HACK@SEC is a competition, coincides with the USENIX Security conference, for penetration testing of the hardware and firmware. In this competition, participants compete to identify the security vulnerabilities, implement the related exploit, propose a mitigation technique or a patch, and report them. The participants are encouraged to use any tools and techniques with a focus on the exploitation of the bugs.
This year, yet another RISC-V soc with security vulnerabilities ready to be exploited
WHAT ARE WE FOCUSING ON THIS YEAR?
This year, we together develop practical and effective solutions and computer-aided tools to identify the vulnerabilities more efficiently in buggy SoC, with a special focus on exploitation.
The competition is Live
WHAT HAPPENS IN THE LIVE COMPETITION?
The teams will be provided an SoC including a set of bugs and will compete in a live capture-the-flag competition. They will need to apply their techniques and developed tools to detect and exploit as many vulnerabilities in a limited time-frame.
Bugs and exploits submitted will be evaluated live and winners will be announced in the USENIX Security conference.