Microcorruption – Embedded Security CTF
microcorruption.com
microcorruption.com
I wrote the kernel of Microcorruption (the emulator and the basic web interface) as a "hack night" challenge for our team at Matasano. When we couldn't get people to leave the office at 1:00AM that night, I decided we should probably run it as an open CTF. I got Square to re-skin the interface and teammates Hans and Nicholas (one of our absurdly overqualified interns) to spend 6 months revamping the levels, and there you have it.
(Aside: I once asked Greg Brockman, then at Stripe, why Stripe's CTFs always ended so quickly. Why would you ever take one of these things down, I wondered? Greg told me I'd understand after a week of running it. So far as I know, the only things that have ever caused problems for the Microcorruption deployment were due to the log filesystem filling up.)
Anyways.
I left Matasano a year and a half ago to start Starfighter, a company based on these kinds of games. Matasano used Microcorruption to do recruiting, but we got so many qualified leads from it that it was sort of a waste to ever do another one there.
As luck would have it, we just last week opened the beta test for Starfighter's Microcorruption-style CTF. It's called Jailbreak. Here are the change bars (design-wise; the two CTFs share no code):
- Jailbreak is AVR and Microcorruption is MSP430. AVR is much more... interesting... to do memory corruption on.
- Jailbreak includes a compiler (we compile both to AVR in later levels and to a bytecode VM that runs out of the emulator's dmem, and escaping that interpreter is the goal of several levels). Microcorruption was just GCC.
- Jailbreak is multiple cores, and connects to the market we use for the Trading CTF we did in January. All the cores in Jailbreak are event-driven; they "run" "constantly", and respond to network events. Microcorruption sort-of kind-of rebooted with every user input.
We're beta-testing the "trainer" for Jailbreak right now, and I expect it to be open to the public on Tuesday or Wednesday of next week (we'll open it up when the beta testers clear all the levels, which hasn't happened yet, which is due mostly to very bad documentation and lots of balance problems, which is why we beta test these things). The trainer is 10 levels that are very similar in style to Microcorruption; the full CTF will probably be out in early-mid July.
I'm supposed to be writing my thesis but can't wait to get back to the game. Will sign up for Jailbreak too.
What resources should I consult when I get stuck? This line of work might be something I'm interested in for real.
Generally, the most important advice I can give is: have a clear distinction between public CTFs, which are outreach mechanisms, and work-sample challenges, which are qualifiers. Don't qualify candidates with CTFs! Use CTFs to organically pull in the sorts of developers who tend to qualify well --- and, ideally, use work-sample challenges for all or most of that qualification.
I'm eagerly awaiting Starfighter's analogous exploit tech path, since it's by the same person (people?)
In the meantime, I've done quite a lot of CTFs, reverse engineering, binary exploitation etc. I tried again yesterday, and I'm already up to "Algiers". I guess that just goes to show that it isn't really suitable for absolute beginners like I was, unless you're very perseverant.
I understand Square/Matasano ran it to hire people at the time - could anyone tell me if having completed it means I can be considered able to do a job in the field, and someone worth hiring? Or is the CTF just an introduction to the field? I have been doing a lot of learning since, and understand there is a vast (and endlessly fascinating) amount to learn beyond what's in the CTF - but what level do I need to be at before I consider applying for jobs? I remember reading that Matasano used to send candidates books to read and learn from as part of the interview process (which just sounds like my dream company) - as someone who would happily learn whatever it takes during the interview process and on the job, what level do I need to be at before I even consider applying?
* Penetration Tester
* Security Engineer
Those should bring up quite a few results.
(Might be worth stating if in fact you've finished the CTF challenge; otherwise, what makes you sure this is the case?)
Spend enough time learning the instruction set and the concepts involved and the answers will become apparent.
Honestly really isn't for myself, but based on experience teaching a wide variety of people, that some people learn different ways and are more willing to take something new on if they feel they won't break "it" (which is what the website does) and feel there's a built-in for getting to done. Most users get that connect the dots isn't the same as DIY, but still a option that helps some users that would have never tried, but were interested in the topic. Thanks for commenting.