20 Commits
Author SHA1 Message Date
Kevin Thomas 86d3dbdb12 Week 4-BN: flash over SWD from the console (no BOOTSEL)
Add the flash.sh / OpenOCD program-over-probe path to Steps 21 and 29: run it
from Binary Ninja's console via subprocess, and note the probe is single-owner
(stop debug-server.sh's OpenOCD first). Verified live: Verified OK, reset, and the
board booted the hacked image.
2026-10-03 16:40:28 -04:00
Kevin Thomas 1b292058f5 Week 4-BN: export the image dynamically from the view's segment; run uf2conv in-app
Read the loadable segment (seg.start + seg.data_length) instead of hardcoding the
range or calling os.path.getsize, and document converting the .bin to UF2 from
Binary Ninja's own Python console (chdir + runpy). Verified: the dump is byte-exact
except the patches, and uf2conv yields a valid UF2 (magic/family/blocks OK).
2026-10-03 16:28:42 -04:00
Kevin Thomas f9e4cab78e Week 4-BN: fix the .bin export step in both projects
The console's CWD is read-only, so open('...bin','wb') fails with OSError
Errno 30. Write next to the loaded file via bv.file.original_filename, and read
the image range (0x10000000 + 0x3bbc / 0x3d34) instead of the whole mapped view.
2026-10-03 16:24:09 -04:00
Kevin Thomas 73de93e194 Week 4-BN: define SDK types before set_user_type (fixes 'unknown type name')
The Python shortcut failed with SyntaxError: unknown type name 'stdio_driver_t'
then 'va_list' then 'uint'. set_user_type re-parses each signature as C, so the
Pico SDK types (uint, va_list, stdio_driver_t, uart_inst_t, gpio_function_t) must
be defined first. Add the sdk parse/define block to both snippets and correct the
stale 'undefined named types are fine' note.
2026-10-03 16:10:35 -04:00
Kevin Thomas 023b1cb4b7 Week 4-BN: edit registers from the Python console (dbg.set_reg_value)
Replace the wrong 'double-click the value' instruction with
dbg.set_reg_value('r1', 0x46) / dbg.set_reg_value('r0', 0x20080000);
right-click + E kept as the alternative. Drop the 'turns orange' claim.
2026-10-03 15:41:52 -04:00
Kevin Thomas f37eface3e Week 4-BN: write target RAM from BN itself (dbg.write_memory), drop the command-port step
Both string-hack steps now use dbg.write_memory(0x20080000, b'foo: %d\r\n\0')
in Binary Ninja's Python console instead of OpenOCD mww over nc/4444.
2026-10-03 15:32:50 -04:00
Kevin Thomas e392d3da92 Week 4-BN: document the working void-return fix (fn.return_value setter)
Y and fn.return_type both fail for _reset_handler; fn.return_value =
ReturnValue(Type.void()) holds through reanalysis (verified live).
2026-10-03 15:23:00 -04:00
Kevin Thomas 7b956eb83d Week 4-BN: note that BN analysis can override a void return type
_reset_handler and potentially any function: BN may show int32_t even after
you set void; the analysis wins over the low-confidence void. Leave it.
2026-10-03 15:20:01 -04:00
Kevin Thomas da756ec241 Week 4-BN: give _reset_handler a prototype (void _reset_handler(void))
Fix the six places it was left as an em dash: both Step 4 symbol tables,
both resolution tables, and both Python shortcuts.
2026-10-03 15:11:43 -04:00
Kevin Thomas 41e6d6c11f Week 4-BN: resolve functions with Y (Change Type); fully resolve name+type
- Step 16: Y is the primary resolution key (Change Type sets name+type); N is
  rename-only; explicit how-to and worked examples use G then Y
- Step 4: add exact DWARF signatures to both symbol tables
- Python shortcut now sets names AND types (bv.get_function_at(...).set_user_type)
- Step 26: worked examples use G then Y
2026-10-03 15:08:58 -04:00
Kevin Thomas e41c4581bd Week 4-BN: detailed step-by-step resolution worked examples for Project 2 (0x0008)
- Step 26: worked examples for main, gpio_init, sleep_ms, stdio_init_all,
  __wrap_printf (same G/N/Y mechanics as Step 16)
2026-10-03 14:58:46 -04:00
Kevin Thomas 55888dadb0 Week 4-BN: step-by-step function resolution in BN, int32_t note, serial tip
- Step 16: G/N/Y key table and worked examples (main, stdio_init_all, uart_init,
  __wrap_printf); note BN shows int32_t where Ghidra shows int
- Step 26: worked check + pointer to Step 16
- troubleshooting: macOS serial capture needs raw termios at 115200
2026-10-03 14:58:07 -04:00
Kevin Thomas 4f56b897cf Week 4-BN: require hardware breakpoints (F2 software bps do not work on flash)
- Step 13/14/25 and tables: use Debugger -> Add Hardware Breakpoint... (HE),
  warn that F2 Toggle Breakpoint is a software breakpoint and never installs on
  read-only flash
- new troubleshooting entry: r1 reverts to 0x2b (core running because the
  breakpoint is not installed; registers widget is a per-stop snapshot)
2026-10-03 13:57:26 -04:00
Kevin Thomas 283629e1e1 Week 4-BN: make the whole lab use the GDB MI GUI workflow
- Step 13 rewritten: set/move breakpoints in the GUI, not the command port
- Steps 14/14b/25/25b: breakpoints via the GUI (command port only for the
  RAM string write, which BN cannot do)
- Step 22/23: adapter corrected GDB RSP -> GDB MI
- cheat sheet, GUI-actions and OpenOCD tables: GUI-first, command port as fallback
- troubleshooting: real GDB MI causes (pre-existing breakpoint, gdb path, LLDB);
  stops reported as Breakpoint not SingleStep
2026-10-03 11:49:06 -04:00
Kevin Thomas 3e52dd0412 Add Week 4 Binary Ninja notebook and OpenOCD/flash host tooling
- WEEK04-BN.md/.pdf: full Binary Ninja dynamic + static lab for 0x0005 and 0x0008
- README: link the Week 4-BN notebook after Week 4a
- debug-server.sh/.ps1: OpenOCD launcher (USE_CORE=0, -rtos none, BP_ADDR)
- flash.sh/.ps1: UF2 flash helpers
- pyproject.toml: ruff config for root host-side scripts
2026-10-03 11:33:10 -04:00
Kevin Thomas 4c58ae8eac Convert all course PDFs to tagged, accessible (Canvas-compliant) documents 2026-10-01 13:54:39 -04:00
Kevin Thomas 35eacd2c0e Course update: lessons, CTF 0x0011a_cb, and documentation
- 0x0011a_cb (Operation Dark Vector): nation-state CTF redesign with an
  AES-128-ECB sealed target and a plaintext launch origin; RP2350 firmware with
  bearing-driven servo, tri-color LEDs, GSV stats, and a realistic no-fix path
- docs: story-driven classified brief, GDB and Ghidra tutorials with deep
  step-throughs, regenerated artifacts and PDFs
- scripts: docstring standard, AES per-student randomizer, telemetry monitor
- week 3 to week 5 lessons: Ghidra patching tutorial, CMSIS-SVD hardware RE,
  double floating-point and GPIO architecture chapters, README structure
2026-09-27 14:18:56 -04:00
Kevin Thomas 054787416f Added PDFs 2026-08-15 07:11:17 -04:00
Kevin Thomas bd949952ad Added legal statements 2026-07-19 09:26:57 -04:00
Kevin Thomas 6a9090915b Initial commit 2026-07-06 21:23:12 -04:00