Skip to content
Operating Systems
12: CTF
Initializing search
cs-pub-ro/operating-systems
Home
Live
Full
Info
Assignments
Extra
Operating Systems
cs-pub-ro/operating-systems
Home
Live
Live
Lectures
Lectures
01: The Software Stack
01: The Software Stack
Demos
Demos
Pitch: Four Small Surprises
Pitch: Four Small Surprises
Demo: Two Ways to Build the Same String
Demo: char *str and char str[]
Demo: The Same Command, Three Times
Demo: An Assignment That Does Nothing
Demo: Hello, World at Five Heights
Demo: What a Security Guarantee Costs
Demo: Four Containers, Three Protocols
Slides
02: OS Types and the OS Interface
02: OS Types and the OS Interface
Demos
Demos
Demo: The Kernel Does the Heavy Lifting
Demo: Building an Operating System
Demo: Building an Operating System
Demo: Build Hello, World with Unikraft
Demo: The System Call Interface
Demo: The System Call Interface
Demo: What a System Call Costs
Demo: Talking to the Kernel Directly
Demo: Privileged Instructions Fault in User Mode
Demo: Optimizing the OS Interface
Demo: Optimizing the OS Interface
Demo: Buffering in User Space
Demo: Moving Work into the Kernel with sendfile()
Slides
03: Memory
04: Virtual Memory
05: Paging
06: Processes and Threads
07: Scheduling
08: Concurrency
09: I/O Interface
10: Inter-Process Communication
11: Network I/O
12: Inter-Application Interaction
Labs
Labs
01: The Software Stack
01: The Software Stack
Demo: Copy String
Demo: printf vs write
01: Implement strlen(), strcpy(), strcat(), memcpy()
02: XOR Encryption — Build and Use a Library
03: Stream Ciphers — Four Ways to Link the Same Program
Bonus: Stream Ciphers — One Executable per Cipher
Bonus: Make Your Own Library — Static vs Dynamic Linking
02: The Operating System Interface
02: The Operating System Interface
Demo: The write System Call
01: The getpid System Call
02: The nanosleep System Call
Bonus: clock_gettime and time
Bonus: Plugging _putchar() Into a Custom printf
03: Memory Operations
03: Memory Operations
Demo: Copy a File Using a Global Buffer
Demo: Copy a File Using a Heap Buffer
Demo: Copy a File Using mmap
01: XOR-Encrypt a File With a Fixed Key
02: Sort Products by Price
03: A Growable In-Memory Database
Bonus: A Shrinking In-Memory Database
Bonus: Sort Products With a Linked List
04: Memory Debugging
04: Memory Debugging
Demo: Debugging an In-Memory Database with GDB and Valgrind
01: The Histogram That Counts Too Much
02: The Program That Is Right and Still Broken
03: The Symbol Table With Three Bugs
Bonus: Patch the Bug, No Source Code Allowed
Bonus: The JSON Parser With a Heap Buffer Overflow
05: Memory Security
05: Memory Security
Demo: Flip the Lock (heap-0)
Demo: Set the Access Level (heap-1)
01: Overflow a Heap Buffer (heap-0)
02: Overflow to an Exact Value (heap-1)
03: Hijack a Function Pointer (heap-2)
04: Use-After-Free (heap-3)
Bonus: Cross Two Structs (heap-havoc)
Bonus: Leak and Overflow a PIE (heap-mayhem)
06: Processes and Threads
07: Parallelizing Execution
08: Troubleshooting Concurrency
09: The I/O Interface. File I/O
10: Pipes and Redirection
11: Socket IPC
12: CTF
Full
Full
Lectures
Lectures
01: The Software Stack
01: The Software Stack
Demos
Demos
Pitch: Four Small Surprises
Pitch: Four Small Surprises
Demo: Two Ways to Build the Same String
Demo: char *str and char str[] Are Not the Same Declaration
Demo: The Same Command, Three Times, Fifteen Times Faster
Demo: Python Strings Are Immutable, Except When It Would Be Slow
Demo: Hello, World at Five Heights of the Stack
Demo: What a Security Guarantee Costs
Demo: A Web Application Is Four Programs Talking
Demo: A Web Application Is Four Programs Talking
Dockerized Wordpress with NGINX web server & MariaDB
Slides
02: Operating System Types and the OS Interface
02: Operating System Types and the OS Interface
Demos
Demos
Demo: The Kernel Does the Heavy Lifting
Demo: Building an Operating System
Demo: Building an Operating System
Demo: Build Hello, World with Unikraft
Demo: The System Call Interface
Demo: The System Call Interface
Demo: What a System Call Costs
Demo: Talking to the Kernel Directly
Demo: Privileged Instructions Fault in User Mode
Demo: Optimizing the OS Interface
Demo: Optimizing the OS Interface
Demo: Buffering in User Space
Demo: Moving Work into the Kernel with sendfile()
Slides
03: Memory
04: Virtual Memory
05: Paging
06: Processes and Threads
07: Scheduling
08: Concurrency
09: I/O Interface
10: Inter-Process Communication
11: Network I/O
12: Inter-Application Interaction
Labs
Labs
01: The Software Stack
01: The Software Stack
Demo: Copy String
Demo: printf vs write
01: Implement strlen(), strcpy(), strcat(), memcpy()
02: XOR Encryption — Build and Use a Library
03: Stream Ciphers — Four Ways to Link the Same Program
Bonus: Stream Ciphers — One Executable per Cipher
Bonus: Make Your Own Library — Static vs Dynamic Linking
02: The Operating System Interface
02: The Operating System Interface
Demo: The write System Call
01: The getpid System Call
02: The nanosleep System Call
Bonus: clock_gettime and time
Bonus: Plugging _putchar() Into a Custom printf
03: Memory Operations
03: Memory Operations
Demo: Copy a File Using a Global Buffer
Demo: Copy a File Using a Heap Buffer
Demo: Copy a File Using mmap
01: XOR-Encrypt a File With a Fixed Key
02: Sort Products by Price
03: A Growable In-Memory Database
Bonus: A Shrinking In-Memory Database
Bonus: Sort Products With a Linked List
04: Memory Debugging
04: Memory Debugging
Demo: Debugging an In-Memory Database with GDB and Valgrind
01: The Histogram That Counts Too Much
02: The Program That Is Right and Still Broken
03: The Symbol Table With Three Bugs
Bonus: Patch the Bug, No Source Code Allowed
Bonus: The JSON Parser With a Heap Buffer Overflow
05: Memory Security
05: Memory Security
Demo: Flip the Lock (heap-0)
Demo: Flip the Lock (heap-0)
Build
Deploy
Publish
Solve
Demo: Set the Access Level (heap-1)
Demo: Set the Access Level (heap-1)
Build
Deploy
Publish
Solve
01: Overflow a Heap Buffer (heap-0)
01: Overflow a Heap Buffer (heap-0)
Build
Deploy
Publish
Solve
02: Overflow to an Exact Value (heap-1)
02: Overflow to an Exact Value (heap-1)
Build
Deploy
Publish
Solve
03: Hijack a Function Pointer (heap-2)
03: Hijack a Function Pointer (heap-2)
Build
Deploy
Publish
Solve
04: Use-After-Free (heap-3)
04: Use-After-Free (heap-3)
Build
Deploy
Publish
Solve
Bonus: Cross Two Structs (heap-havoc)
Bonus: Cross Two Structs (heap-havoc)
Build
Deploy
Publish
Solve
Bonus: Leak and Overflow a PIE (heap-mayhem)
Bonus: Leak and Overflow a PIE (heap-mayhem)
Build
Deploy
Publish
Solve
06: Processes and Threads
07: Parallelizing Execution
08: Troubleshooting Concurrency
09: The I/O Interface. File I/O
10: Pipes and Redirection
11: Socket IPC
12: CTF
Info
Info
How the Lab Works
Resources
Resources
QEMU Guide (MacOS)
UTM Guide (MacOS)
Rules and Grading (2026-2027)
Assignments
Assignments
ELF Loader Assignment
Mini-libc
Minishell
Extra
Session 12: CTF - Full Contents
¶
Back to top