Spyke

Posts

cybersecurity·CybersecuritybyBrownie

Creating a Linux kernel panic CTF

Hi everyone! I was tasked to create few challenges for a CTF at my university as part of my bachelor thesis. The last challenge I should create is essentially about crashing a system, while another "monitoring" system is detecting if the other one is running, and if not it gives you a flag. The tasks are meant for 4th year high-school students, so nothing insane, but this one still should be at an "extreme" difficulty in regard to the experience high-school students could have.

Issue is, I have no prior experience in such exploitation, and I don't necessarily know where to start with this one. My idea was creating a custom vulnerable module/driver in the linux kernel, that the players would be tasked to somehow exploit (some kind of overflow I guess, so that it would trigger kernel panic). I suppose it could be something similar to this: https://nofilqasim.info/Making%20a%20Kernel%20CTF%20%28PUCon%2724%20pwn%20CTF%29/ , except I believe the author of this CTF made it as a privilege escalation task, which is not exactly what I desire.

I was wondering if anyone could give me some pointers or ideas on where to start with this, and if what I have described above might be too difficult for the students to exploit, and consequently for me to implement.

Thank you for any answers!

View original on lemmy.zip
20
fuck_ai·Fuck AIbyBrownie

Research in AI

I've been very fed up with AI for about past 6 months, completely started to boycott it, discuss it with people of all kinds of different views, and I found joy and pride once again in my own work.

But the world issues coming from AI, and even more so from the billionaires and empires behind it seem to further pile up to insane heights. I've been trying to learn more and more about it, and after my bachelor and masters I am considering pursuing phd and research surrounding AI, especially from the critical perspective, which seems to be deeply neglected in the research pov.

This is still a few years in the future, and lot could change, but I am curious what do people here think about pursuing such a thing, and if in current academic world it is even something that would be possible doing, given lot of the grants and funding of AI research comes from these companies that just want to gain even more power through it.

As I said, I am already trying to know as much as possible about it, but I would like to look more deeply into its impact on society, impact on students etc.

Do you think this would be a worthwile endevaour? And if not, where do you think I should be heading to make change about this while not completely starving to death?

View original on lemmy.zip
25

You reached the end