{"id":23050052,"url":"https://github.com/yuawn/hitcon-badge-2019","last_synced_at":"2025-08-15T02:31:32.081Z","repository":{"id":93094541,"uuid":"203902214","full_name":"yuawn/HITCON-Badge-2019","owner":"yuawn","description":"HITCON electric badge for HITCON CMT 2019.","archived":false,"fork":false,"pushed_at":"2020-03-19T04:55:24.000Z","size":4133,"stargazers_count":77,"open_issues_count":0,"forks_count":16,"subscribers_count":4,"default_branch":"master","last_synced_at":"2025-08-14T22:41:58.821Z","etag":null,"topics":["arm","badge","challenges","conference","confrence","ctf","education","hitcon","pwn","pwnable","security","trustzone"],"latest_commit_sha":null,"homepage":"","language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/yuawn.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null}},"created_at":"2019-08-23T01:38:45.000Z","updated_at":"2025-01-06T01:50:04.000Z","dependencies_parsed_at":"2023-06-04T19:15:23.091Z","dependency_job_id":null,"html_url":"https://github.com/yuawn/HITCON-Badge-2019","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/yuawn/HITCON-Badge-2019","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yuawn%2FHITCON-Badge-2019","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yuawn%2FHITCON-Badge-2019/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yuawn%2FHITCON-Badge-2019/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yuawn%2FHITCON-Badge-2019/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/yuawn","download_url":"https://codeload.github.com/yuawn/HITCON-Badge-2019/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yuawn%2FHITCON-Badge-2019/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":270514467,"owners_count":24598368,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-15T02:00:12.559Z","response_time":110,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["arm","badge","challenges","conference","confrence","ctf","education","hitcon","pwn","pwnable","security","trustzone"],"created_at":"2024-12-15T23:19:01.647Z","updated_at":"2025-08-15T02:31:30.979Z","avatar_url":"https://github.com/yuawn.png","language":"C","funding_links":[],"categories":[],"sub_categories":[],"readme":"# HITCON Badge 2019\n## Overview\nHITCON Badge 2019 is based on `M2351ZIAAE` MCU. \n## Usage\nThere are four pages, you can use `LEFT` and `RIGHT` button on the badge to switch them.\n### Page 0: LED Level Display\n* Badge will show the status of 24 LEDs.\n    * Locked: white color\n    * Unlocked: Bright and colorful\n* Press `UP` + `A`/`B` to decrease/increase the brightness.\n* You can unlock each LED by playing the game or completing the mission with sponsors.\n### Page 1: Pattern Display\n* Use `UP` and `DOWN` button to select patterns.\n* Pattern 0 will be unlocked by unlocking led 0 1 2.\n    * Pattern 1: led 3 4 5.\n    * Pattern 2: led 6 7 8.\n    * ..\n* If the pattern is still locked, it will render the error pattern (all LED are red).\n* There are 11 patterns in total.\n### Page 2: Paint Mode\n* In this page, you can customize the color of LEDs!\n* Select the LEDs by pressing `UP` `DOWN` `LEFT` `RIGHT`.\n* Change the color by pressing `A` `B`.\n* Press `AB` (at the same time) and then press `LEFT`/`RIGHT` to leave paint mode.\n### Page 3: Snake\n```\n################################\n#                              #\n#                              #                                   \n#                              #                                   \n#                              #                                   \n#                              #                                   \n#                              #                                   \n#                              #                                   \n#      @@@@@@@          o      #                                   \n#                              #                                   \n#                              #                                   \n#                              #                                   \n#                              #                                   \n#                              #\n#                              #\n#                              # \n#                              #\n################################\n[Score] 6 pt\n```\n* Let badge connect to the computor with Micro USB cable.\n* Use any client you like to connect the serial com port.\n    * Linux/macOS: You can use `screen` command.\n        * example: `screen /dev/tty.usbmodemxxx` (replace `/dev/tty.usbmodemxxx` with correct path)\n    * Windows: You can use `PuTTY` (Connection type: Serial) to connect the COM port.\n* Control the snake by pressing `UP` `DOWN` `LEFT` `RIGHT`.\n* Press `AB` at the same time to pause the game.\n    * Press `AB` again to continue the game, `LEFT` to exit.\n* Score\n    * score \u003e= 50, snake pattern (pattern 8) will unlocked!\n    * score == 2147483647: Well done, hacker :)\n## Badge Command Line\n```\n  _  _ ___ _____ ___ ___  _  _   ___ __  _ ___\n | || |_ _|_   _/ __/ _ \\| \\| | |_  )  \\/ / _ \\\n | __ || |  | || (_| (_) | .` |  / / () | \\_, /\n |_||_|___| |_| \\___\\___/|_|\\_| /___\\__/|_|/_/\n\n\nHitconBadge2019 \u003e\u003e\n```\n* There is a simple command line interface running on the badge.\n* You can use it by connecting the badge to computer with micro usb.\n### Commands\n#### help\nType help for all available commands.\n```\nHitconBadge2019 \u003e\u003e help\nshow\ninfo\nunlock\nsetname\nclear\nhello\nangelboy\nyuawn\nping\nls\nid\ncat\necho\nalias\nwhoami\nhelp\n```\n#### show\nShow command will display the status of all LEDs and patterns.\n```\nHitconBadge2019 \u003e\u003e show\nPattern 0: Lock\n  led 00: Lock\n  led 01: Lock\n  led 02: Lock\nPattern 1: Lock\n  led 03: Lock\n  led 04: Lock\n  led 05: Lock\nPattern 2: Lock\n  led 06: Lock\n  led 07: Lock\n  led 08: Lock\nPattern 3: Lock\n  led 09: Lock\n  led 10: Lock\n  led 11: Lock\nPattern 4: Lock\n  led 12: Lock\n  led 13: Lock\n  led 14: Lock\nPattern 5: Lock\n  led 15: Lock\n  led 16: Lock\n  led 17: Lock\nPattern 6: Lock\n  led 18: Lock\n  led 19: Lock\n  led 20: Lock\nPattern 7: Lock\n  led 21: Lock\n  led 22: Lock\n  led 23: Lock\n\nBadge challenge:\n[Stage 1] Snake pattern: Lock\n[Stage 2] Pwned NS pattern: Lock\n[Stage 3] Pwned the whole badge pattern: Lock\n```\n## HITCON Badge Challenges\n\u003e Badge source code, solution and exploits will be released within the talk `HITCON Badge 2019 秘辛: MCU ARM TrustZone challenges` at R0 (Day2 14:40 - 15:30).\n\nThere are 11 pattern in total, but three of them are special, so you need to get them in special way :)\n### Stage 0 - Warm Up\n* Before pwning the badge, why not play some game first.\n* Get the score higher than 50, you can unlock the snake pattern.\n### Stage 1 - Hack The Game\n* Try to let the score == 2147483647 by playing the game.\n* Or pwn the badge :)\n* You will know how to do it by reversing the binary of normal world (NonSecure world) in this MCU TrustZone.\n* To make life easier, the binary is not striped and not a raw binary, just take them all (See `firmware/`)\n### Stage 2 - Pwn the Badge\n* The final target is protected by TrustZone in Secure Region.\n* I put my secret in the TrustZone, it is pretty safe, isn't it?\n* Try to pwn the badge for all patterns!\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fyuawn%2Fhitcon-badge-2019","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fyuawn%2Fhitcon-badge-2019","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fyuawn%2Fhitcon-badge-2019/lists"}