!
Hello hackers! DEF CONAcademy is LIVE at DEF CON Singapore! For those who're new to the concept, DEFCON Academy is a first-stage education community. We have laptops, material, and l337 h4X0R mentors standing by to help you learn. Drop by and LEARN TO HACK with us!
The room is FULL for @the_robwaz’s talk about Speculative Execution and micro architectural vulnerabilities at @DEFCON Academy (but I only photographed the man himself)!
The @the_robwaz is setting up for his @DEFCONAcademy talk on Race Conditions at 1pm in room 235! At @DEFCON? Come learn about concurrency errors in software!
Come to @DEFCON Academy to see @TheWyrmSuperior talk about buffer overflows, starting in two minutes!
Need more motivation? We have swag and awards! Come early, and we'll have stickers. Solve enough challenges, and we'll give you a limited-edition challenge coin, a pwn shirt, or, for the true high achievers, a belt to induct you into the martial art of hacking. All at Room 235!
We've spent the intervening year preparing a whole weekend of talks, demos, fascinating material, and dozens of mentors standing by to help you learn through hundreds of hands-on challenges. Check out the schedule (defcon.pwn.college/) and come to Room 235 to learn!
Capture the Flag contests aren't specifically meant to educate: challenges can involve learning, perfecting, or expanding skills, but may or may not help the hacker with that process. This approachability gap between pwncollege and CTF/real security is something we often observe.
We've since pushed into both basic concepts (e.g., how to use Linux pwn.college/linux-lu...) and very cutting-edge techniques (sophisticated exploits, other platforms, etc), pushing toward a "zero to hero" model that aims to fully train top cybersecurity experts.
And AZ CTF comes to a close! Congrats to the winners! And, of course, everyone can now tackle the chals on #pwncollege at: pwn.college/az-ctf-2...
ASU is a "top 11" cybersecurity school and rising fast! We've got amazing faculty (and also myself), great research, and absolutely TOP-NOTCH education (which yields incredible students!). And you know what'll make ASU even more awesome year? YOU!
48 hours later, the @pwncollege V8 Exploitation #QuarterlyQuiz has still not been competed! There's still a chance to nab that 🥇 out from under @ky1ebot's nose! Give it a try at pwn.college/quarterl... !
pwn.college emoji badges follow hackers around all the various scoreboards of the site. For example, check out these decorated hackers making up the scoreboard of our previous Quarterly Quiz, the KylebotFS!
Even the educational material for this QQ is tough... The Kernel Exploitation module that introduces concepts used in the Quarterly Quiz has also yet to be fully solved, with n132 in the lead!
How tough? 44.5 hours in, only two levels are solved, both by @zolutal! Perhaps the world's next kylebot, zolutal pursues pwning research in our lab and in competitions (including pwn2own! twitter.com/thezdi/s...), and might be ignoring the upcoming CCS deadline to win this QQ...