pwnduino

pwn AVR FCSC 2023 solved on

star star

Description

An AVR board is used in a SCADA access control system. It contains a dedicated firmware that implements computations on a secret stored in the internal memory of the microcontroler: this secret must not leave it. In order to execute these computations, it is necessary to prove an authentication password. The console will be disconnected after 10 seconds of inactivity.

During an audit mission, you are asked to evaluate the security of this system, and to validate that the sensitive secret does not leak. You have been able to access a development server containing a debug binary and its source code. Using this information, you are confident that it is possible to recover the production firmware secret!

Files

Author

rbe

Challenge Instructions

  1. First, download docker-compose.yml:
    curl https://hackropole.fr/challenges/fcsc2023-pwn-pwnduino/docker-compose.public.yml -o docker-compose.yml
  2. Launch the challenge by executing in the same folder:
    docker compose up
  3. Then, in another console, access the challenge with Netcat:
    nc localhost 4000
⚠️ Important: You must solve the challenge by interacting with the Docker container through the exposed network port. Any other way is not considered valid.

In case you encounter problems, please consult the FAQ.

Flag

Share my success on Fediverse, Twitter, Linkedin, Facebook, or via email.

Submit your solution

You can submit your writeup for this challenge. Read the FAQ to learn how to proceed.

You need to be logged in to submit a writeup.

Writeups

I've been looking for a long time and I still can't find the flag!

You can vote for the solutions you prefer by using the on their respective pages.

DateAuthor Language Tags Vote
2023-11-06
numb3rss
🇬🇧
TeamFrance