Please complete Tasks 1-5 here. Please set the value of BUF_SIZE to 136 for the Level 1, Level 2, and Level 3 tasks. Please complete Tasks 1-4 here (Task 5 is optional and bonus points will be assigned). Please set the value of BUF_SIZE to 32 for the Return-to-LibC lab. See Rubric for point allocation for grading this project. Please note that submitting working code is not sufficient, your lab writeup must provide screenshots, and explain what you did and how you did it.
The Lab Setup files (stack.c, call_shellcode.c) can be downloaded here and here.
New! Students who have an Apple Silicon machine may complete Tasks 1-7 here instead of the tasks listed above. Please use the following settings:
The Lab Setup files (including docker containers) can be downloaded here.
Submission Instructions: Submit the source code as a .zip file containing your code, as well as a writeup explaining what you did as a pdf document on Canvas. Include your full name in the writeup. Name the .zip file as x-project1.zip and the writeup as x-project1.pdf, where x is your first and last name. For example, if your name is "Jane Doe," you should be handing in two files named "JaneDoe-project1.zip" and "JaneDoe-project1.pdf."
Please complete Tasks 1-4 here. Please complete Tasks 1-6 here.
The Lab Setup files can be downloaded from here and here.
Please see here (Passcode: wua1?S51) for a short video on Lab Setup.
IMPORTANT: There is an issue with the built-in container setup for the CSRF lab. For your attack to work please go to the attacker container and run the following command: sudo chmod +x /var/www/attacker
New! Students who have an Apple Silicon machine may complete the same lab using the Setup files found here and here with the same rubric as above.
However, in the CSRF lab (the issue likely also affects the XSS lab), there is one issue related to the latest version of Firefox, which is also mentioned on the project website. (On ARM-based machines, the original seed image is not installed, so the latest version of Firefox is used.) To resolve this, students need to modify Firefox settings to remove a restriction.
Specifically, students should navigate to the Privacy & Security page -> Enhanced Tracking Protection -> Custom -> and uncheck "Cookies." Without doing this, the project cannot be completed successfully on Apple machines.
Submission Instructions: Submit the source code as a .zip file containing your code, as well as a writeup explaining what you did as a pdf document on Canvas. Include your full name in the writeup. Name the .zip file as x-project2.zip and the writeup as x-project2.pdf, where x is your first and last name. For example, if your name is "Jane Doe," you should be handing in two files named "JaneDoe-project2.zip" and "JaneDoe-project2.pdf."
Homework 1. Assigned on 10/2/24. Due on 10/12/24 at 11:59pm.
Please complete Tasks 2-6 here.
The Lab Setup files can be downloaded from here.
New! Students who have an Apple Silicon machine may complete the same lab using the Setup files found here with the same rubric as above.
Submission Instructions: Submit the source code as a .zip file containing your code, as well as a writeup explaining what you did as a pdf document on Canvas. Include your full name in the writeup. Name the .zip file as x-project3.zip and the writeup as x-project3.pdf, where x is your first and last name. For example, if your name is "Jane Doe," you should be handing in two files named "JaneDoe-project3.zip" and "JaneDoe-project3.pdf."
Homework 2. Assigned on 10/28/24. Due on 11/6/24 at 11:59pm.