Commit Graph
101 Commits
Author SHA1 Message Date
Kevin Thomas 55251a2d52 WEEK05-BN: add Binary Ninja lesson for Week 5 (float + double IEEE 754)
New WEEK05-BN.md/.pdf mirroring WEEK04-BN: build/flash/symbol map, load the raw
.bin, dynamic (GDB MI break + live double hack) then static (resolve functions,
patch the 42.5->99.0 one-word and 42.52525->99.99 two-word constants, export,
convert, flash) for both 0x000e float and 0x0011 double. README links it.
2026-10-03 18:50:25 -04:00
Kevin Thomas 4de5f0a8cf Week 4-BN: explicit BN-console OpenOCD kill (per-OS) in Steps 15b and 25c
Both static-pass transitions now show the console kill (pkill / taskkill) as a
numbered step, not just a terminal command.
2026-10-03 18:21:27 -04:00
Kevin Thomas b58715a616 Week 4-BN: Kill only disconnects BN - also stop the OpenOCD process (Steps 15b/25c)
The X/Kill ends the BN debug session but leaves the external OpenOCD (started by
debug-server.sh) running and holding the probe. Tell the reader to pkill/taskkill it
too, and give the console form.
2026-10-03 18:21:00 -04:00
Kevin Thomas 0594cde63b Week 4-BN: free the probe (pkill/taskkill) in the Step 21 and 29 console flash snippets
Step 29's snippet had no pkill, so with the debug-server OpenOCD still attached the
flash failed with 'CMSIS-DAP command CMD_INFO failed / OpenOCD init failed'. Add the
pkill to Step 29 and both Step 21 blocks.
2026-10-03 18:19:11 -04:00
Kevin Thomas e25104a1b0 Week 4-BN: add explicit 'stop the debugger (press the X)' steps 15b and 25c
End each dynamic section by killing the debug session (X / Debugger -> Kill) before
the static pass, so the OpenOCD session is shut down and the probe is free.
2026-10-03 18:12:54 -04:00
Kevin Thomas ed7cf82302 Week 4-BN: add Step 22b - load Project 2 into Binary Ninja and save its .bndb
Mirror Steps 7-8 for Project 2 (Open with Options, thumb2/thumb2/0x10000000,
verify the vector words, Save As .bndb) and point at Step 26 for resolving the
Project 2 functions.
2026-10-03 17:49:42 -04:00
Kevin Thomas c09234c983 Week 4-BN: PEP8 inline comments (two spaces before #) across all snippets
Normalize every inline comment in the code blocks so it is separated from the
statement by exactly two spaces.
2026-10-03 17:45:07 -04:00
Kevin Thomas c6e43703b3 Week 4-BN: Step 23 console option to kill + restart OpenOCD parked at main
Add the Binary Ninja console form (pkill/taskkill then Popen debug-server with
BP_ADDR=0x10000234), matching Step 10.
2026-10-03 17:43:33 -04:00
Kevin Thomas 3738ec5b25 Week 4-BN: console snippets read the repo from ~/.embedded-hacking-repo (no bv, no errors)
The console snippets no longer depend on bv.file.original_filename, so they work
with no database open. Step 3 has a one-time setup (pwd > ~/.embedded-hacking-repo,
or the PowerShell equivalent) and every build/flash/server snippet reads root from
that file. Removes the bv asserts.
2026-10-03 17:40:39 -04:00
Kevin Thomas fae2ffc938 Week 4-BN: guard the console snippets against bv being None
Every console snippet derives the repo path from bv.file.original_filename, so
with no database open bv is None and it fails with 'NoneType has no attribute
file'. Add 'assert bv is not None, "Open the .bndb first..."' to all 12 snippets
so the failure is explicit.
2026-10-03 17:37:54 -04:00
Kevin Thomas 5225f47ecf Week 4-BN: add the BN console flash option to Steps 5, 6, and 22
Every flash step now has the terminal form and the console form (pkill/taskkill,
then Popen flash.sh/.ps1 into flash.log), matching Steps 10/21/29. Steps 5/6 note
they need a database open to derive the repo root.
2026-10-03 17:34:47 -04:00
Kevin Thomas ef2bf0eb71 Week 4-BN: start OpenOCD from the BN console in the background; gitignore helper logs
Step 10 now shows starting the debug server from the console: pkill/taskkill any
running OpenOCD first, then Popen debug-server.sh(.ps1) with BP_ADDR and output to
openocd.log so the console returns immediately. Verified: Popen returns in ~6 ms,
log shows 'Startup breakpoint at 0x10000234' + 'Listening on port 3333'. Ignore
openocd.log/flash.log/build.log.
2026-10-03 17:30:24 -04:00
Kevin Thomas 9dc954ea0c Week 4-BN: build from the BN console too (per-OS, plain cmake)
Add macOS/Linux/Windows console build snippets to Step 3. The console's PATH is
minimal (no Homebrew on macOS), so macOS adds /opt/homebrew/bin to PATH then runs
plain cmake; Linux/Windows already have cmake on PATH. With the Popen flash, the
whole build->patch->flash loop runs inside Binary Ninja.
2026-10-03 17:09:29 -04:00
Kevin Thomas c9bdc6efc5 Week 4-BN: flash from the BN console without blocking it (Popen, not run)
subprocess.run blocks the console until OpenOCD exits (and can hang it if the
probe is contended). Use subprocess.Popen with output to flash.log and
start_new_session, then poll p.poll() or read the log. Verified: Popen returns in
~1 ms, flash completes ~2 s later with 'Verified OK'. Applied to Steps 21 and 29.
2026-10-03 16:59:06 -04:00
Kevin Thomas 54852d1241 Week 4-BN: give every command all OS variants (macOS/Linux + Windows)
Add the missing Windows PowerShell/cmd forms for flash, stop-server, debug-server
BP_ADDR, and the Step 29 uf2conv call, so no command is platform-ambiguous.
2026-10-03 16:49:00 -04:00
Kevin Thomas c2bab7cbd6 README: name arm-none-eabi-gdb in the toolchain; split compile/flash per platform
The Pico extension's Arm GNU Toolchain includes arm-none-eabi-gdb (used by the
GDB / GDB MI labs) -- call it out. Keep the identical cmake build for all OSes but
give full Windows / macOS / Linux compile+flash blocks, plus the explicit
PICO_SDK_PATH/PICO_TOOLCHAIN_PATH fallback.
2026-10-03 16:43:25 -04:00
Kevin Thomas 86d3dbdb12 Week 4-BN: flash over SWD from the console (no BOOTSEL)
Add the flash.sh / OpenOCD program-over-probe path to Steps 21 and 29: run it
from Binary Ninja's console via subprocess, and note the probe is single-owner
(stop debug-server.sh's OpenOCD first). Verified live: Verified OK, reset, and the
board booted the hacked image.
2026-10-03 16:40:28 -04:00
Kevin Thomas d9c2922445 README: add native Development Environment Setup (Windows/macOS/Linux)
Install everything for the course without a VM: VS Code Pico extension (SDK,
Arm toolchain, picotool, OpenOCD), Binary Ninja Personal, Ghidra + JDK 21, and a
serial monitor. Ends with a compile + SWD flash example for 0x0001 hello, world.
2026-10-03 16:39:29 -04:00
Kevin Thomas 1b292058f5 Week 4-BN: export the image dynamically from the view's segment; run uf2conv in-app
Read the loadable segment (seg.start + seg.data_length) instead of hardcoding the
range or calling os.path.getsize, and document converting the .bin to UF2 from
Binary Ninja's own Python console (chdir + runpy). Verified: the dump is byte-exact
except the patches, and uf2conv yields a valid UF2 (magic/family/blocks OK).
2026-10-03 16:28:42 -04:00
Kevin Thomas f9e4cab78e Week 4-BN: fix the .bin export step in both projects
The console's CWD is read-only, so open('...bin','wb') fails with OSError
Errno 30. Write next to the loaded file via bv.file.original_filename, and read
the image range (0x10000000 + 0x3bbc / 0x3d34) instead of the whole mapped view.
2026-10-03 16:24:09 -04:00
Kevin Thomas 73de93e194 Week 4-BN: define SDK types before set_user_type (fixes 'unknown type name')
The Python shortcut failed with SyntaxError: unknown type name 'stdio_driver_t'
then 'va_list' then 'uint'. set_user_type re-parses each signature as C, so the
Pico SDK types (uint, va_list, stdio_driver_t, uart_inst_t, gpio_function_t) must
be defined first. Add the sdk parse/define block to both snippets and correct the
stale 'undefined named types are fine' note.
2026-10-03 16:10:35 -04:00
Kevin Thomas 023b1cb4b7 Week 4-BN: edit registers from the Python console (dbg.set_reg_value)
Replace the wrong 'double-click the value' instruction with
dbg.set_reg_value('r1', 0x46) / dbg.set_reg_value('r0', 0x20080000);
right-click + E kept as the alternative. Drop the 'turns orange' claim.
2026-10-03 15:41:52 -04:00
Kevin Thomas f37eface3e Week 4-BN: write target RAM from BN itself (dbg.write_memory), drop the command-port step
Both string-hack steps now use dbg.write_memory(0x20080000, b'foo: %d\r\n\0')
in Binary Ninja's Python console instead of OpenOCD mww over nc/4444.
2026-10-03 15:32:50 -04:00
Kevin Thomas e392d3da92 Week 4-BN: document the working void-return fix (fn.return_value setter)
Y and fn.return_type both fail for _reset_handler; fn.return_value =
ReturnValue(Type.void()) holds through reanalysis (verified live).
2026-10-03 15:23:00 -04:00
Kevin Thomas 7b956eb83d Week 4-BN: note that BN analysis can override a void return type
_reset_handler and potentially any function: BN may show int32_t even after
you set void; the analysis wins over the low-confidence void. Leave it.
2026-10-03 15:20:01 -04:00
Kevin Thomas da756ec241 Week 4-BN: give _reset_handler a prototype (void _reset_handler(void))
Fix the six places it was left as an em dash: both Step 4 symbol tables,
both resolution tables, and both Python shortcuts.
2026-10-03 15:11:43 -04:00
Kevin Thomas 41e6d6c11f Week 4-BN: resolve functions with Y (Change Type); fully resolve name+type
- Step 16: Y is the primary resolution key (Change Type sets name+type); N is
  rename-only; explicit how-to and worked examples use G then Y
- Step 4: add exact DWARF signatures to both symbol tables
- Python shortcut now sets names AND types (bv.get_function_at(...).set_user_type)
- Step 26: worked examples use G then Y
2026-10-03 15:08:58 -04:00
Kevin Thomas e41c4581bd Week 4-BN: detailed step-by-step resolution worked examples for Project 2 (0x0008)
- Step 26: worked examples for main, gpio_init, sleep_ms, stdio_init_all,
  __wrap_printf (same G/N/Y mechanics as Step 16)
2026-10-03 14:58:46 -04:00
Kevin Thomas 55888dadb0 Week 4-BN: step-by-step function resolution in BN, int32_t note, serial tip
- Step 16: G/N/Y key table and worked examples (main, stdio_init_all, uart_init,
  __wrap_printf); note BN shows int32_t where Ghidra shows int
- Step 26: worked check + pointer to Step 16
- troubleshooting: macOS serial capture needs raw termios at 115200
2026-10-03 14:58:07 -04:00
Kevin Thomas 4f56b897cf Week 4-BN: require hardware breakpoints (F2 software bps do not work on flash)
- Step 13/14/25 and tables: use Debugger -> Add Hardware Breakpoint... (HE),
  warn that F2 Toggle Breakpoint is a software breakpoint and never installs on
  read-only flash
- new troubleshooting entry: r1 reverts to 0x2b (core running because the
  breakpoint is not installed; registers widget is a per-stop snapshot)
2026-10-03 13:57:26 -04:00
Kevin Thomas 283629e1e1 Week 4-BN: make the whole lab use the GDB MI GUI workflow
- Step 13 rewritten: set/move breakpoints in the GUI, not the command port
- Steps 14/14b/25/25b: breakpoints via the GUI (command port only for the
  RAM string write, which BN cannot do)
- Step 22/23: adapter corrected GDB RSP -> GDB MI
- cheat sheet, GUI-actions and OpenOCD tables: GUI-first, command port as fallback
- troubleshooting: real GDB MI causes (pre-existing breakpoint, gdb path, LLDB);
  stops reported as Breakpoint not SingleStep
2026-10-03 11:49:06 -04:00
Kevin Thomas 3f7b242b18 Rewrite root uf2conv.py as the canonical, documented converter
Single canonical copy at the repo root: full type annotations and
Google-style docstrings, pathlib instead of os.path, explicit except
clauses, upstream error-path bugs fixed, and module globals replaced
with an explicit ConverterContext.
2026-10-03 11:39:03 -04:00
Kevin Thomas 3e52dd0412 Add Week 4 Binary Ninja notebook and OpenOCD/flash host tooling
- WEEK04-BN.md/.pdf: full Binary Ninja dynamic + static lab for 0x0005 and 0x0008
- README: link the Week 4-BN notebook after Week 4a
- debug-server.sh/.ps1: OpenOCD launcher (USE_CORE=0, -rtos none, BP_ADDR)
- flash.sh/.ps1: UF2 flash helpers
- pyproject.toml: ruff config for root host-side scripts
2026-10-03 11:33:10 -04:00
Kevin Thomas 34f21bcd52 Update README.md 2026-10-02 09:37:56 -04:00
Kevin Thomas 4c58ae8eac Convert all course PDFs to tagged, accessible (Canvas-compliant) documents 2026-10-01 13:54:39 -04:00
Kevin Thomas ed95369a0e Regenerate Week 7 PDF as tagged/accessible document; document tagging in PDF skill 2026-10-01 11:46:31 -04:00
Kevin Thomas 62e8a2ca70 Fix Week 7 ASCII-art arrow mojibake and regenerate PDF 2026-10-01 11:46:31 -04:00
Kevin Thomas ec1964b5cc Revise today's tutorial and lesson information
Updated tutorial date and lesson details for October 1, 2026.
2026-10-01 09:46:18 -04:00
Kevin Thomas 8c21fb50c6 Update README.md 2026-09-30 09:30:14 -04:00
Kevin Thomas bbda3d31d1 Update README.md 2026-09-29 09:49:06 -04:00
Kevin Thomas 498f8cafc0 Add files via upload 2026-09-29 09:48:35 -04:00
Kevin Thomas 2ac27dc108 Update README.md 2026-09-29 08:47:05 -04:00
Kevin Thomas 4b92d17357 Update README.md 2026-09-28 18:13:10 -04:00
Kevin Thomas 67d3226b22 Update README.md 2026-09-28 12:42:28 -04:00
Kevin Thomas c9c23dd413 Update README.md 2026-09-28 12:06:04 -04:00
Kevin Thomas a06615b615 Update README.md 2026-09-28 10:38:34 -04:00
Kevin Thomas 026bdb9597 Update README.md 2026-09-28 09:52:26 -04:00
Kevin Thomas b3e0a05ade Update README.md 2026-09-27 19:23:22 -04:00
Kevin Thomas 35eacd2c0e Course update: lessons, CTF 0x0011a_cb, and documentation
- 0x0011a_cb (Operation Dark Vector): nation-state CTF redesign with an
  AES-128-ECB sealed target and a plaintext launch origin; RP2350 firmware with
  bearing-driven servo, tri-color LEDs, GSV stats, and a realistic no-fix path
- docs: story-driven classified brief, GDB and Ghidra tutorials with deep
  step-throughs, regenerated artifacts and PDFs
- scripts: docstring standard, AES per-student randomizer, telemetry monitor
- week 3 to week 5 lessons: Ghidra patching tutorial, CMSIS-SVD hardware RE,
  double floating-point and GPIO architecture chapters, README structure
2026-09-27 14:18:56 -04:00
Kevin Thomas 5201ee4b6b Revise today's tutorial and lesson information
Updated tutorial date and lesson details.
2026-08-27 09:10:37 -04:00