---
title: SHA2017 — A recap of insanity
date: 2017-08-10
tags:
  - security
  - sha2017
  - sha
  - hacking
  - information-security
url: https://blog.paradoxis.nl/sha2017-a-recap-of-insanity-47aaf52c15a2
author:
  name: Luke Paris
  bio: OSCP & OSWE certified Dutch security researcher specializing in active directory, malware development and all things devops. Currently work for Merlon Security in The Hague, and previously worked in Fox-IT's Red Team for 6 years.
  links:
    - type: linkedin
      url: https://www.linkedin.com/in/paradoxis
    - type: github
      url: https://github.com/paradoxis
    - type: unsplash
      url: https://unsplash.com/@paradoxis
---

# SHA2017 — A recap of insanity

To summarize the last five days of my life, I can’t think of anything other than “amazingly chaotic”, and I loved *every minute of it*. If you’ve never been to a hacker camp before; it's exactly what it sounds like, a bunch of nerds on a camp site hacking stuff and having a blast.

From the fourth through the eighth of August I attended a hacker camp named SHA2017, it’s an independently organized hacker camp by members of the hacking community which hosts everything from lectures to [CTF (capture the flag](https://en.wikipedia.org/wiki/Capture_the_flag#Computer_security)) challenges to massive neon colored raves.

## The ransomware race begins

If you didn’t know, lots of hacker related events (think of DefCon, CCC, etc) hand out electronic badges that you can tinker with during the event, SHA2017 was no exception. The amazing people that organized the event created these cool badges with an e-ink display so you wouldn’t be walking around with a black screen around your neck if the battery died.

![Image for post](https://blog.paradoxis.nl/assets/img/figure-01-8dc2c340-2400.webp "Two of the SHA2017 event badges")

The badges shipped with MicroPython (a stripped down version of my favorite weapon of choice: Python) and an app store called the Hatchery which allowed anyone to submit a package and let others download it. Naturally, the first thing that came to mind was: **Ransomware.**

Whilst developing my malicious masterpiece I noticed something odd in my terminal, one of the other attendees was poking around with my socket server, what followed was one of the best conversations I’ve ever had.

> I connected to an API and then the human developing it started talking to me. #sha2017 is full of surprises.
>
> — albi.eth (@vrde), [Aug 6, 2017](https://twitter.com/vrde/status/894181952282140673)

Yup, I ended up having a nice chat with the guy that was screwing with my server; we eventually met each other the third day and spent the entire evening chilling and partying our asses off, memories were made.

## The ransomware is unleashed!

No better way to start day #2 of SHA2017 than with a nice dose of ransomware. Around lunchtime the first wave of ransomware was unleashed, after reading up on the Micro-Python docs and reverse engineering the badge creator’s code I eventually managed to pull off a working version of badge ransomware.

Now you may be wondering, how did were people tricked into installing said ransomware? Surely at a hacking convention people should be smart enough to not install strange software right? — Well, by using the oldest trick in the book: *We called it “*[*ASCII porn*](https://badge.sha2017.org/projects/ascii_porn)*”.*

> Hahaha, first ransomware hits   @SHA2017Badge #SHA2017 #RepectTheBootloader #YOLO pic.x.com/55zNk48L0n
>
> — Sndr Ptrs (@sndrptrs), [Aug 5, 2017](https://twitter.com/sndrptrs/status/893850502559084546)

Initially I chose to make the ransomware non-persistent. I visited the badge bar and saw the flood of people that bricked their badges asking the admins to help them (even before the ransomware wave) that it didn’t feel right to send half the camp there because someone was demanding a Club Mate for the release of their badge.

That was of course, until one of the admins barged into our tent and asked us: *“Who made the ransomware?”*. This was the moment I thought: *“Shit, I’m about to get kicked out of SHA.”* — At which point he tells me to refresh the webpage on which I published my ransomware.

> > I made it persistent for you, it’s funnier that way

[▶ A man in a tuxedo slowly clapping in an empty theatre (video)](https://blog.paradoxis.nl/files/sha2017-a-recap-of-insanity-47aaf52c15a2/applause.mp4)

The end result: Two Club Mate’s, seven unlocked badges and one grumpy father that didn’t appreciate the joke. Victory tastes sweet.

## New friends and local fame

One day after the release of the ransomware (and the even bigger geek magnet ‘The Legend of Zelda’ clone of it), my server had crashed twice due to the amount of people probing, spamming and straight up attacking my server with everything ranging from SQL injection attacks to a full on DDOS attack (a tiny VPS doesn’t stand a chance against a 100 gigabit connection).

When looking through my logs, I spotted something odd.. Someone had been [mass-spamming ASCII goatsee](https://raw.githubusercontent.com/Paradoxis/SHA2017/master/ransomware/keys.txt) into my logs (if you want to mentally scar yourself, Google that word). I also noticed this odd line of text..

![Image for post](https://blog.paradoxis.nl/assets/img/figure-02-569916e3-2400.webp "Oh shit")

Yeah, turns out that when we copied the code from our brilliantly named “ASCII porn” app, we forgot to change a single (yet very essential) line of code, which ended up bricking all the devices that installed our second version of the ransomware. To those whose badges I bricked: Sorry ❤

![Image for post](https://blog.paradoxis.nl/assets/img/figure-03-c06574c7-2400.webp "By not changing the name of the app, the badge would enter an infinite crash loop as ‘ascii_porn’ didn’t exist")

Luckily, only around twenty people installed the app in that timeframe and I didn’t receive any death threats, and naturally I visited the guys over at the /dev/lol village to thank them, turns out they were actually working on a (working) anti-virus for the badges! From that moment, I was referred to as:

> > “The ransomware guy”

## Pong and Capture The Flag

After successfully launching my first ever malware campaign, I decided to take a step back and do some relaxing, I attended some talks, learned a bunch of new stuff and wrote a [working version](https://badge.sha2017.org/projects/pong_multiplayer) of the wildly popular [Pong game](https://en.wikipedia.org/wiki/Pong) which people could play together on their badges (including nifty graphics and bouncy walls).

I also decided to take on the Junior CTF challenge. After a few intense hours of hacking around I managed to get 100% of the flags, putting me at the #171st spot in the high scores.

![Image for post](https://blog.paradoxis.nl/assets/img/figure-04-e8a6d938-1920.webp "Special thanks to Rik van Duijn, Vincent van der Eijk and a guy named Perzik")

## The final day

All good things must come to an end, sadly that includes SHA. The rest of the final day was spent tearing down our tents, attending the final talks and saying goodbye to new friends.

![Image for post](https://blog.paradoxis.nl/assets/img/figure-05-3fc57a1e-2048.webp "SHA2017")

SHA2017 was an unforgettable experience and I can’t wait until the next. Special thanks to kaliumxyz, [vrde](https://medium.com/u/892da16ad550), [Tim Daubenschütz](https://medium.com/u/e006ffecda2d), the /dev/lol village, my colleagues and the entire SHA2017 for the memories that were made.

---

Any code or scripts used during the event can be found on my GitHub: [Paradoxis/SHA2017 on GitHub](https://github.com/Paradoxis/SHA2017)
