如果你对硬件 CTF 感兴趣,这里是 HC0N CTF 2026 的第一个公开挑战,包含 RISC-V RP2350 利用挑战(底层)。
我们尽量让挑战不那么精英化或难度过高,以便数百名参会者有机会解决这些挑战。希望我们做到了。
如果你想在家运行这个 CTF,拿一块 Raspberry Pi Pico 2,刷入这个固件,并且不要看 write-up! -> ctf.uf2
给使用与 CTF 不同板子(RP2350/RP2354...)的人:
CTF PCB 在 GPIO 25 上有一个 SMD LED,你必须在该 GPIO 上连接一个 LED

完成这个 CTF 后,如果你喜欢,这里有另一个类似但挑战不同的:https://github.com/therealdreg/ctfhardwarehackingcon2026
警告:以下 write-ups 包含挑战的剧透。如果你想自己解决,建议在完成 CTF 之前不要阅读。
第一名 获胜者:@mrexodia (Duncan Ogilvie) writeups/first_winner.md

奖品:okhi hardware keylogger USB/PS2 kit + CWP (Certified WifiChallenge Professional) https://github.com/therealdreg/okhi
第二名 获胜者:@M3RINOOOOO (Cristobal Merino Saez) writeups/second_winner.md

奖品:Pimoroni PGA2350, PICO2 WH, Pimoroni PICO PLUS 2W, PICO2 H, CWP (Certified WifiChallenge Professional)
第三名 获胜者:@p4bl0vx (Pablo Moya Lopez) writeups/third_winner.md

奖品:Pimoroni PGA2350, PICO2 WH, Pimoroni PICO PLUS 2W, CWP (Certified WifiChallenge Professional).
这里我们提供一些帮助,让 HCON 2026 的硬件黑客 CTF 更简单。

Linux 主机应该是你的首选 ;-),调试效果更好。
TeraTerm: Setup -> Terminal -> Transmit: CR+LF & [x] Local echo

其他:
cutecom:``` sudo apt-get update sudo apt-get install cutecom
# 警告
其中一项挑战需要硬件调试。如果你在家独立完成挑战(没有队友拥有另一块板子),那么要解决该挑战,你还需要购买以下两件物品。(如果不购买也没关系——但你将无法解决那个特定的挑战。)
- https://www.tiendatec.es/raspberry-pi-pico/2025-raspberry-pi-debug-probe-5056561803265.html
- https://www.tiendatec.es/raspberry-pi-pico/1979-cable-depuracion-pico-jtag-jst-sh-1-0-a-dupont-hembra-15cm-8472496024846.html
# 关于脚本
本仓库中的工具由 @b1n4ri0 为社区开发,特别针对 2026 年 HCON 硬件破解挑战赛而设计。
# 利用带有调试功能的 RP2350 RISCV Hazard3 (@Wren6991) 三级流水线 RV32IMACZb* 处理器
RISCV Hazard3 是一款支持调试的三级流水线 RV32IMACZb* 处理器,用于 HCON2026HWCTF 开发板上的 RP2350 微控制器。
# 使用 picotool 转储 RISCV Hazard3 固件
使用 `picotool` 从 RP2350 设备转储固件是一个直接了当的过程。在本节中,你将学习如何高效地完成此操作。
注意:`picotool` 仅在 RP2350(及 RP2040)设备处于 BOOTSEL 模式或运行中的固件包含来自 Pico SDK 的 USB stdio 支持时才能与之交互。
## 构建 picotool
通过你喜欢的包管理器安装必要的构建工具和库。```bash
sudo apt-get update
sudo apt install build-essential pkg-config libusb-1.0-0-dev cmake -y
创建一个专用目录来组织你的工具。这确保后续步骤中使用的路径是正确的。```bash cd $HOME mkdir rptools cd rptools
克隆 `picotool` 和 `pico-sdk` 项目,我们需要工具本身和 SDK。注意,`picotool` 需要 `pico-sdk` 才能正确编译。```bash
git clone https://github.com/raspberrypi/picotool.git
git clone https://github.com/raspberrypi/pico-sdk.git
cd picotool
创建构建目录并运行CMake。
重要提示:我们必须使用 -DPICO_SDK_PATH 标志来告诉CMake在上一步中下载SDK的具体位置,或者我们可以在环境变量中设置 PICO_SDK_PATH。```bash
mkdir build
cd build
cmake -DPICO_SDK_PATH=$HOME/rptools/pico-sdk ..
sudo make install
默认情况下,访问 USB 设备需要 root 权限。复制 udev 规则文件以允许在不使用 `sudo` 的情况下运行 `picotool`。```bash
sudo cp ../udev/60-picotool.rules /etc/udev/rules.d/
重新加载 udev 规则(或拔下并重新插入您的设备),然后运行 picotool version 检查版本,以确保一切正常工作:```bash
$ ./picotool version
picotool v2.2.0-a4 (Linux, GNU-15.2.0, Release)
## 使用预编译的二进制文件
如果您希望跳过构建过程,可以从[官方仓库](https://github.com/raspberrypi/pico-sdk-tools/releases)下载预编译的二进制文件。```bash
gunzip picotool-2.2.0-a4-x86_64-lin.tar.gz
tar -xf picotool-2.2.0-a4-x86_64-lin.tar
cd picotool
运行 picotool version 应该按预期工作:```bash
$ ./picotool version
picotool v2.2.0-a4 (Linux, GNU-11.4.0, Release)
## 在RP2350上启用BOOTSEL模式
要执行诸如转储固件之类的操作,`picotool` 要求设备处于BOOTSEL模式。但是,如果当前运行的固件包含Pico SDK中的USB stdio支持,`picotool` 也可以与该设备交互。
下面,我将介绍几种激活此模式的方法。选择最适用于你的情况的方法,或者直接选择对你有用的方法。
如果你的板卡**未处于BOOTSEL模式**,但包含USB stdio支持,那么在尝试执行 `picotool` 命令时,你会看到类似如下的输出:```bash
$ ./picotool info
No accessible RP-series devices in BOOTSEL mode were found.
but:
RP2350 device at bus 1, address 23 appears to have a USB serial connection, so consider -f (or -F) to force reboot in order to run the command.
这是使用的标准硬件方法:
BOOTSEL 或 BOOT 按钮。BOOTSEL 按钮。替代方法(如果您不想拔下开发板):
BOOTSEL 按钮。RESET 或 RST 按钮。BOOTSEL。现在您应该能够执行 picotool 命令:```bash
$ ./picotool info
Program Information
name: hello_usb
features: USB stdin / stdout
binary start: 0x10000000
binary end: 0x10011d50
target chip: RP2350
image type: RISC-V
### 软件启用 BOOTSEL
如果设备固件正在运行并且支持 USB stdio,你可以强制将其进入 BOOTSEL 模式,而无需触碰开发板。```bash
./picotool reboot -uf
该命令使用 -u 标志指定要重启到 BOOTSEL 模式。然而,由于设备当前正在执行用户代码,picotool 默认会忽略该请求。因此,我们必须附加 -f 标志,强制正在运行的应用程序接受重置命令。
如果没有 -f,操作将失败,因为该工具期望设备已经处于 BOOTSEL 模式。```bash
$ ./picotool info
Program Information
name: hello_usb
features: USB stdin / stdout
binary start: 0x10000000
binary end: 0x10011d50
target chip: RP2350
image type: RISC-V
**提示:** 您可以通过在命令后附加 `-f` 标志,直接在运行中的设备上执行命令,无需先手动重启。`picotool` 将处理重启、执行命令,然后重新启动回到应用程序。```bash
$ ./picotool info -f
Tracking device serial number XXXXXXXXXXXXXXXX for reboot
The device was asked to reboot into BOOTSEL mode so the command can be executed.
Program Information
name: hello_usb
features: USB stdin / stdout
binary start: 0x10000000
binary end: 0x10011d50
target chip: RP2350
image type: RISC-V
The device was asked to reboot back into application mode.
对于这个CTF挑战,我们可以直接在未进入BOOTSEL模式的情况下提取固件。
我建议收集有关正在运行的程序的信息。你可以使用 info 命令来实现,该命令默认显示“程序信息”部分。由于设备当前正在运行代码,我们添加 -f 标志以强制连接。```bash
$ ./picotool info -f
Tracking device serial number XXXXXXXXXXXXXXXX for reboot
The device was asked to reboot into BOOTSEL mode so the command can be executed.
Program Information name: hello_usb features: USB stdin / stdout binary start: 0x10000000 binary end: 0x10011d50 target chip: RP2350 image type: RISC-V
The device was asked to reboot back into application mode.
该输出揭示了关键细节,例如程序名称、其内存范围以及映像架构。
现在,我们继续提取程序,创建一个目录来存储提取出的文件。```bash
mkdir -p $HOME/hcon2026hwctf/
运行以下命令以提取固件:```bash ./picotool save -pvf -t bin $HOME/hcon2026hwctf/hello_usb.bin
这个单一命令处理整个提取过程。它会强制 RP2350 重启进入 BOOTSEL 模式,从闪存读取当前安装的程序,并将其保存为原始二进制文件。为确保提取正确,它会读取数据以验证转储的文件与芯片上的内容完全一致。
你应该会得到类似这样的输出:```bash
$ ./picotool save -pvf -t bin $HOME/hcon2026hwctf/hello_usb.bin
Tracking device serial number XXXXXXXXXXXXXXXX for reboot
The device was asked to reboot into BOOTSEL mode so the command can be executed.
Saving file: [==============================] 100%
Wrote 73040 bytes to /home/b1n4ri0/hcon2026hwctf/hello_usb.bin
Verifying Flash: [==============================] 100%
OK
The device was asked to reboot back into application mode.
就是这样,你已经成功转储了程序!
注意:请记住,你只提取了已安装的程序,而非闪存中的全部内容。
如果遇到错误,请确认设备连接正确。若自动重启失败,请手动进入 BOOTSEL 模式,并在不使用 -f 标志的情况下重新运行命令。有关可用选项的更多信息,只需运行 picotool help <command>。