Jump to content
View in the app

A better way to browse. Learn more.

Tuts 4 You

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Featured Replies

On 03/10/2017 at 8:18 AM, Rurik said:

@satoshi The organizer gave a good hint on Twitter: 

  Reveal hidden contents

Take a look at the "REST APIs" like mentioned above, and the way this program deals with rand().

 

Thanks for the hint! I managed to solve it. That challenge was pretty tricky haha

  • Replies 62
  • Views 22.7k
  • Created
  • Last Reply

Top Posters In This Topic

Most Popular Posts

  • Suggestions:   I have seen a number of people doing something like this on twitter, am I doing it right?  

  • IIRC, if you check the input bounds, it'll take either a coordinate or a 16-byte string.

  • Let's put some links together... https://www.fireeye.com/blog/threat-research/2017/10/2017-flare-on-challenge-solutions.html - official solutions. https://lifeinhex.com/about-flare-2017/ - m

Posted Images

The challenge has ended. Congratulations everybody :D

So, is anybody going to write some full writeups or dump some of his notes/overviews/thoughts?
I'm always looking forward to these when a competition ends :)

Ok! This is my script for solve challenge 5 ... I used Binary Ninja, gdb inside a Linux VM ( just to know the the value of key used to decrypt the 1 level :)) and, ofc, python. 

5 challenge.7z

:/  That guy just scraped the FireEye web page and posted their results.

 

Good stuff on using Binary Ninja for #5, still reading through it. I just bought BN for fun, and trying to find situations where it would fare better than IDA.

I'll probably dump my notes and scripts to github here soon, after some clean-up.

Let's put some links together... :)

https://www.fireeye.com/blog/threat-research/2017/10/2017-flare-on-challenge-solutions.html - official solutions.

https://lifeinhex.com/about-flare-2017/ - my non-writeup. If I ever get bored find some free time, I'll make detailed tutorials about #11 and #12. 
http://www.rtcore.gq/2017/10/flare-on-2017.html - by @Etor Madiv

The remaining list comes from twitter feed:
https://www.securifera.com/blog/2017/10/16/flare-4-challenge-11-writeup/ by b0yd
http://irq5.io/2017/10/15/flare-on-2017-write-up-pewpewboat-exe/ by darell tan aka zxcvgm
http://www.bulbafett.com/index.php/2017/10/12/2017-flare-on-write-up/ by bulbafett
https://theromanxpl0it.github.io/articles/flareon2017/ by dp1
https://github.com/L4ys/CTF/tree/master/flareon4 by _L4ys
https://blahcat.github.io/2017/10/13/flareon-4-writeups/ by _blahcat_
 

If you notice more writeups, please post links, preferrably direct ones (no t.co/whatever crap!) ;)

 

I don't do write-ups anymore as much as I do rambling sets of notes and raw scripts, but I've been slowly pushing mine up.  Will clean-up over time.

https://github.com/Rurik/CTF/tree/master/FLARE_2017

@Rurik: epic tweet! :D

 

@kao Am I wrong? :D

We knew what we were signing up for, based on the prior three years. Last year took the most out of me, mentally. This year not as bad, but close, but it took a very long time. Just need to reverse faster.
Or maybe the wife has high standards of prizes from the Szechuan sauce and Lego David Bowie from LabyREnth :D

  • The title was changed to Flare-On 4

Create an account or sign in to comment

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.