Saturday, December 12, 2020

Google CTF 2020 - writeonly

Stumbled across a writeup on the Google CTF 2020 event.  Found it interesting that although the team used pwntools, they made it over-complicated by writing the shellcode in C and then extracted the assembly code for the exploit injection.  Isn't it the whole point of using pwntools is to help you generate the shellcode assembly?

Anyway, I looked up the challenge and found source code for the challenge itself and an implementation of a clean (official?) exploit.  Here are the results of me playing with that code.  Changes include:

- modified the Dockerfile so I can run the challenge locally.  Used socat to expose the executable via port 1337 of the container

- as for the actual exploit, instead of doing a complete shellcode injection, I modified to code to just dump the flag file.

- this modification also avoided overwriting the child code with bunch of NOPs. It injects code precisely at the start of the infinite loop of the child thread (check_flag+0x8). This can be found by looking at the end of the disassembled code of the check_flag function:

 ...
 4022d9:       bf 01 00 00 00          mov    $0x1,%edi
 4022de:       e8 fd cf 04 00          callq  44f2e0 <__sleep>
 4022e3:       e9 52 ff ff ff          jmpq   40223a <check_flag+0x8>

 

- commands used to build the docker image, disassembling child's function, and running the exploit etc can be found in the Makefile

 

Detailed description of the challenge and complete source code available on github.




Friday, December 4, 2020

How (not) to add another dimension to a relational database table

This is just a rant. I am not going to mention the name of the software, ok?

So I was working on an open source project, trying to add a new feature to it. The software can display some questions in random order and allow user to enter answers. Say we have five questions, Question A to Question E, randomly shown and the user entered answers as such:


What is being displayed on screen...
QuestionsAnswers
Question BAnswer B
Question EAnswer E
Question DAnswer D
Question CAnswer C
Question AAnswer A


And here are the corresponding rows in database when user saved those answers:

What is being stored on db...
problem_idquestionanswer
1Question AAnswer B
2Question BAnswer E
3Question CAnswer D
4Question DAnswer C
5Question EAnswer A

Instead of using one row to store each question and answer pair, whoever wrote that code decided to utilize the "answer" column independently from other columns and store values in the order displayed on screen!!

They even included comments in the code:

# note that answers are stored in display order...

I mean... WTF!? How am I going to retrieve the data? Am I supposed to use the same random seed to see how questions are ordered on screen and match against the answers?


Sunday, November 29, 2020

A phono preamp

Here is my Muffy phono preamp and the matching power supply. They are not the offical PCBs though. The official online store was out of stock. So I downloaded the free (but older) design files and sent them to a PCB prototyping factory for printing. And yes, I picked white for the PCB color.

 



 

But the question is: I don't even own a turntable... why do I even bother to go all the way to have the PBCs printed, ordering all the resistors/capacitors/voltage regulators, and finally hunting down a suitable enclosure to house everything?   🙄

Monday, November 16, 2020

Retiring some of my PostgreSQL BuildFarm animals

To support the PostgreSQL community, I have been running multiple PostgreSQL BuildFarm animals since 2013. They run on my spare ARM SoC boards such as BeagleBone Black and Odroid C2.

Since the primary storage of these devices are micro SD cards, compiling programs on them put a heavy burden on the lifespan of the cards. Usually I needed to replace them every 2 years due to wearing.

Recently, two of the animals failed again, namely flier (AArch64 with clang) and mayfly (AArch64 with gcc).

I am thinking to retire these two. There are more and more people contributing to the BuildFarm running AARCH64 machines. Some of them are running on cloud machines / VMs and should provide better performance and stability. There seems to be immediate need to resurrect my AArch64 animals.

So instead of spending more $ on SD cards / external storage for my SoC boards, I will probably put my animals at rest.

RIP.

Saturday, January 11, 2020

ROCm with Ryzen 2200G

For reference, here is the output from running /opt/rocm/bin/rocminfo on Ryzen 2200G (with vega 8) after installing ROCm:


Wednesday, November 13, 2019

Compiling cloudflared for armv6

I have a Raspberry Pi 1 running pi-hole for ads filtering.  Recently I tried to configure it to use Cloudflare DNS-over-https but it isn't stable.  Not to mention that the latest "official" release of cloudflared is broken for Raspberry Pi.  So here are the steps to compile it on Raspberry Pi (Note that the build process will take 30+ minutes on RPi.  So you may want to cross-compile it on a PC instead.  Just change the env variable CGO_ENABLED to 0 in the build script.  It only takes a few seconds to compile on my Ryzen 2200G.  Compiling it on RPi is just for fun).

Preparation


We need golang 1.12 or later to compile cloudflared.  But the official go version on Raspbian is 1.7.  Use this to download golang 1.12.  Extract the content and take note of the path.

wget https://storage.googleapis.com/golang/go1.12.linux-armv6l.tar.gz

Also, the build process needs more than 1GB of memory.  You may want to create a temporary swap file:

sudo fallocate -l 1G swapfile

sudo dd if=/dev/zero of=swapfile bs=1M count=1024
sudo chmod 600 swapfile
sudo mkswap swapfile
sudo swapon swapfile


After building cloudflared, you can use "swapoff" to remove the temporary swap space and then delete the physical file.

Compiling

Here is the script to compile the cloudflared binary.  Save and run it under a working folder.  Edit the definition of the first two variables to point to the golang version you are using and the cloudflared version to compile.  If you are corss-compiling, change the "CC" environment to the cross compiler.

#!/bin/sh
set -e

# custom install version of go >= 1.12
GOLANG_PATH=$HOME/apps/go/bin
# which version to build
CLOUDFLARED_VERSION=2019.11.0

export GOPATH=$(pwd)
export GOOS=linux
export GOARCH=arm
export GOARM=6
export CGO_ENABLED=1
export CC=gcc
export PATH=${GOLANG_PATH}:$PATH
CLOUDFLARED_BUILDTIME=$(date)

go get -v github.com/cloudflare/cloudflared/cmd/cloudflared
cd src/github.com/cloudflare/cloudflared
git checkout tags/${CLOUDFLARED_VERSION}
cd ../../../../

go build -v "-ldflags=-X 'main.Version=${CLOUDFLARED_VERSION}' -X 'main.BuildTime=${CLOUDFLARED_BUILDTIME}'" github.com/cloudflare/cloudflared/cmd/cloudflared


Installation

Follow the instructions on pi-hole web site on how to configure pi-hole to use DNS-over-https

Saturday, May 4, 2019

Building Visual Studio Code on Jetson Nano

Here are the steps for building Visual Studio Code on Nvidia Jetson Nano.

Install nodejs

Visual Studio Code needs node version between 8 and 10. To install node 10 and yarn:

curl -sL https://deb.nodesource.com/setup_10.x | sudo -E bash -

sudo apt-get install -y nodejs

curl -sL https://dl.yarnpkg.com/debian/pubkey.gpg | sudo apt-key add -

echo "deb https://dl.yarnpkg.com/debian/ stable main" | sudo tee /etc/apt/sources.list.d/yarn.list

sudo apt-get update && sudo apt-get install yarn


Install libraries 

We also need some libraries:

sudo apt-get install libx11-dev libxkbfile-dev libsecret-1-dev 


Clone and build Visual Studio Code

In a working directory, clone the source code and build.

git clone https://github.com/microsoft/vscode

cd vscode

scripts/npm.sh install


Edit 2019-06-15: To enable extensions, edit the product.json file and add the following:

"extensionsGallery": {
  "serviceUrl": "https://marketplace.visualstudio.com/_apis/public/gallery",
  "cacheUrl": "https://vscode.blob.core.windows.net/gallery/index",
  "itemUrl": "https://marketplace.visualstudio.com/items"
}


To run Visual Studio Code:

scripts/code.sh

Friday, May 3, 2019

ROCm OpenCL with openSUSE Tumbleweed

EDIT 2022:

Follow the latest doc instead: https://docs.amd.com/bundle/ROCm-Installation-Guide-v5.4/page/How_to_Install_ROCm.html

EDIT 20200622:
With ROCm 3.5, the easiest way is to use zypper.

- Add repository:
sudo zypper addrepo --no-gpgcheck http://repo.radeon.com/rocm/zyp/zypper/ rocm
sudo zypper ref

- Install packages:
sudo zypper in rocm-opencl3.5.0 hsa-ext-rocr-dev3.5.0

- Update lib path (if necessary). ROCm 3.5 is installed under "/opt/rocm-3.5.x". Create a symbolic link "/opt/rocm -> /opt/rocm-3.5.1". Check the lib path in /etc/ld.so.conf.d and make sure these are listed

  - /opt/rocm/lib
  - /opt/rocm/lib64
  - /opt/rocm/hsa/lib
  - /opt/rocm/opencl/lib

If not, create a new file (e.g. rocm.conf) and add the above paths.  Then run "sudo ldconfig".

Run both "/usr/bin/clinfo" and "/opt/rocm/opencl/bin/clinfo" to check if OpenCL is working.



EDIT 20200110:
(0) As of 2020-01-05, running "clinfo" with openSUSE Tumbleeweed 20200103 and these  ROCm packages will cause null pointer dereference errors.
(0) Things are working again with Tumbleeweed 20200108.
(1) The user needs to be member of the "video" group.  Run this command to add yourself to the group "sudo usermod -a -G video $LOGNAME"
(2) The site now has RPM packages for openSUSE.  Go the http://repo.radeon.com/rocm/zyp/zypper/ to download the packages instead.  Also, no need to specify "--nodeps" when installing the packages

- - 8< - - -


With Tumbleweed running Linux kernel 5.0, it is easy to install ROCm OpenCL with upstream kernel.

- Go to http://repo.radeon.com/rocm/zyp/zypper/ and download the latest version of following packages:

hsakmt-roct
hsa-rocr-dev
rocm-opencl
rocm-opencl-devel
rocminfo-1.0.0

(EDIT 20200126) With ROCm 3.0, you also need to install these packages (due to an issue):
comgr
rocm-smi-lib64

- Install them without checking dependencies, assuming you already have libc etc packages installed, e.g.:

sudo rpm -ivh comgr-1.6.0.121-cbb02f9-Linux.rpm hsakmt-roct-1.0.9-319-g02e2b30.x86_64.rpm hsa-rocr-dev-1.1.30100.0-local-build-ecafeba1-Linux.rpm rocm-opencl-2.0.0--8f28d95ad-Linux.rpm rocm-opencl-devel-2.0.0--8f28d95ad-Linux.rpm rocm-smi-lib64-2.2.0.8.local-build-0-a246aac.rpm rocminfo-1.0.0.0.local_build-0-a134847.rpm

- That's it! Optionally, install clinfo with zypper to check the available platforms.  Or you can just use the one installed by rocminfo (under /opt/rocm*/bin). If you have been using Mesa OpenCL, you may want to uninstall it.

Saturday, April 20, 2019

OpenCL hangs with mesa-opencl and Radeon


OpenCL applications (e.g. clinfo and gimp etc) will hang when running under openSUSE Tumbleweed. This is with Mesa-libOpenCL 19.0.1 running on Radeon Sea Islands with amdgpu driver (radeon.cik_support=0 amdgpu.cik_support=1 amdgpu.dc=1).

Seems hitting this same bug.

EDIT: Fixed in Mesa 19.0.3.

Monday, March 25, 2019

NVIDIA Jetson Nano first impression

Just received my NVIDIA Jetson Nano developer kit today.  Here are my first impressions:

- the mounting holes on the board are tiny.  M3 pole won't fit.  The package does come with a paper (!) stand though

- the board is picky on the power supply.  Tried several USB chargers and the board will shutdown during boot.  Ended up using the barrel plug.  Needed to short jumper J48 to enable power supply via the barrel plug.

- during first boot, after configuring the keyboard etc, the machine froze when trying to login.  Needed to recycle the power.

- Need to manually install Tensorflow for python3 (this should install the CUDA accelerated Tensorflow)

- When trying to install scipy with pip3  (compiling from source), the heatsink was too hot to touch and the machine eventually locked up.  Needed to cycle the power to reboot.

- the cpuinfo:

- dmesg:

- lsusb (with keyboard and mouse attached):

- first successful login: