Exploit Linux Machines Through Fun Challenges
exploit-exercises.com
exploit-exercises.com
* I recently came across a computer security course which used CTF virtual machines for an assignment (you can download the VM and see how you do against Tufts University students): http://www.cs.tufts.edu/comp/116/assignments/a04.php
* Offensive Security's "Penetration Testing with BackTrack" (PWB) course uses a series of CTF challenges as the final exam.
* Any recommendations on any encryption challenges in this style?
We are seeing a return to the old guild system of masterpieces as proof of ability and learning aid. I couldn't be happier. I'd love to see a mash up between stackoverflow's gamification and Offensive Security certification/teaching process.
Whenever I have tried to write code in the C to be deliberately vulnerable and have tried to overwrite memory etc it never seems to work in the way I expect.
For example I will have two arrays that are contiguous in memory (checking this with gdb) and I will then write a big set of values into one array that should overflow into the other. Then try and do something like print the values that should have been overflowed into but I often find I either get a segfault or that the values that are printed are actually the correct values assigned the the array that should be overwritten.
I haven't tried these specific puzzles with the VMs though. I always do -fno-stack-protector when compiling but I don't know if there is some other security mechanism that could be stopping it from working?
Also, be sure to turn off Write^Execute memory pages and ASLR as another commenter has suggested.
Alternatively, you could try your hand at defeating these protection mechanisms yourself with a number of (relatively) newfangled techniques.
JITSpray - http://dsecrg.com/pages/pub/show.php?id=22 ROP - http://cseweb.ucsd.edu/~hovav/talks/blackhat08.html
and more!