Reverse engineering a custom CPU from a single program
robertxiao.ca
robertxiao.ca
We used the publicly available bootcode.bin and loader.bin to RE most of the ISA before the Pis even started shipping, though there were some more obscure instructions that we weren't sure about until we could run our own code.
But when my pi did arrive, we knew enough to write a binary that would blink an LED on more-or-less the first attempt.
I guess the real lesson, custom ISAs are not a good form of security.
And that’s just the easy first version. XOR with a hash of the address, swap bits across entire cache lines when loading each cache line in the instruction cache, etc.
Such mechanisms even would be fairly secure if the attacker has access to the machine code of a JITter. The attacker would have to crack the encryption to understand what the JITter does.
An internal API which people reverse engineer and use is just going to lead to hassles later when you want to change the API, when people start writing bots or abuse the API in ways you hadn't imagined, or expose bugs in the API the official client didn't.
[0] https://safiire.github.io/blog/2017/08/19/solving-danish-def...
Just a consideration: aren't the names of these persons "principally" known (at least if you are willing to do some investigations) if you are a company/government agency that has an interest in them?
Some names will be popular through fame or common channels, but you'll never get a full list. Especially RE when some of their activities aren't legal and they don't want to be found.
I have trouble believing that if you don't want to be found, you will participate in a reverse-engineering competition with your real-life identity.
I (and I know quite some programmers who think the same) really hate it when for piquing my interest some fancy puzzle/problem is presented, but the real work that is to be done has nothing to do with the marketing. I don't believe that such kind of "false advertising" is a smart way to retain talent.
If I wanted to attract talent, I would rather put some problems on the company website that are really related to problems that occur(ed) in such a job position to attract talent that exactly loves the kind of problems that likely does occur at the job position that I want to fill.
[0] https://opentechlab.org.uk/
[1] https://github.com/v3l0c1r4pt0r/lkv-wiki/wiki/Instruction-Se...
Usually out of pride or the sunk cost fallacy (or something like it) I'll convince myself there was no other way the problem was going to be solved. Either way the next time around I spend just a little bit longer trying to think of an easy way out.
Being a CTF challenge, I'm surprised that they didn't settle on something decidedly more rude ;) I wonder if the organizers can release their assembler for the architecture, or a spec at least…