Setting up a WireGuard VPN on a Raspberry Pi

I used to run Synology’s built-in OpenVPN Server. I had a spare Raspberry Pi lying around and figured I’d stand up another VPN server and play with WireGuard at the same time. After trying it out, the speed, configuration and chaining to an internal DNS server all worked without issue, so I’ll probably make it my main connection method going forward. Raspberry Pi Setting Flash lite x64 with the official tool and drop in an ssh file so the SSH server starts automatically: ...

April 3, 2022

Airpods Pro and WF-1000XM4

I won a pair of WF-1000XM4 in a Christmas raffle a while back, so here is a quick comparison with the Airpods Pro. Because of its ear tips, the WF-1000XM4 sometimes gives the sensation that the noise cancelling drops out for a moment during certain activities. For example when working out or yawning, but swapping in a third-party silicone ear tip should fix it. The WF-1000XM4 presses fairly hard against the contour of the ear; for me the Airpods Pro is more comfortable. ...

January 14, 2022

Scoop install list

Just noting down my install list, used with PowerShell 7+. scoop is an installer for Windows, a bit like brew on macOS, with PowerShell as its backend. There are also many buckets you can add: scoop bucket add nerd-fonts scoop bucket add extras scoop bucket add sysinternals You can also use the online package search to see whether what you need is available. Productivity Tools firefox 95.0.2 draw.io - handy for diagrams vlc 7zip anydesk teamviewer obs-studio keepassxc - password manager marktext - markdown editor snipaste - screenshot tool megasync Command Tools sudo - run with administrator privileges on Windows curl netcat wget ag - great search tool croc - handy for transferring files speedtest-cli - for the occasional idle test file bat busybox - adds a lot of extra linux commands cloc - count files by type grep less hexyl - view hex upx ttyd strings neovim Security Tools gobuster yara x64dbg - debugger pe-bear sysinternals - Microsoft’s big toolkit collection processhacker detect-it-easy process-explorer Font Font nerd? ...

January 12, 2022

ASRock IPMI reset

I bought a used ASRock server motherboard online and wanted to use its IPMI feature, but the password had already been changed, so I looked online for a way to reset it. First, boot into any Windows install and download Supermicro’s IPMICFG tool: https://www.supermicro.com/SwDownload/SwSelect_Free.aspx?cat=IPMI ipmicfg -user list Maximum number of Users : 10 Count of currently enabled Users : 1 User ID | User Name | Privilege Level | Enable --------|-----------|-----------------|------- 2 | admin | Administrator | Yes ipmicfg -user setpwd 2 admin Or reset it to factory defaults: ...

September 5, 2020

Use TTL to unbrick router

I once bricked a router while reflashing it. Using an FT232 adapter you can open the router’s case and hook up to the RS232 pads on the board — connecting GND, TX and RX to the computer lets you issue commands directly and even drop into a system shell. Use PuTTY to connect to the FT232’s COM port. As for the pinout on the router board, you can look it up in the DD-WRT or OpenWRT wiki; reference material is available for almost every router. ...

August 17, 2018

How to pwnable

Updated over time~ website, doc and video https://ctf-wiki.github.io/ctf-wiki LiveOverflow youtube channel https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w http://liveoverflow.com/binary_hacking/protostar/index.html Heap techniques summary https://github.com/shellphish/how2heap A series of slides by a Japanese competitor http://www.slideshare.net/bata_24/presentations 杨坤:掘金CTF ——CTF中的内存漏洞利用技巧 http://netsec.ccert.edu.cn/wp-content/uploads/2015/10/2015-1029-yangkun-Gold-Mining-CTF.pdf Modern Binary Exploitation by RPISEC http://security.cs.rpi.edu/courses/binexp-spring2015/ https://github.com/RPISEC/MBE https://raintrees.net/projects/a-painter-and-a-black-cat/wiki/CTF_Pwn exploit techniques compiled by inaz2 http://inaz2.hatenablog.com/archive/category/Exploit?page=1 http://inaz2.hatenablog.com/archive/category/Exploit?page=2 http://j00ru.vexillium.org/blog/24_03_15/dragons_ctf.pdf https://github.com/str4tan/pwning Heap: https://github.com/cloudburst/libheap https://github.com/DhavalKapil/libdheap https://github.com/degrigis/Heapy https://github.com/shellphish/how2heap wargame and ctf https://pwnable.tw/ http://pwnable.kr/ https://bamboofox.cs.nctu.edu.tw/ http://overthewire.org/wargames/ https://w3challs.com/ https://exploit-exercises.com/nebula/ http://ctf.katsudon.org/ http://ctf.katsudon.org/ctf4u/ tools debug ...

January 9, 2018

Some environment notes

Notes on my environment; I’ll update with anything I missed later. Fonts Monospace fonts monaco sourcecode pro Bitstream Vera Sans Mono ubuntu mono Hardware I set up a home server running Debian; total power draw stays under 30 watts — very power-efficient, great value!!! The only downside is there are only 2 SATA connectors and the motherboard doesn’t support RAID. mb:asus N3150M-E ram:8G storage:120G SSD + 1T Keyboard Ducky One 80% with brown switches; I swapped in PBT keycaps. PBT feels a bit powdery to the touch, and I bought ones that are easy to clean, at Cherry OEM profile height. It felt OEM at first but I got used to it after a few days. ...

August 5, 2016

Return Oriented Programming

Some notes. Tools for finding gadgets rp++ ROPgadget Ret2libc When the program has NX enabled, shellcode on the stack can’t execute; you can use ret2libc, or use ROP to call mprotect and open an rwx segment. Passing arguments x86 via the stack x86_64 via registers Ret2libc stack layout Stack the arguments as completely as possible to avoid annoying issues. The usual x86 layout is: padding + function + ret address + argv1 + argv2 + argv3 .... The function can usually jump straight to .plt; the ret address is where you want to go after it finishes. If you’re just building system("/bin/sh"), the ret address can be left blank. ...

May 31, 2016

TU CTF - Where Heretics Suffer

When I got this challenge it was already a binary, compiled with a newer gcc that has some new mechanisms for function calls, as follows: 80485cb: 8d 4c 24 04 lea ecx,[esp+0x4] 80485cf: 83 e4 f0 and esp,0xfffffff0 80485d2: ff 71 fc push DWORD PTR [ecx-0x4] 80485d5: 55 push ebp 80485d6: 89 e5 mov ebp,esp 80485d8: 51 push ecx 80485d9: 83 ec 34 sub esp,0x34 ...... 8048682: b8 00 00 00 00 mov eax,0x0 8048687: 8b 4d fc mov ecx,DWORD PTR [ebp-0x4] 804868a: c9 leave 804868b: 8d 61 fc lea esp,[ecx-0x4] 804868e: c3 ret You can see that during setup, lea ecx,[esp+0x4] puts the value of esp into ecx, then pushes ecx onto the stack; after we overflow, we also overwrite that original value. ...

May 21, 2016

Install qira on rpi

Comment out the capstone section inside install.sh, then run it. Download capstone: git clone https://github.com/aquynh/capstone.git $ ./make.sh $ sudo ./make.sh install

March 16, 2016