Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
hcon2026hwctf — 硬件黑客CTF hcon2026hwctf - RISCV Hazard3(@Wren6991)由@b1n4ri0 @antoniovazquezblanco和@therealdreg利用 | Kitploit
工具/GitHubGitHub/therealdreg/hcon2026hwctf
嵌入式系统安全漏洞利用逆向工程硬件黑客CTF学习与教育固件分析二进制利用实验室与实践
GitHubtherealdreg/hcon2026hwctf

hcon2026hwctf

硬件黑客CTF hcon2026hwctf - RISCV Hazard3(@Wren6991)由@b1n4ri0 @antoniovazquezblanco和@therealdreg利用

252245个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库网站

硬件黑客 CTF hcon2026hwctf

如果你对硬件 CTF 感兴趣,这里是 HC0N CTF 2026 的第一个公开挑战,包含 RISC-V RP2350 利用挑战(底层)。

我们尽量让挑战不那么精英化或难度过高,以便数百名参会者有机会解决这些挑战。希望我们做到了。


如果你想在家运行这个 CTF,拿一块 Raspberry Pi Pico 2,刷入这个固件,并且不要看 write-up! -> ctf.uf2

给使用与 CTF 不同板子(RP2350/RP2354...)的人:
CTF PCB 在 GPIO 25 上有一个 SMD LED,你必须在该 GPIO 上连接一个 LED

LED25


完成这个 CTF 后,如果你喜欢,这里有另一个类似但挑战不同的:https://github.com/therealdreg/ctfhardwarehackingcon2026

Write-ups

警告:以下 write-ups 包含挑战的剧透。如果你想自己解决,建议在完成 CTF 之前不要阅读。

第一名 获胜者:@mrexodia (Duncan Ogilvie) writeups/first_winner.md

mrexeodia

奖品:okhi hardware keylogger USB/PS2 kit + CWP (Certified WifiChallenge Professional) https://github.com/therealdreg/okhi


第二名 获胜者:@M3RINOOOOO (Cristobal Merino Saez) writeups/second_winner.md

m3rino

奖品:Pimoroni PGA2350, PICO2 WH, Pimoroni PICO PLUS 2W, PICO2 H, CWP (Certified WifiChallenge Professional)


第三名 获胜者:@p4bl0vx (Pablo Moya Lopez) writeups/third_winner.md

p4bl0vx

奖品:Pimoroni PGA2350, PICO2 WH, Pimoroni PICO PLUS 2W, CWP (Certified WifiChallenge Professional).

提示与技巧 by @b1n4ri0 @antoniovazquezblanco & @therealdreg

这里我们提供一些帮助,让 HCON 2026 的硬件黑客 CTF 更简单。

https://www.h-c0n.com

boardphoto

操作系统

Linux 主机应该是你的首选 ;-),调试效果更好。

串口配置

TeraTerm: Setup -> Terminal -> Transmit: CR+LF & [x] Local echo

其他:

  • Transmit: CR+LF
  • Local echo
  • RTS
  • DTR

Linux 下的 GUI

cutecom:``` sudo apt-get update sudo apt-get install cutecom

# 警告

其中一项挑战需要硬件调试。如果你在家独立完成挑战(没有队友拥有另一块板子),那么要解决该挑战,你还需要购买以下两件物品。(如果不购买也没关系——但你将无法解决那个特定的挑战。)

- https://www.tiendatec.es/raspberry-pi-pico/2025-raspberry-pi-debug-probe-5056561803265.html
- https://www.tiendatec.es/raspberry-pi-pico/1979-cable-depuracion-pico-jtag-jst-sh-1-0-a-dupont-hembra-15cm-8472496024846.html

# 关于脚本

本仓库中的工具由 @b1n4ri0 为社区开发,特别针对 2026 年 HCON 硬件破解挑战赛而设计。

# 利用带有调试功能的 RP2350 RISCV Hazard3 (@Wren6991) 三级流水线 RV32IMACZb* 处理器

RISCV Hazard3 是一款支持调试的三级流水线 RV32IMACZb* 处理器,用于 HCON2026HWCTF 开发板上的 RP2350 微控制器。

# 使用 picotool 转储 RISCV Hazard3 固件

使用 `picotool` 从 RP2350 设备转储固件是一个直接了当的过程。在本节中,你将学习如何高效地完成此操作。

注意:`picotool` 仅在 RP2350(及 RP2040)设备处于 BOOTSEL 模式或运行中的固件包含来自 Pico SDK 的 USB stdio 支持时才能与之交互。

## 构建 picotool

通过你喜欢的包管理器安装必要的构建工具和库。```bash
sudo apt-get update
sudo apt install build-essential pkg-config libusb-1.0-0-dev cmake -y

创建一个专用目录来组织你的工具。这确保后续步骤中使用的路径是正确的。```bash cd $HOME mkdir rptools cd rptools

克隆 `picotool` 和 `pico-sdk` 项目,我们需要工具本身和 SDK。注意,`picotool` 需要 `pico-sdk` 才能正确编译。```bash
git clone https://github.com/raspberrypi/picotool.git
git clone https://github.com/raspberrypi/pico-sdk.git
cd picotool

创建构建目录并运行CMake。

重要提示:我们必须使用 -DPICO_SDK_PATH 标志来告诉CMake在上一步中下载SDK的具体位置,或者我们可以在环境变量中设置 PICO_SDK_PATH。```bash mkdir build cd build cmake -DPICO_SDK_PATH=$HOME/rptools/pico-sdk .. sudo make install

默认情况下,访问 USB 设备需要 root 权限。复制 udev 规则文件以允许在不使用 `sudo` 的情况下运行 `picotool`。```bash
sudo cp ../udev/60-picotool.rules /etc/udev/rules.d/ 

重新加载 udev 规则(或拔下并重新插入您的设备),然后运行 picotool version 检查版本,以确保一切正常工作:```bash $ ./picotool version picotool v2.2.0-a4 (Linux, GNU-15.2.0, Release)

## 使用预编译的二进制文件

如果您希望跳过构建过程,可以从[官方仓库](https://github.com/raspberrypi/pico-sdk-tools/releases)下载预编译的二进制文件。```bash
gunzip picotool-2.2.0-a4-x86_64-lin.tar.gz
tar -xf picotool-2.2.0-a4-x86_64-lin.tar
cd picotool

运行 picotool version 应该按预期工作:```bash $ ./picotool version picotool v2.2.0-a4 (Linux, GNU-11.4.0, Release)

## 在RP2350上启用BOOTSEL模式

要执行诸如转储固件之类的操作,`picotool` 要求设备处于BOOTSEL模式。但是,如果当前运行的固件包含Pico SDK中的USB stdio支持,`picotool` 也可以与该设备交互。

下面,我将介绍几种激活此模式的方法。选择最适用于你的情况的方法,或者直接选择对你有用的方法。

如果你的板卡**未处于BOOTSEL模式**,但包含USB stdio支持,那么在尝试执行 `picotool` 命令时,你会看到类似如下的输出:```bash
$ ./picotool info
No accessible RP-series devices in BOOTSEL mode were found.

but:

RP2350 device at bus 1, address 23 appears to have a USB serial connection, so consider -f (or -F) to force reboot in order to run the command.

物理启用 BOOTSEL

这是使用的标准硬件方法:

  1. 从计算机上拔下 RP2350 开发板。
  2. 按住 BOOTSEL 或 BOOT 按钮。
  3. 按住按钮的同时,将开发板重新插入计算机。
  4. 松开 BOOTSEL 按钮。

替代方法(如果您不想拔下开发板):

  1. 按住 BOOTSEL 按钮。
  2. 按下并松开 RESET 或 RST 按钮。
  3. 松开 BOOTSEL。

现在您应该能够执行 picotool 命令:```bash $ ./picotool info Program Information name: hello_usb features: USB stdin / stdout binary start: 0x10000000 binary end: 0x10011d50 target chip: RP2350 image type: RISC-V

### 软件启用 BOOTSEL

如果设备固件正在运行并且支持 USB stdio,你可以强制将其进入 BOOTSEL 模式,而无需触碰开发板。```bash
./picotool reboot -uf

该命令使用 -u 标志指定要重启到 BOOTSEL 模式。然而,由于设备当前正在执行用户代码,picotool 默认会忽略该请求。因此,我们必须附加 -f 标志,强制正在运行的应用程序接受重置命令。

如果没有 -f,操作将失败,因为该工具期望设备已经处于 BOOTSEL 模式。```bash $ ./picotool info Program Information name: hello_usb features: USB stdin / stdout binary start: 0x10000000 binary end: 0x10011d50 target chip: RP2350 image type: RISC-V

**提示:** 您可以通过在命令后附加 `-f` 标志,直接在运行中的设备上执行命令,无需先手动重启。`picotool` 将处理重启、执行命令,然后重新启动回到应用程序。```bash
$ ./picotool info -f
Tracking device serial number XXXXXXXXXXXXXXXX for reboot
The device was asked to reboot into BOOTSEL mode so the command can be executed.

Program Information
 name:          hello_usb
 features:      USB stdin / stdout
 binary start:  0x10000000
 binary end:    0x10011d50
 target chip:   RP2350
 image type:    RISC-V

The device was asked to reboot back into application mode.

转储 RP2350 固件

对于这个CTF挑战,我们可以直接在未进入BOOTSEL模式的情况下提取固件。

我建议收集有关正在运行的程序的信息。你可以使用 info 命令来实现,该命令默认显示“程序信息”部分。由于设备当前正在运行代码,我们添加 -f 标志以强制连接。```bash $ ./picotool info -f Tracking device serial number XXXXXXXXXXXXXXXX for reboot The device was asked to reboot into BOOTSEL mode so the command can be executed.

Program Information name: hello_usb features: USB stdin / stdout binary start: 0x10000000 binary end: 0x10011d50 target chip: RP2350 image type: RISC-V

The device was asked to reboot back into application mode.

该输出揭示了关键细节,例如程序名称、其内存范围以及映像架构。

现在,我们继续提取程序,创建一个目录来存储提取出的文件。```bash
mkdir -p $HOME/hcon2026hwctf/

运行以下命令以提取固件:```bash ./picotool save -pvf -t bin $HOME/hcon2026hwctf/hello_usb.bin

这个单一命令处理整个提取过程。它会强制 RP2350 重启进入 BOOTSEL 模式,从闪存读取当前安装的程序,并将其保存为原始二进制文件。为确保提取正确,它会读取数据以验证转储的文件与芯片上的内容完全一致。

你应该会得到类似这样的输出:```bash
$ ./picotool save -pvf -t bin $HOME/hcon2026hwctf/hello_usb.bin
Tracking device serial number XXXXXXXXXXXXXXXX for reboot
The device was asked to reboot into BOOTSEL mode so the command can be executed.

Saving file:          [==============================]  100%
Wrote 73040 bytes to /home/b1n4ri0/hcon2026hwctf/hello_usb.bin
Verifying Flash:      [==============================]  100%
  OK

The device was asked to reboot back into application mode.

就是这样,你已经成功转储了程序!

注意:请记住,你只提取了已安装的程序,而非闪存中的全部内容。

如果遇到错误,请确认设备连接正确。若自动重启失败,请手动进入 BOOTSEL 模式,并在不使用 -f 标志的情况下重新运行命令。有关可用选项的更多信息,只需运行 picotool help <command>。

使用 Ghidra 逆向分析 RISC-V Hazard3 固件

下载工具