1 of 17

Psi Beta Rho Practice 1

Spring Quarter 2023 - Week 2

2 of 17

PBR’s got spirit!!!

3 of 17

👏Welcome back!👏

  • Schedule
    • https://bit.ly/PBRS2023
  • Guest Speaker
  • Writeups
    • Only one required for the quarter. Preferably from a CTF we have attended. Due date is last practice of the quarter.
  • *new this quarter* CTF attendance
    • Participate in at least one CTF in-person this quarter
    • We will be doing ångstromCTF during practice week 4 after working on it Saturday of week 3

4 of 17

📣 Announcements 📣

  • PBR Practices
    • Same as last quarter: 6-8PM Ackerman Union 3517
    • Sign up in our discord! https://discord.gg/j9dgf2q in #pbr-announcements
  • Cyber Spring GM: Tomorrow (Wednesday 4/12)
    • 6-8PM @ MS 5200
  • ACM Cyber officer apps
    • Due Tomorrow 11:59pm
  • Cylab:
  • Unofficial PBR minecraft server (started during cursedCTF): see #private-chatter pins

5 of 17

⛳️CTFs⛳️

  • cursedCTF 2023 (last weekend)
  • bucketCTF 2023 (last weekend)
  • (optional) PlaidCTF 2023 (Week 2)
  • ångstromCTF (Week 3)
    • https://ctftime.org/event/1859
    • Also during practice week 4
  • San Diego CTF (Week 6)
  • DEFCON CTF Quals (Week 8)

6 of 17

Practice Focus:

Python Pickles

by Ronak

7 of 17

What is pickle

  • Serializer of objects mainly for python

8 of 17

What is pickle

9 of 17

Deep dive

10 of 17

Deep Dive Disassembly

11 of 17

Elit Hax0ring

12 of 17

Amogus

  • Seems very convenient, is this actually applicable anywhere??????
  • ACTUALLY USED EVERYWHERE AAAAAA

13 of 17

How not get hac

  • Use json

14 of 17

Live Demo

Lets pwn benson 😳

15 of 17

Kalmar CTF

  • Will do in pickle group maybe

16 of 17

Focus groups

web

rev/pwn

crypto

Benson

Andrew

Alec

17 of 17

Thanks for coming! :)