h0 Compile and Analyze (Tero)
a) Compile a simple program. Analyze the binary.
Once you've submitted your report, cross review two. (As always)
Tips
- Tero & Lari will give tips on the way.
- C and C++ are nice languages for this. On Linux, the compilers are cpp and g++.
- You're allowed to ask AI if you need the help. AI must be cited as the source, with specifics (model, jailbrakes, settings...). You're not allowed to generate prose with AI, as your classmates will have to read what you write.
- Use Markdown to create your report. You can easily publish your report with Github, Gitlab or similar.
- Karvinen 2023: Create a Web Page Using Github
h1 Freedom of Action, Control, and Risk Mitigation (Lari)
The target environment is your own home network and the computer you use to complete the course exercises. In practice, the “organisation” consists of your household and your own IT environment, including devices, router/Wi-Fi, cloud services, lab machines, a possible NAS, and so on.
Objectives
- Define a reasonable ISMS scope for your own environment.
- Identify the different network boundaries and interfaces, and document your IT environment.
- Aim to produce documentation detailed enough to allow your environment to be audited on paper.
Tasks
- a) Basic Level. Define the ISMS scope for your home network and study lab (½–1 page). Describe at least the following:
- a1) What is included in the scope
- Basic home network infrastructure: router, Wi-Fi, possible network shares or NAS, printer, and IoT devices where relevant.
- Devices used for the course exercises: laptop or workstation, possible virtual machines, a lab server such as a Linux VM, and a phone if you use it for MFA.
- Information and data: course materials, personal notes, repositories, lab materials, and possible credentials or cryptographic keys.
- a2) What is excluded from the scope and why
- Examples of exclusions: devices belonging to other family members, smart TVs, game consoles, an employer-managed computer, and the ISP’s network on the internet side of your router.
- Justify the exclusions based on factors such as ownership, manageability, lack of relevance to the course, or risk acceptance.
- a3) Key interfaces and boundaries
- Cloud services, such as GitHub/GitLab, Google Drive/OneDrive, and the institution’s learning management system (LMS).
- Remote connections, such as VPN, SSH, and RDP, as well as the boundary between the home network and the internet, including the router and firewall.
- Suppliers and service providers: internet service provider (ISP), device vendors, and cloud service providers.
- Deliverables
- A scope description of ½–1 page.
- One simple network and interface diagram. Boxes and arrows are sufficient. The diagram must show:
- The “Home Network / Study Lab” area (in scope).
- The “External Environment” (out of scope).
- The interfaces and boundaries, such as internet, cloud services, and remote connections.
- Evidence Addendum
- Write 1–3 lines for each item under the heading: "What evidence could I present?". Examples include a screenshot of the router configuration page, a device inventory, a list of virtual machines, a repository link, and backup configuration settings.
- b) Linking the Assignment to the Standard. Identify at least two interested parties in the context of your home network.
- For each interested party, describe:
- Their need, expectation, or requirement, such as security, privacy, or availability.
- The ISO 27001 requirement area to which it relates: Context, Leadership, Planning, Support, Operation, Performance Evaluation, or Improvement.
- How you would demonstrate that the requirement has been fulfilled (evidence).
- Examples of Interested Parties. Select the parties that are relevant to your environment:
- You – continuity of the course exercises and preservation of your data.
- Family members or housemates – privacy and assurance that the study lab does not disrupt everyday activities.
- Internet service provider – compliance with the service agreement and device usage terms.
- Cloud service providers, such as GitHub, Google, or Microsoft – account security, MFA, and compliance with the terms of service.
- Educational institution or course organiser – academic integrity and assurance that no harmful activities are conducted on the network.
- Employer, if you use the same computer or network – separation of environments and protection of employer information.
- Authorities or regulators, at a general level – lawful use and appropriate processing of personal data.
- Deliverable. Create a table with the following columns:
- Interested Party
- Need or Requirement
- ISO 27001 Reference (Requirement Area)
- How Compliance Is Demonstrated (Evidence)
Tip
- In a home environment, “leadership” can be interpreted as you acting as the owner: you make the decisions, accept the risks, and establish and maintain the rules for your environment.
Translation made by AI (sol 5.4)
h2 Break & Unbreak (Tero)
h3 No Strings Attached (Tero)
h4 Some Disassembly Required (Tero)
h5 Binääri tässä, missä koodit? (Lari)
- main.cpp - käytiin yhdessä tunnilla läpi GDB:n perusasiat.
- Lab0.zip - Harjoitellaan tunnilla itsenäisesti debuggerin käyttöä. Etsitään virhe ja pyritään korjaamaan se
- Lab1.zip - Harjoitellaan tunnilla itsenäisesti. Etsitään, miksi ohjelma kaatuu ja voidaanko se korjata.
- Lab2.zip - kotitehtävä.
Ohjelma on käännetty, mutta koodit ovat päässeet katoamaan. Tehtävänä on löytää ohjelman kysymä uusi salasana ja ohjelman tulostama lippu. Kirjoita dokumentti siitä, miten sait nämä selville. Sekä mitä uutta opit GNU Debuggerista, että mitä et oppinut tunnilla.
- Lab3.zip - Tiedostossa on Nora Crackme -haasteita. Valitse yksi tiedosto ja yritä ratkaista binäärin salasana. Kirjoita tästä dokumentti, miten sait salasanan selville.
- Lab4.zip - Vapaaehtoinen tehtävä. Ratkaise tämän binäärin salasana ja kirjoita siitä dokumentaatio.
Dokumentaation tulee olla sellaisella tasolla, että kuka tahansa kurssilla olevista kykenee toistamaan ratkaisusi.
Tärkeimpänä tehtävänä on oppia käyttämään analyyttista ajattelua ja GNU Debuggeria, joten ethän käytä tehtävän tekemiseen tekoälyä, vaikka sen käyttö helpottaa tehtävien tekemistä merkittävästi. Tällöin oppimisen tavoitteet eivät toteudu.
Päivitetty 2026-08-05
h6 Onkohan tämä turvallinen käyttää? (Lari)
Tutki kotona Tapo C200 -kameran ohjelmiston turvallisuutta ja käytä kaikkia menetelmiä, joita olet oppinut tällä kurssilla analyysin tekemiseen.
Kirjoita tutkimuksestasi raportti, josta selviää, mitä löysit ja miten löysit mahdolliset ongelmat. Onko mahdollista käyttää hyödyksi löytämiäsi haavoittuvuuksia.
Päivitetty 2026-08-05
h7 Happy Hacking Day
h8 Bonus
Optional: Bonus: list and link here your completed
- a) Optional tasks
- b) Substantially improved tasks after grading
- c) Success in application hacking outside the course
- For example, in CTFs related to application hacking
Deadline 24 h before the last meeting, i.e., the same as the previous task.