diff --git a/0x0001b_ctf/CTF-01-I.pdf b/0x0001b_ctf/CTF-01-I.pdf index faf4a09..f8c9a54 100644 Binary files a/0x0001b_ctf/CTF-01-I.pdf and b/0x0001b_ctf/CTF-01-I.pdf differ diff --git a/0x0001b_ctf/CTF-01-R.md b/0x0001b_ctf/CTF-01-R.md index 6223c60..9dbec48 100644 --- a/0x0001b_ctf/CTF-01-R.md +++ b/0x0001b_ctf/CTF-01-R.md @@ -90,8 +90,8 @@ UART settings: **115200 baud, 8 data bits, no parity, 1 stop bit**. The instructor-issued artifact hashes are: ```text -CTF-01.bin 6FD296F7A85F243FB26BF6BFFCBEAB26815FD8915101A81F72069063A5635E5A -CTF-01.uf2 980F04369C23AD32A063DFE18DE5AF08DF3830138FC7E7898B1F011B4F5E1D9D +CTF-01.bin 425591AC17FF4C22206286EE6F40B06A89523483804850A41854A9B6F89D7B70 +CTF-01.uf2 B1552EE3BB5763D96C65D8DF1C86984EE842EF1A823FDF5D94132B1E10FF9D16 ``` --- @@ -102,7 +102,7 @@ CTF-01.uf2 980F04369C23AD32A063DFE18DE5AF08DF3830138FC7E7898B1F011B4F5E1D9D | Criterion | Points | Full credit | Partial credit | No credit | |-----------|--------|-------------|----------------|-----------| -| Criterion 1.1: Ghidra Project Setup | 3 | Correct project name, `ARM Cortex 32-bit little endian`, base `0x10000000` | One item off | Not set up | +| Criterion 1.1: Ghidra Project Setup | 3 | Correct project name, `ARM:LE:32:Cortex` (ARM Cortex 32-bit little endian), base `0x10000000` | One item off | Not set up | | Criterion 1.2: main() and Status-Loop Addresses | 4 | Both addresses correct | One correct | Neither found | | Criterion 1.3: Vector Table Decoding | 4 | Correct base, initial SP, reset pointer | One missing | Not found | | Criterion 1.4: Thumb Addressing | 4 | Correctly clears bit 0 and identifies `main()` | General explanation | Incorrect | diff --git a/0x0001b_ctf/CTF-01-R.pdf b/0x0001b_ctf/CTF-01-R.pdf index 9d49ecf..be777b4 100644 Binary files a/0x0001b_ctf/CTF-01-R.pdf and b/0x0001b_ctf/CTF-01-R.pdf differ diff --git a/0x0001b_ctf/CTF-01-S.md b/0x0001b_ctf/CTF-01-S.md index 1fbdef8..6d19d05 100644 --- a/0x0001b_ctf/CTF-01-S.md +++ b/0x0001b_ctf/CTF-01-S.md @@ -34,8 +34,8 @@ | Console | UART0, GPIO 0 TX / GPIO 1 RX, 115200 8N1 | ```text -CTF-01.bin 6FD296F7A85F243FB26BF6BFFCBEAB26815FD8915101A81F72069063A5635E5A -CTF-01.uf2 980F04369C23AD32A063DFE18DE5AF08DF3830138FC7E7898B1F011B4F5E1D9D +CTF-01.bin 425591AC17FF4C22206286EE6F40B06A89523483804850A41854A9B6F89D7B70 +CTF-01.uf2 B1552EE3BB5763D96C65D8DF1C86984EE842EF1A823FDF5D94132B1E10FF9D16 ``` Proof tool: `python3 scripts/verify_ctf.py` returns `11/11 checks passed` against @@ -87,7 +87,7 @@ mode. Clearing bit 0 (`0x1000015B & ~1`) gives the real instruction address | Criterion | Points | Full Credit (Answer Key) | Partial Credit | No Credit | |-----------|--------|--------------------------|----------------|-----------| -| Criterion 1.1: Ghidra Project Setup | 3 | Correct project name, `ARM Cortex 32-bit little endian`, base `0x10000000` | One item off | Not set up | +| Criterion 1.1: Ghidra Project Setup | 3 | Correct project name, `ARM:LE:32:Cortex` (ARM Cortex 32-bit little endian), base `0x10000000` | One item off | Not set up | | Criterion 1.2: main() and Status-Loop Addresses | 4 | Both addresses correct | One correct | Neither found | | Criterion 1.3: Vector Table Decoding | 4 | Correct base, initial SP, reset pointer | One missing | Not found | | Criterion 1.4: Thumb Addressing | 4 | Correctly clears bit 0 and identifies `main()` | General explanation | Incorrect | diff --git a/0x0001b_ctf/CTF-01-S.pdf b/0x0001b_ctf/CTF-01-S.pdf index 3536342..7d7e907 100644 Binary files a/0x0001b_ctf/CTF-01-S.pdf and b/0x0001b_ctf/CTF-01-S.pdf differ diff --git a/0x0001b_ctf/CTF-01.bin b/0x0001b_ctf/CTF-01.bin index 9e61bbb..2a1de88 100644 Binary files a/0x0001b_ctf/CTF-01.bin and b/0x0001b_ctf/CTF-01.bin differ diff --git a/0x0001b_ctf/CTF-01.uf2 b/0x0001b_ctf/CTF-01.uf2 index 040b05e..e0313c1 100644 Binary files a/0x0001b_ctf/CTF-01.uf2 and b/0x0001b_ctf/CTF-01.uf2 differ diff --git a/0x0001b_ctf/CTF-01_fixed.bin b/0x0001b_ctf/CTF-01_fixed.bin index cecaec1..a9d582c 100644 Binary files a/0x0001b_ctf/CTF-01_fixed.bin and b/0x0001b_ctf/CTF-01_fixed.bin differ diff --git a/0x0001b_ctf/CTF-01_fixed.uf2 b/0x0001b_ctf/CTF-01_fixed.uf2 index 220b2ca..7384d9a 100644 Binary files a/0x0001b_ctf/CTF-01_fixed.uf2 and b/0x0001b_ctf/CTF-01_fixed.uf2 differ diff --git a/0x0001b_ctf/include/console.h b/0x0001b_ctf/include/console.h index ec78554..b5a6502 100644 --- a/0x0001b_ctf/include/console.h +++ b/0x0001b_ctf/include/console.h @@ -31,6 +31,9 @@ #ifndef CONSOLE_H #define CONSOLE_H +#include "grid.h" +#include + /** * @brief Print the response controller's boot identity and unconditional signal line. * @@ -40,7 +43,14 @@ * @param None. * @return None. */ -void print_boot_banner(void); +static inline void print_boot_banner(void) +{ + printf("GLOBAL EMBEDDED RESPONSE NETWORK\r\n"); + printf("BLACK START WINDOW: 27 MINUTES\r\n"); + printf("UART0 115200 8N1 | AUTHORIZED LAB CONSOLE\r\n"); + printf("SIGNAL: NORMAL\r\n"); + printf("RESPONSE> "); +} /** * @brief Print the recurring grid classification and dispatch authorization report. @@ -51,6 +61,12 @@ void print_boot_banner(void); * @param None. * @return None. */ -void print_status(void); +static inline void print_status(void) +{ + printf("GRID STATUS: %s\r\n", operator_state ? "STABLE" : "CRITICAL"); + printf("DISPATCH PATH: %s\r\n", dispatch_state ? "AUTHORIZED" : "HELD"); + printf("LAST FRAME: QUARANTINED\r\n"); + printf("RESPONSE> "); +} #endif // CONSOLE_H diff --git a/0x0001b_ctf/include/grid.h b/0x0001b_ctf/include/grid.h index ab1ffee..c1444c8 100644 --- a/0x0001b_ctf/include/grid.h +++ b/0x0001b_ctf/include/grid.h @@ -46,6 +46,22 @@ extern volatile uint32_t operator_state; // Automated dispatch authorization decision (drives DISPATCH PATH). extern volatile uint32_t dispatch_state; +// Quarantined black-start authorization frame, retained in flash, never sent. +static volatile const char dispatch_frame[] = + "WORLDGRID:BLACKSTART:GRID-7:WATER-3"; + +static inline void retain_dispatch_frame(void) +{ + volatile char frame_marker = dispatch_frame[0]; + (void)frame_marker; +} + +static inline void evaluate_grid(void) +{ + operator_state = (grid_deviation < SAFE_THRESHOLD) ? 1 : 0; + dispatch_state = (grid_deviation < SAFE_THRESHOLD) ? 1 : 0; +} + /** * @brief Anchor the hidden dispatch frame in flash without transmitting it. * @@ -56,8 +72,6 @@ extern volatile uint32_t dispatch_state; * @param None. * @return None. */ -void retain_dispatch_frame(void); - /** * @brief Classify the frozen telemetry reading against the compiled threshold. * @@ -68,6 +82,4 @@ void retain_dispatch_frame(void); * @param None. * @return None. */ -void evaluate_grid(void); - #endif // GRID_H diff --git a/0x0001b_ctf/scripts/verify_ctf.py b/0x0001b_ctf/scripts/verify_ctf.py index f542dd4..357eff9 100644 --- a/0x0001b_ctf/scripts/verify_ctf.py +++ b/0x0001b_ctf/scripts/verify_ctf.py @@ -14,8 +14,8 @@ ROOT = Path(__file__).resolve().parent.parent BIN = ROOT / "CTF-01.bin" UF2 = ROOT / "CTF-01.uf2" -EXPECTED_BIN_SHA = "6fd296f7a85f243fb26bf6bffcbeab26815fd8915101a81f72069063a5635e5a" -EXPECTED_UF2_SHA = "980f04369c23ad32a063dfe18de5af08df3830138fc7e7898b1f011b4f5e1d9d" +EXPECTED_BIN_SHA = "425591ac17ff4c22206286ee6f40b06a89523483804850a41854a9b6f89d7b70" +EXPECTED_UF2_SHA = "b1552ee3bb5763d96c65d8df1c86984ee842ef1a823fdf5d94132b1e10ff9d16" CMP_A = 0x100001FC CMP_B = 0x1000020A diff --git a/0x0001b_ctf/src/console.c b/0x0001b_ctf/src/console.c index be37f9b..0b0edd0 100644 --- a/0x0001b_ctf/src/console.c +++ b/0x0001b_ctf/src/console.c @@ -1,50 +1 @@ -// MIT License -// -// Copyright (c) 2026 Kevin Thomas -// -// Permission is hereby granted, free of charge, to any person obtaining a copy -// of this software and associated documentation files (the "Software"), to deal -// in the Software without restriction, including without limitation the rights -// to use, copy, modify, merge, publish, distribute, sublicense, and/or sell -// copies of the Software, and to permit persons to whom the Software is -// furnished to do so, subject to the following conditions: -// -// The above copyright notice and this permission notice shall be included in all -// copies or substantial portions of the Software. -// -// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR -// IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, -// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE -// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER -// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, -// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE -// SOFTWARE. -// -// Author: Kevin Thomas -// Email: kevin@mytechnotalent.com -// GitHub: https://github.com/mytechnotalent -// File: console.c -// Desc: Implements the UART console banner and status reporting logic for -// Operation Black Start. -// Created: 2026 - #include "console.h" -#include "grid.h" -#include - -void print_boot_banner(void) -{ - printf("GLOBAL EMBEDDED RESPONSE NETWORK\r\n"); - printf("BLACK START WINDOW: 27 MINUTES\r\n"); - printf("UART0 115200 8N1 | AUTHORIZED LAB CONSOLE\r\n"); - printf("SIGNAL: NORMAL\r\n"); - printf("RESPONSE> "); -} - -void print_status(void) -{ - printf("GRID STATUS: %s\r\n", operator_state ? "STABLE" : "CRITICAL"); - printf("DISPATCH PATH: %s\r\n", dispatch_state ? "AUTHORIZED" : "HELD"); - printf("LAST FRAME: QUARANTINED\r\n"); - printf("RESPONSE> "); -} diff --git a/0x0001b_ctf/src/grid.c b/0x0001b_ctf/src/grid.c index 37ded64..33786d6 100644 --- a/0x0001b_ctf/src/grid.c +++ b/0x0001b_ctf/src/grid.c @@ -1,57 +1,6 @@ -// MIT License -// -// Copyright (c) 2026 Kevin Thomas -// -// Permission is hereby granted, free of charge, to any person obtaining a copy -// of this software and associated documentation files (the "Software"), to deal -// in the Software without restriction, including without limitation the rights -// to use, copy, modify, merge, publish, distribute, sublicense, and/or sell -// copies of the Software, and to permit persons to whom the Software is -// furnished to do so, subject to the following conditions: -// -// The above copyright notice and this permission notice shall be included in all -// copies or substantial portions of the Software. -// -// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR -// IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, -// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE -// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER -// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, -// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE -// SOFTWARE. -// -// Author: Kevin Thomas -// Email: kevin@mytechnotalent.com -// GitHub: https://github.com/mytechnotalent -// File: grid.c -// Desc: Implements the grid telemetry and safety evaluation logic for -// Operation Black Start. -// Created: 2026 - #include "grid.h" #include -// Frozen grid frequency deviation reading latched when comms were severed. volatile uint32_t grid_deviation = 87; - -// Operator-facing classification of the frozen reading (drives GRID STATUS). volatile uint32_t operator_state = 0; - -// Automated dispatch authorization decision (drives DISPATCH PATH). volatile uint32_t dispatch_state = 0; - -// Quarantined black-start authorization frame, retained in flash, never sent. -static volatile const char dispatch_frame[] = - "WORLDGRID:BLACKSTART:GRID-7:WATER-3"; - -void retain_dispatch_frame(void) -{ - volatile char frame_marker = dispatch_frame[0]; - (void)frame_marker; -} - -void evaluate_grid(void) -{ - operator_state = (grid_deviation < SAFE_THRESHOLD) ? 1 : 0; - dispatch_state = (grid_deviation < SAFE_THRESHOLD) ? 1 : 0; -} diff --git a/0x0011a_cb/0x0011a_cb.uf2 b/0x0011a_cb/0x0011a_cb.uf2 index 2ef2376..e356615 100644 Binary files a/0x0011a_cb/0x0011a_cb.uf2 and b/0x0011a_cb/0x0011a_cb.uf2 differ diff --git a/0x0011a_cb/GHIDRA_REVERSING_TUTORIAL.md b/0x0011a_cb/GHIDRA_REVERSING_TUTORIAL.md index 8277213..9f11d68 100644 --- a/0x0011a_cb/GHIDRA_REVERSING_TUTORIAL.md +++ b/0x0011a_cb/GHIDRA_REVERSING_TUTORIAL.md @@ -358,6 +358,12 @@ python3 scripts/float_hex_converter.py 0xC0535CD1633482BF # -77.450280 `struct.unpack(" **Crypto boundary (design note).** The target is a single 16-byte AES-128-ECB block +> under a hardcoded ASCII key. That is intentionally minimal and weak: ECB mode, one +> block, and the key sitting in the image, so anyone holding the `.bin` can decrypt +> it. It is chosen to make the offline decrypt fit a lesson, not as a model of sound +> cryptography. Treat it as a puzzle, not a recipe. + And the plaintext pair at `0x1000A090` / `0x1000A098` (`+38.840280` / `-77.428890`)? That is the **decoy**, the beacon's broadcast, and it is a lie. The real target only exists after the AES. diff --git a/0x0011a_cb/GHIDRA_REVERSING_TUTORIAL.pdf b/0x0011a_cb/GHIDRA_REVERSING_TUTORIAL.pdf index e911521..43acbae 100644 Binary files a/0x0011a_cb/GHIDRA_REVERSING_TUTORIAL.pdf and b/0x0011a_cb/GHIDRA_REVERSING_TUTORIAL.pdf differ diff --git a/0x0017a_ctf/CTF-02-I.md b/0x0017a_ctf/CTF-02-I.md index 62e7555..37de55e 100644 --- a/0x0017a_ctf/CTF-02-I.md +++ b/0x0017a_ctf/CTF-02-I.md @@ -142,7 +142,7 @@ for the field relays because it was the strongest gate anyone had ever shipped that would still boot on the target. A decade of asking "what if it must not be broken?" is the only reason the relay console can be an authoritative gate at all. Tonight, in a tunnel with rescue crews -approaching a block the firmware is lying about, that wall of encryption +approaching a block the firmware is lying about, that authenticated gate matters more than DEEPLINE's own design review ever did. ### The Disaster diff --git a/0x0017a_ctf/CTF-02-I.pdf b/0x0017a_ctf/CTF-02-I.pdf index 281b7dd..9775ab0 100644 Binary files a/0x0017a_ctf/CTF-02-I.pdf and b/0x0017a_ctf/CTF-02-I.pdf differ diff --git a/0x0017a_ctf/CTF-02-R.md b/0x0017a_ctf/CTF-02-R.md index a581874..c8d392a 100644 --- a/0x0017a_ctf/CTF-02-R.md +++ b/0x0017a_ctf/CTF-02-R.md @@ -112,7 +112,7 @@ CTF-02.uf2 F3CD4840260DB820D792758CECACC5297BEF1971B9EACF7601279256D8AF1EAB | Criterion | Points | Full credit | Partial credit | No credit | |-----------|--------|-------------|----------------|-----------| -| Criterion 1.1: Ghidra Project Setup | 3 | Correct project name, `ARM Cortex 32-bit little endian`, base `0x10000000` | One item off | Not set up | +| Criterion 1.1: Ghidra Project Setup | 3 | Correct project name, `ARM:LE:32:Cortex` (ARM Cortex 32-bit little endian), base `0x10000000` | One item off | Not set up | | Criterion 1.2: Vector Table Decoding | 3 | Correct base, initial SP, reset pointer | One missing | Not found | | Criterion 1.3: main() and Status-Loop Addresses | 4 | Both addresses correct | One correct | Neither found | | Criterion 1.4: Thumb Addressing and Literal Pool | 2 | Bit 0 cleared and one pool entry traced to its string | Partial | Incorrect | diff --git a/0x0017a_ctf/CTF-02-R.pdf b/0x0017a_ctf/CTF-02-R.pdf index 43bcdae..670ea36 100644 Binary files a/0x0017a_ctf/CTF-02-R.pdf and b/0x0017a_ctf/CTF-02-R.pdf differ diff --git a/0x0017a_ctf/CTF-02-S.md b/0x0017a_ctf/CTF-02-S.md index dc05e3f..310a619 100644 --- a/0x0017a_ctf/CTF-02-S.md +++ b/0x0017a_ctf/CTF-02-S.md @@ -98,7 +98,7 @@ Clearing bit 0 gives `0x1000015A`. A representative literal pool entry is | Criterion | Points | Full Credit (Answer Key) | Partial Credit | No Credit | |-----------|--------|--------------------------|----------------|-----------| -| Criterion 1.1: Ghidra Project Setup | 3 | Correct project name, `ARM Cortex 32-bit little endian`, base `0x10000000` | One item off | Not set up | +| Criterion 1.1: Ghidra Project Setup | 3 | Correct project name, `ARM:LE:32:Cortex` (ARM Cortex 32-bit little endian), base `0x10000000` | One item off | Not set up | | Criterion 1.2: Vector Table Decoding | 3 | Correct base, initial SP, reset pointer | One missing | Not found | | Criterion 1.3: main() and Status-Loop Addresses | 4 | Both addresses correct | One correct | Neither found | | Criterion 1.4: Thumb Addressing and Literal Pool | 2 | Bit 0 cleared and one pool entry traced to its string | Partial | Incorrect | diff --git a/0x0017a_ctf/CTF-02-S.pdf b/0x0017a_ctf/CTF-02-S.pdf index 2ce477f..d527d76 100644 Binary files a/0x0017a_ctf/CTF-02-S.pdf and b/0x0017a_ctf/CTF-02-S.pdf differ diff --git a/README.md b/README.md index 2f73752..5c28949 100644 --- a/README.md +++ b/README.md @@ -491,7 +491,7 @@ Forty-two stories beneath frozen tundra, a shadow intelligence alliance called D # Supplemental Material (Beyond the Scope of the Course) -## Pico 2 IoT Projects & CTFs & Pi 4B/5 Embedded Linux C IoT Project & CTF +## Pico 2 IoT Projects & CTFs ### Act I of OPERATION COLD IRON [HERE](https://github.com/mytechnotalent/cold-chain-monitor) @@ -533,6 +533,10 @@ Forty-two stories beneath frozen tundra, a shadow intelligence alliance called D ### Act X of OPERATION COLD IRON CTF [HERE](https://github.com/mytechnotalent/CTF_chemical-warning-terminal) +
+ +## Pi 4B/5 Embedded Linux C IoT Project & CTF + ### OPERATION TELESCREEN [HERE](https://github.com/mytechnotalent/telescreen) ### OPERATION TELESCREEN CTF [HERE](https://github.com/mytechnotalent/CTF_telescreen)