Commit Graph
30 Commits
Author SHA1 Message Date
Kevin Thomas ed7cf82302 Week 4-BN: add Step 22b - load Project 2 into Binary Ninja and save its .bndb
Mirror Steps 7-8 for Project 2 (Open with Options, thumb2/thumb2/0x10000000,
verify the vector words, Save As .bndb) and point at Step 26 for resolving the
Project 2 functions.
2026-10-03 17:49:42 -04:00
Kevin Thomas c09234c983 Week 4-BN: PEP8 inline comments (two spaces before #) across all snippets
Normalize every inline comment in the code blocks so it is separated from the
statement by exactly two spaces.
2026-10-03 17:45:07 -04:00
Kevin Thomas c6e43703b3 Week 4-BN: Step 23 console option to kill + restart OpenOCD parked at main
Add the Binary Ninja console form (pkill/taskkill then Popen debug-server with
BP_ADDR=0x10000234), matching Step 10.
2026-10-03 17:43:33 -04:00
Kevin Thomas 3738ec5b25 Week 4-BN: console snippets read the repo from ~/.embedded-hacking-repo (no bv, no errors)
The console snippets no longer depend on bv.file.original_filename, so they work
with no database open. Step 3 has a one-time setup (pwd > ~/.embedded-hacking-repo,
or the PowerShell equivalent) and every build/flash/server snippet reads root from
that file. Removes the bv asserts.
2026-10-03 17:40:39 -04:00
Kevin Thomas fae2ffc938 Week 4-BN: guard the console snippets against bv being None
Every console snippet derives the repo path from bv.file.original_filename, so
with no database open bv is None and it fails with 'NoneType has no attribute
file'. Add 'assert bv is not None, "Open the .bndb first..."' to all 12 snippets
so the failure is explicit.
2026-10-03 17:37:54 -04:00
Kevin Thomas 5225f47ecf Week 4-BN: add the BN console flash option to Steps 5, 6, and 22
Every flash step now has the terminal form and the console form (pkill/taskkill,
then Popen flash.sh/.ps1 into flash.log), matching Steps 10/21/29. Steps 5/6 note
they need a database open to derive the repo root.
2026-10-03 17:34:47 -04:00
Kevin Thomas ef2bf0eb71 Week 4-BN: start OpenOCD from the BN console in the background; gitignore helper logs
Step 10 now shows starting the debug server from the console: pkill/taskkill any
running OpenOCD first, then Popen debug-server.sh(.ps1) with BP_ADDR and output to
openocd.log so the console returns immediately. Verified: Popen returns in ~6 ms,
log shows 'Startup breakpoint at 0x10000234' + 'Listening on port 3333'. Ignore
openocd.log/flash.log/build.log.
2026-10-03 17:30:24 -04:00
Kevin Thomas 9dc954ea0c Week 4-BN: build from the BN console too (per-OS, plain cmake)
Add macOS/Linux/Windows console build snippets to Step 3. The console's PATH is
minimal (no Homebrew on macOS), so macOS adds /opt/homebrew/bin to PATH then runs
plain cmake; Linux/Windows already have cmake on PATH. With the Popen flash, the
whole build->patch->flash loop runs inside Binary Ninja.
2026-10-03 17:09:29 -04:00
Kevin Thomas c9bdc6efc5 Week 4-BN: flash from the BN console without blocking it (Popen, not run)
subprocess.run blocks the console until OpenOCD exits (and can hang it if the
probe is contended). Use subprocess.Popen with output to flash.log and
start_new_session, then poll p.poll() or read the log. Verified: Popen returns in
~1 ms, flash completes ~2 s later with 'Verified OK'. Applied to Steps 21 and 29.
2026-10-03 16:59:06 -04:00
Kevin Thomas 54852d1241 Week 4-BN: give every command all OS variants (macOS/Linux + Windows)
Add the missing Windows PowerShell/cmd forms for flash, stop-server, debug-server
BP_ADDR, and the Step 29 uf2conv call, so no command is platform-ambiguous.
2026-10-03 16:49:00 -04:00
Kevin Thomas 86d3dbdb12 Week 4-BN: flash over SWD from the console (no BOOTSEL)
Add the flash.sh / OpenOCD program-over-probe path to Steps 21 and 29: run it
from Binary Ninja's console via subprocess, and note the probe is single-owner
(stop debug-server.sh's OpenOCD first). Verified live: Verified OK, reset, and the
board booted the hacked image.
2026-10-03 16:40:28 -04:00
Kevin Thomas 1b292058f5 Week 4-BN: export the image dynamically from the view's segment; run uf2conv in-app
Read the loadable segment (seg.start + seg.data_length) instead of hardcoding the
range or calling os.path.getsize, and document converting the .bin to UF2 from
Binary Ninja's own Python console (chdir + runpy). Verified: the dump is byte-exact
except the patches, and uf2conv yields a valid UF2 (magic/family/blocks OK).
2026-10-03 16:28:42 -04:00
Kevin Thomas f9e4cab78e Week 4-BN: fix the .bin export step in both projects
The console's CWD is read-only, so open('...bin','wb') fails with OSError
Errno 30. Write next to the loaded file via bv.file.original_filename, and read
the image range (0x10000000 + 0x3bbc / 0x3d34) instead of the whole mapped view.
2026-10-03 16:24:09 -04:00
Kevin Thomas 73de93e194 Week 4-BN: define SDK types before set_user_type (fixes 'unknown type name')
The Python shortcut failed with SyntaxError: unknown type name 'stdio_driver_t'
then 'va_list' then 'uint'. set_user_type re-parses each signature as C, so the
Pico SDK types (uint, va_list, stdio_driver_t, uart_inst_t, gpio_function_t) must
be defined first. Add the sdk parse/define block to both snippets and correct the
stale 'undefined named types are fine' note.
2026-10-03 16:10:35 -04:00
Kevin Thomas 023b1cb4b7 Week 4-BN: edit registers from the Python console (dbg.set_reg_value)
Replace the wrong 'double-click the value' instruction with
dbg.set_reg_value('r1', 0x46) / dbg.set_reg_value('r0', 0x20080000);
right-click + E kept as the alternative. Drop the 'turns orange' claim.
2026-10-03 15:41:52 -04:00
Kevin Thomas f37eface3e Week 4-BN: write target RAM from BN itself (dbg.write_memory), drop the command-port step
Both string-hack steps now use dbg.write_memory(0x20080000, b'foo: %d\r\n\0')
in Binary Ninja's Python console instead of OpenOCD mww over nc/4444.
2026-10-03 15:32:50 -04:00
Kevin Thomas e392d3da92 Week 4-BN: document the working void-return fix (fn.return_value setter)
Y and fn.return_type both fail for _reset_handler; fn.return_value =
ReturnValue(Type.void()) holds through reanalysis (verified live).
2026-10-03 15:23:00 -04:00
Kevin Thomas 7b956eb83d Week 4-BN: note that BN analysis can override a void return type
_reset_handler and potentially any function: BN may show int32_t even after
you set void; the analysis wins over the low-confidence void. Leave it.
2026-10-03 15:20:01 -04:00
Kevin Thomas da756ec241 Week 4-BN: give _reset_handler a prototype (void _reset_handler(void))
Fix the six places it was left as an em dash: both Step 4 symbol tables,
both resolution tables, and both Python shortcuts.
2026-10-03 15:11:43 -04:00
Kevin Thomas 41e6d6c11f Week 4-BN: resolve functions with Y (Change Type); fully resolve name+type
- Step 16: Y is the primary resolution key (Change Type sets name+type); N is
  rename-only; explicit how-to and worked examples use G then Y
- Step 4: add exact DWARF signatures to both symbol tables
- Python shortcut now sets names AND types (bv.get_function_at(...).set_user_type)
- Step 26: worked examples use G then Y
2026-10-03 15:08:58 -04:00
Kevin Thomas e41c4581bd Week 4-BN: detailed step-by-step resolution worked examples for Project 2 (0x0008)
- Step 26: worked examples for main, gpio_init, sleep_ms, stdio_init_all,
  __wrap_printf (same G/N/Y mechanics as Step 16)
2026-10-03 14:58:46 -04:00
Kevin Thomas 55888dadb0 Week 4-BN: step-by-step function resolution in BN, int32_t note, serial tip
- Step 16: G/N/Y key table and worked examples (main, stdio_init_all, uart_init,
  __wrap_printf); note BN shows int32_t where Ghidra shows int
- Step 26: worked check + pointer to Step 16
- troubleshooting: macOS serial capture needs raw termios at 115200
2026-10-03 14:58:07 -04:00
Kevin Thomas 4f56b897cf Week 4-BN: require hardware breakpoints (F2 software bps do not work on flash)
- Step 13/14/25 and tables: use Debugger -> Add Hardware Breakpoint... (HE),
  warn that F2 Toggle Breakpoint is a software breakpoint and never installs on
  read-only flash
- new troubleshooting entry: r1 reverts to 0x2b (core running because the
  breakpoint is not installed; registers widget is a per-stop snapshot)
2026-10-03 13:57:26 -04:00
Kevin Thomas 283629e1e1 Week 4-BN: make the whole lab use the GDB MI GUI workflow
- Step 13 rewritten: set/move breakpoints in the GUI, not the command port
- Steps 14/14b/25/25b: breakpoints via the GUI (command port only for the
  RAM string write, which BN cannot do)
- Step 22/23: adapter corrected GDB RSP -> GDB MI
- cheat sheet, GUI-actions and OpenOCD tables: GUI-first, command port as fallback
- troubleshooting: real GDB MI causes (pre-existing breakpoint, gdb path, LLDB);
  stops reported as Breakpoint not SingleStep
2026-10-03 11:49:06 -04:00
Kevin Thomas 3e52dd0412 Add Week 4 Binary Ninja notebook and OpenOCD/flash host tooling
- WEEK04-BN.md/.pdf: full Binary Ninja dynamic + static lab for 0x0005 and 0x0008
- README: link the Week 4-BN notebook after Week 4a
- debug-server.sh/.ps1: OpenOCD launcher (USE_CORE=0, -rtos none, BP_ADDR)
- flash.sh/.ps1: UF2 flash helpers
- pyproject.toml: ruff config for root host-side scripts
2026-10-03 11:33:10 -04:00
Kevin Thomas 4c58ae8eac Convert all course PDFs to tagged, accessible (Canvas-compliant) documents 2026-10-01 13:54:39 -04:00
Kevin Thomas 35eacd2c0e Course update: lessons, CTF 0x0011a_cb, and documentation
- 0x0011a_cb (Operation Dark Vector): nation-state CTF redesign with an
  AES-128-ECB sealed target and a plaintext launch origin; RP2350 firmware with
  bearing-driven servo, tri-color LEDs, GSV stats, and a realistic no-fix path
- docs: story-driven classified brief, GDB and Ghidra tutorials with deep
  step-throughs, regenerated artifacts and PDFs
- scripts: docstring standard, AES per-student randomizer, telemetry monitor
- week 3 to week 5 lessons: Ghidra patching tutorial, CMSIS-SVD hardware RE,
  double floating-point and GPIO architecture chapters, README structure
2026-09-27 14:18:56 -04:00
Kevin Thomas 054787416f Added PDFs 2026-08-15 07:11:17 -04:00
Kevin Thomas bd949952ad Added legal statements 2026-07-19 09:26:57 -04:00
Kevin Thomas 6a9090915b Initial commit 2026-07-06 21:23:12 -04:00