GreHack 2018 Writeups

From YobiWiki
Jump to navigation Jump to search

The GreHack2018 CTF was an offline CTF and one big advantage of offline CTFs is that you can have hardware-oriented challenges, in this case a series of challenges lovely crafted by Philippe Paget (@PagetPhil).

The series is made of 5 (or 6) levels representing the evolution of a realistic product: a hardware secret keeper dongle based on STM32.

The GreHack Secret Keeper

The first level provides the hardware information useful for all levels.

Products Information

How the product works: just plug the USB type A connector and connect to the virtual serial port at 9600 8N1. The fancy menus will guide you over all the available functionality.
A few words about security: At GreHack no joke with security. All the specifications are done at the end of the evening, after several beers, in the respect of the traditions. This GreHack Secret Keeper use SHA-256 hash for ALL the passwords used in the application and the entire secrets are store encrypted with AES-ECB-256. Those algorithms are the state of the art and don’t have any flaw. Until today our whole implementation is proven secure.
So, well done, you’ve choose the most secure "Secret Keeper" of the market. The GreHack team hope you’ll enjoy it and store all your valuable secrets in.

Challenges howto

1) Mandatory Instructions to follow in order to not kill the game: do not burn or lock the microcontroller!

  • Never put 2 power lines on the microcontroller boards. The Type A USB port from the serial module of each Secret Keeper is enough for power. A single VCC wire per microcontroller board. Be careful not to add a VCC wire when connecting the ST-LINK if the serial USB module is connected! And, never connect an USB cable to the microcontroller module, it is useless: the port is disabled and will provide a second power supply witch will fry the microcontroller.
  • NEVER write in the flash of microcontrollers with low level tools. This includes the "option bytes" or the "fuse configuration" which makes it possible to protect & lock the microcontroller and makes it impossible to dump or even to erase.

2) General instructions to solve the 6 levels:

  • The 6 challenges retrace the life of a real product and all successive #fail until its final well protected ultimate version. It should be noted that 99.99% of the code is identical when a firmware is used for the next version of the module. Just minor fixes are applied to remove some flaws.
  • These are hardware / reverse / exploit category challenges. No steganography or puzzle. Everything is factual, any clue in the subject is important and everything is to read in the first degree.
  • It is almost impossible to solve the challenges in the disorder (only the level 2 can be skipped but would miss for understanding the following levels).

3) Pinout

  • Level 1 - 2 :

Grehack2018 hw lv12.jpg

  • Level 3 4 5 6 :

Grehack2018 hw lv3456.jpg

LED: GPIO port A, GPIO PIN 15, (PA15), LED on with output at 0

4) Available extra stuff:

In order to solve the challenges there is additional stuff available on the desk, do not hesitate to use it, it’s even mandatory for the ST-LINK. Other boards, serial modules, cables etc. are available for testing.

5) USB / Serial module :

2 different modules are used in the Secret Keeper: most are PL2303 and there are some CH340. Available, 3 other modules with FTDI chip if there are problems with drivers.

Datasheets

The bundle contains also the following datasheets:

First grip on GreHack Secret Keeper

The software is roughly the same across levels and the hardware of the first two levels is left unconfigured, so one can play with it, explore menus, add a password, wipe it all, etc.

$ screen /dev/ttyUSB0 9600
    ################################
    #### GreHack Secret Keeper #####
    ################################
 
                .==.
              _/____\_
       _.,--'" ||^ || "`z._
      /_/^ ___\||  || _/o\ "`-._
    _/  ]. L_| || .||  \_/_  . _`--._
   /_~7  _ . " ||. || /] \ ]. (_)  . "`--.
  |__7~.(_)_ []|+--+|/____T_____________L|
  |__|  _^(_) /^   __\____ _   _|
  |__| (_){_) J ]K{__ L___ _   _]
  |__| . _(_) \v     /__________|________
  l__l_ (_). []|+-+-<\^   L  . _   - ---L|
   \__\    __. ||^l  \Y] /_]  (_) .  _,--'
     \~_]  L_| || .\ .\\/~.    _,--'"
      \_\ . __/||  |\  \`-+-<'"
        "`---._|J__L|X o~~|[\\    "Keep your secrets in a proven ship"
               \____/ \___|[//
                `--'   `--+-'
 

Press ENTER to start

Pressing Enter...

Secret Keeper is empty

*** Secret Keeper is empty ***

-1- Set a password.
-2- Generate good password.
-3- Product information.

Choice: 

-1- Set a password.

Choice: 1
Enter a password: ****
Repeat password:  ****

Password set, rebooting

=> see "Secret Keeper locked"

-2- Generate good password.

Choice: 2
Helper function to generate a good password.

Please enter 8 random chars max: aaaaaaaa

Generated password: 8Acx511SNdf1

Press ENTER to continue

-3- Product information.

Choice: 3
.......................................
..............OOOOo....................
............oOOOOOOo...................
............oOOOOOOO...................
............oOOOOOOOOOOOO..............
..........OOOOOOOOOOOOOOOOOOO..........
........OOOOOOOOOOOOOOOOOOOOOOO........
.......OOOOOOOOOOOOOOOOOOOOOOOOOo......
.....OOOOOOOOOOOOOOOOOOOOOOOOOOOOO.....
....OOOOOOOOOOOOOOOOOoOoOo..ooOoOOO....
...oOOOOOOOOOO.oOOOOOOOOOOOOOOOOOOOo...
...OOOOOO.oOOOOOOOOOOOOOOOOOOOOOOOOOO..
..OOO.oOOOOOOOOOOOOo..oO......Oo..OOO..
..OOOOOOOOOOO.OOOOOOOOO........OOOOOO..
.OOOOOOO.......OOOOOOO..........OOOOOO.
.oOOo.OO.......OOOOOOO..........OOOOOO.
...OOOOO........OOOOOO..........OOOOOO.
..OOOOOO.......oOOOOOO..........OOOOOo.
..oOOOOOo......OOOOOOOO........oOOOOO..
...OOOOOOO....OOOOOOOOOO......OOOOOOO..
....OOOOOOOOOOOOOOOOOOOOOO..OOOOOOOO...
....OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO....
.....OOOOOOOOOOOOOOOOOOOOOOOOOOOOOO....
....OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO...
....OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO...
....OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO....
.....OOOOOOOOOOOOOOOOOOOOOOOOOOOOOO....
......OOOOOOOo.OOOOOOOOOO..OOOOOOO.....
........OOOo....OOOOOOOO...............
.................oOOOO.................
.......................................

*******************************************************************************
**************************** GreHack Secret Keeper ****************************
*******************************************************************************

-------------------------------------------------------------------------------
                              General Information
-------------------------------------------------------------------------------
Type.................: Utility
Platform.............: STM32

-------------------------------------------------------------------------------
                                 Release Notes
-------------------------------------------------------------------------------
Version 1.00

Press ENTER to continue

Secret Keeper locked

*** Secret Keeper locked ***

-1- Enter the password.
-2- Lost password, wipe all.
-3- Generate good password.
-4- Product information.

Choice:

-1- Enter the password.

Choice: 1
Enter the password: 

=> See "Secret Keeper unlocked"

-2- Lost password, wipe all.

Choice: 2
 _       ___            ____        __ 
| |     / (_)___  ___  / __ \__  __/ /_
| | /| / / / __ \/ _ \/ / / / / / / __/
| |/ |/ / / /_/ /  __/ /_/ / /_/ / /_  
|__/|__/_/ .___/\___/\____/\__,_/\__/  Everything
        /_/                            

Done
In 10 seconds the device will reboot

10 9 8 7 6 5 4 3 2 1 0
Reboot

Note that there is a bug in the code: it starts wiping immediately then counts down, so for the higher levels it's very important to not touch the option at all :D It happened to us once and Phil had to reflash it.

-3- Generate good password.

as before

-4- Product information.

as before

Secret Keeper unlocked

*** Secret Keeper unlocked ***

-1- Change password.
-2- Retrieve secret information.
-3- Set secret information.
-4- Product information.

Choice:

-1- Change password.

didn't test

-2- Retrieve secret information.

(tested after setting secret with option 3)

Choice: 2
The secret store in your device is :

titi

Press ENTER to continue

-3- Set secret information.

Choice: 3
Enter your secret here. Up to 512 bytes can be stored.

titi

Your secret was stored successfully

-4- Product information.

as before


Secret Keeper level 1 (50 points)

"An Insomni'Hack 2018 tribute":
Was a 400 points at Insomni'hack and is only a 50 points at GreHack ... with the good tools ( Hello Baldanos :) )
Read the full package to understand how all the challenges works and ask to staff if any doubt.
Your first task is to dump the firmware and find the flag.
--> Use "Secret Keeper 1 / 2 (revision 1.00)"

The STM32F103C8T6 is an ARM Cortex-M3 MCU with 64 Kbytes Flash, 72 MHz CPU, motor control, USB and CAN.

We used the provided ST-LINK/V2 with

Note that there is also pystlink, but we didn't use it.

From the datasheet: "In other words, the Flash memory contents can be accessed starting from address 0x0000 0000 or 0x800 0000."

Dumping its flash is as easy as:

st-flash --reset read dump_v1.bin 0x8000000 0x10000

Followed by a thorough analysis of the firmware...

strings dump_v1.bin |grep GH18
GH18{ST-LINKorBOOTLOADERdumpALL}

Secret Keeper level 2 (100 points)

Now you have the firmware, great.
But something other is still valuable. You need to find it and dump it too.
--> Use "Secret Keeper 1 / 2 (revision 1.00)"

What else to dump? The SRAM!

The STM32F103C8T6 has 20kb of SRAM
From the datasheet: "The SRAM start address is 0x2000 0000."

st-flash --reset read dump_v1_sram.bin 0x20000000 0x2000
strings dump_v1_sram.bin |grep GH18
GH18{DumpRAMMatterForExploiting}

Secret Keeper level 3 (200 points)

Dump the revision 2.00 of the firmware.
--> Use "Secret Keeper 3 / 4 (revision 2.00)"

TODO

Secret Keeper level 4 (300 points)

Read the secret stored in the Secret Keeper.
--> Use "Secret Keeper 3 / 4 (revision 2.00)"

TODO

Secret Keeper level 5 (500 points)

Extract the firmware & read the secret.
--> Use "Secret Keeper 5 (revision 3.00)"

TODO

Secret Keeper level 6 (501 points)

Extract the firmware & read the secret from the Secret Keeper from the software bug-free version.
AKA the INSANE level.
--> Use the special "Secret Keeper" (revision 4.00), ask to the staff for it.

We didn't reach this level but from the previous challenge, we got all the source code and this rv4.00 seems indeed bug-free. Not sure there is a way besides things like fault injections...

Conclusions

Thanks a lot to @PagetPhil for these nice hardware-origented challenges!
We had a lot of fun trying to solve them :)