h0 Compile and Analyze (Tero)
a) Compile a simple program. Analyze the binary.
Once you've submitted your report, cross review two. (As always)
Tips
- Tero & Lari will give tips on the way.
- C and C++ are nice languages for this. On Linux, the compilers are cpp and g++.
- You're allowed to ask AI if you need the help. AI must be cited as the source, with specifics (model, jailbrakes, settings...). You're not allowed to generate prose with AI, as your classmates will have to read what you write.
- Use Markdown to create your report. You can easily publish your report with Github, Gitlab or similar.
- Karvinen 2023: Create a Web Page Using Github
h1 Freedom of Action, Control, and Risk Mitigation (Lari)
The target environment is your own home network and the computer you use to complete the course exercises. In practice, the “organisation” consists of your household and your own IT environment, including devices, router/Wi-Fi, cloud services, lab machines, a possible NAS, and so on.
Objectives
- Define a reasonable ISMS scope for your own environment.
- Identify the different network boundaries and interfaces, and document your IT environment.
- Aim to produce documentation detailed enough to allow your environment to be audited on paper.
Tasks
- a) Basic Level. Define the ISMS scope for your home network and study lab (½–1 page). Describe at least the following:
- a1) What is included in the scope
- Basic home network infrastructure: router, Wi-Fi, possible network shares or NAS, printer, and IoT devices where relevant.
- Devices used for the course exercises: laptop or workstation, possible virtual machines, a lab server such as a Linux VM, and a phone if you use it for MFA.
- Information and data: course materials, personal notes, repositories, lab materials, and possible credentials or cryptographic keys.
- a2) What is excluded from the scope and why
- Examples of exclusions: devices belonging to other family members, smart TVs, game consoles, an employer-managed computer, and the ISP’s network on the internet side of your router.
- Justify the exclusions based on factors such as ownership, manageability, lack of relevance to the course, or risk acceptance.
- a3) Key interfaces and boundaries
- Cloud services, such as GitHub/GitLab, Google Drive/OneDrive, and the institution’s learning management system (LMS).
- Remote connections, such as VPN, SSH, and RDP, as well as the boundary between the home network and the internet, including the router and firewall.
- Suppliers and service providers: internet service provider (ISP), device vendors, and cloud service providers.
- Deliverables
- A scope description of ½–1 page.
- One simple network and interface diagram. Boxes and arrows are sufficient. The diagram must show:
- The “Home Network / Study Lab” area (in scope).
- The “External Environment” (out of scope).
- The interfaces and boundaries, such as internet, cloud services, and remote connections.
- Evidence Addendum
- Write 1–3 lines for each item under the heading: "What evidence could I present?". Examples include a screenshot of the router configuration page, a device inventory, a list of virtual machines, a repository link, and backup configuration settings.
- b) Linking the Assignment to the Standard. Identify at least two interested parties in the context of your home network.
- For each interested party, describe:
- Their need, expectation, or requirement, such as security, privacy, or availability.
- The ISO 27001 requirement area to which it relates: Context, Leadership, Planning, Support, Operation, Performance Evaluation, or Improvement.
- How you would demonstrate that the requirement has been fulfilled (evidence).
- Examples of Interested Parties. Select the parties that are relevant to your environment:
- You – continuity of the course exercises and preservation of your data.
- Family members or housemates – privacy and assurance that the study lab does not disrupt everyday activities.
- Internet service provider – compliance with the service agreement and device usage terms.
- Cloud service providers, such as GitHub, Google, or Microsoft – account security, MFA, and compliance with the terms of service.
- Educational institution or course organiser – academic integrity and assurance that no harmful activities are conducted on the network.
- Employer, if you use the same computer or network – separation of environments and protection of employer information.
- Authorities or regulators, at a general level – lawful use and appropriate processing of personal data.
- Deliverable. Create a table with the following columns:
- Interested Party
- Need or Requirement
- ISO 27001 Reference (Requirement Area)
- How Compliance Is Demonstrated (Evidence)
Tip
- In a home environment, “leadership” can be interpreted as you acting as the owner: you make the decisions, accept the risks, and establish and maintain the rules for your environment.
Translation made by AI (sol 5.4)
h2 Break & Unbreak (Tero)
Now we hack! And code!
You'll learn to find and fix vulnerabilities.
Remember systematic working methods and report as you go. Also reflect: Where could this vulnerability be common? How could this mistake be avoided? What did I learn from this?
Tips
- OWASP 10 is probably the most well-known document about web vulnerabilities
- PortSwigger Academy's articles and labs are excellent material about web hacking.
- Reporting is part of systematic working methods. A way to solve challenging computer problems.
- The client isn't sitting behind you cheering when you hack. In return for payment, the client usually wants a report.
- Did you cite the course, homework, documents, and all other sources?
- Which information came from which source?
- See the optional introductory exercises if needed. When you solve them first, the harder tasks become easier.
- Create a Portswigger Academy account if needed.
- Small hints and near-spoilers.
- If hacking progresses, good. If you think of different approaches, keep going.
- The newest version of the targets has a small improvement to 010-staff-only. But solving the version shown in class works too.
- Stuck? No idea?
- Do the introductory exercises
- Look at the hints; that's why they exist
- Useful: Think of different approaches. Write them down. Summarize what you already know. Do introductory exercises.
- Useless: It's useless to stare at a web form for over 30 min if you can't think of approaches to try at your current skill level. In that case, hints help.
- And we'll look at more together in class.
h3 No Strings Attached (Tero)
Did you know you can get information from binaries before running them? Here we step into next week's world of static analysis.
The uncrowned king of static analysis, 'strings', greets us!
- a) Strings. Download ezbin-challenges.zip. Run 'passtr'. Find the correct password using 'strings'. Also find the flag. (Preferably without looking at the source, if you can.)
- b) Make a new version of the passtr.c program where the password doesn't appear directly as-is in the binary. Demonstrate with a test that the password doesn't appear. (Obfuscation is sufficient.)
- c) Packd. Run 'packd' from the package ezbin-challenges.zip. What is the password? What is the flag? (This task is slightly more challenging. Write down the approaches you tried and hypotheses you came up with. Hopefully you'll reach the goal yourself, but if not, the walkthrough will be revealed in class...)
- d) Optional bonus: Cryptopals. Crypto Challenge Set 1. This can be done as a bonus over several weeks. If you solve items 1 .. "4. Detect single-character XOR", you've already stepped into the world of cryptography.
Tips
- Use the 'strings' program
- Is C unfamiliar? Try yourself first and look for hints online. If it doesn't resolve otherwise, you can ask AIs. Remember to cite sources.
- Cryptopals
- Base64 is needed only for practical reasons. You can use a ready-made language or library implementation.
Additional tips, packd
Packd, minor spoilers. The task is fun even if you look at these. (click to show)
- Look at the beginning of the binary
- The task name gives a hint; could the binary be packed (binary packer)?
- Could it be some common tool (most common binary packers)?
- The flag doesn't end with the character '8'.
Big hints, packd
Spoilers for the packd task. Still not a walkthrough. (click to show)
$ strings foo|head
$ strings -n 20 packd
h4 Some Disassembly Required (Tero)
- x) Read/watch/listen and summarize. (In this x-subsection, you don't need to do tests on a computer; just reading or listening and a summary is enough. A few bullet points are sufficient for the summary.)
- a) Install Ghidra.
- b) rever-C. Reverse engineer the packd binary to C language with Ghidra. Find the main program. Give variables descriptive names. Explain the program's operation. Solve the task from the binary, without the original source code. ezbin-challenges.zip
- c) If backwards. Modify the passtr program's binary (without the original source code) so that it accepts all passwords except the correct one. Demonstrate with tests that the program works. ezbin-challenges.zip
- d) Nora CrackMe: Compile to binaries Tindall 2023: NoraCodes / crackmes. Read README.md: don't look at the source code unless you need training wheels. In these tasks, binaries are reverse engineered. Binaries are not modified, because otherwise the solution to every task would be to change the return value to "return 0".
- e) Nora crackme01. Solve the binary.
- e) Nora crackme01e. Solve the binary.
- f) Nora crackme02. Name the main program's variables from the reverse-engineered binary and explain the program's operation. Solve the binary.
- g) Optional: And beyond. Crackme01 has multiple solutions. How many can you find? Why?
- h) Optional: Unsolicited. Crackme02 has two solutions. Can you find both?
- i) Optional, slightly more challenging: A ray. Nora crackme02e. Solve the binary.
Want even harder challenges? You can solve more NoraCodes/crackmes challenges if you wish and your skills allow.
Tips
- Ghidra installation
- Kali:
- 'sudo apt-get install ghidra'
- Debian 12-Bookworm (from memory)
- 'sudo apt-get install openjdk-17-jdk
- Get the Ghidra version that works with this Java 17 version. I think Ghidra 11.1.2. It's actually quite new.
- Github: NationalSecurityAgency / Ghidra: Releases: 11.1.2: Assets: ghidra_11.1.2_PUBLIC_20240709.zip (about 400 MB)
- Packd reverse engineering
- Did you remember to unpack the packing?
- Training wheels as an adult?
- The only purpose of the tasks is to learn this thing.
- At work, you'll have to solve tasks yourself.
- Basics are learned with simple programs. These skills are applied to more complex programs over time.
- If all ideas and approaches are exhausted, then a model solution (or AI's direct answer) is better than nothing. It's always worth trying the task through even with instructions, so you'll know for the next one.
- Don't delegate learning to AI.
- Current AIs can solve easy tasks. But that's not very useful at work. The course tasks are easy because we're just learning. Skills must later be applied at a level that current AIs can't handle.
- Return value from a command in Bash
- 'echo Tero; echo $?' prints "Tero\n0", where 0 is the return value.
- Zero means everything went well. Other numbers are errors.
- If you end up registering for PicoCTF for fun, you can leave strange questions unanswered (such as those about ethnic group). Such questions are quite foreign to Finns but unfortunately common at least in British universities.
h5 Binääri tässä, missä koodit? (Lari)
- main.cpp - käytiin yhdessä tunnilla läpi GDB:n perusasiat.
- Lab0.zip - Harjoitellaan tunnilla itsenäisesti debuggerin käyttöä. Etsitään virhe ja pyritään korjaamaan se
- Lab1.zip - Harjoitellaan tunnilla itsenäisesti. Etsitään, miksi ohjelma kaatuu ja voidaanko se korjata.
- Lab2.zip - kotitehtävä.
Ohjelma on käännetty, mutta koodit ovat päässeet katoamaan. Tehtävänä on löytää ohjelman kysymä uusi salasana ja ohjelman tulostama lippu. Kirjoita dokumentti siitä, miten sait nämä selville. Sekä mitä uutta opit GNU Debuggerista, että mitä et oppinut tunnilla.
- Lab3.zip - Tiedostossa on Nora Crackme -haasteita. Valitse yksi tiedosto ja yritä ratkaista binäärin salasana. Kirjoita tästä dokumentti, miten sait salasanan selville.
- Lab4.zip - Vapaaehtoinen tehtävä. Ratkaise tämän binäärin salasana ja kirjoita siitä dokumentaatio.
Dokumentaation tulee olla sellaisella tasolla, että kuka tahansa kurssilla olevista kykenee toistamaan ratkaisusi.
Tärkeimpänä tehtävänä on oppia käyttämään analyyttista ajattelua ja GNU Debuggeria, joten ethän käytä tehtävän tekemiseen tekoälyä, vaikka sen käyttö helpottaa tehtävien tekemistä merkittävästi. Tällöin oppimisen tavoitteet eivät toteudu.
Päivitetty 2026-08-05
h6 Onkohan tämä turvallinen käyttää? (Lari)
Tutki kotona Tapo C200 -kameran ohjelmiston turvallisuutta ja käytä kaikkia menetelmiä, joita olet oppinut tällä kurssilla analyysin tekemiseen.
Kirjoita tutkimuksestasi raportti, josta selviää, mitä löysit ja miten löysit mahdolliset ongelmat. Onko mahdollista käyttää hyödyksi löytämiäsi haavoittuvuuksia.
Päivitetty 2026-08-05
h7 Happy Hacking Day
h8 Bonus
Optional: Bonus: list and link here your completed
- a) Optional tasks
- b) Substantially improved tasks after grading
- c) Success in application hacking outside the course
- For example, in CTFs related to application hacking
Deadline 24 h before the last meeting, i.e., the same as the previous task.