<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
    <channel>
        <title>Mustakimur Khandaker</title>
        <link>https://www.mustakim.info/</link>
        <description>Mustakimur Khandaker - Break it to Build it</description>
        <generator>Mustakim</generator><language>en</language><managingEditor>mustakcsecuet@gmail.com (Mustakimur Khandaker)</managingEditor>
            <webMaster>mustakcsecuet@gmail.com (Mustakimur Khandaker)</webMaster><lastBuildDate>Sat, 15 Aug 2026 00:00:00 &#43;0000</lastBuildDate>
            <atom:link href="https://www.mustakim.info/index.xml" rel="self" type="application/rss+xml" />
        <item>
    <title>Places I have been</title>
    <link>https://www.mustakim.info/posts/places-i-have-been/</link>
    <pubDate>Sat, 03 Aug 2024 18:25:51 -0400</pubDate>
    <author>mustakcsecuet@gmail.com (Mustakimur Khandaker)</author>
    <guid>https://www.mustakim.info/posts/places-i-have-been/</guid>
    <description><![CDATA[<br/>
<iframe height="750" src="https://beeneverywhere.net/usermap/11706?width=1200&amp;height=750" title="test title" width="1200"></iframe>]]></description>
</item>
<item>
    <title>Essential Linux Commands for CTF</title>
    <link>https://www.mustakim.info/posts/linux-command-collection/</link>
    <pubDate>Fri, 24 Nov 2023 02:21:53 -0400</pubDate>
    <author>mustakcsecuet@gmail.com (Mustakimur Khandaker)</author>
    <guid>https://www.mustakim.info/posts/linux-command-collection/</guid>
    <description><![CDATA[<p>Hi</p>
<p>I decided to write down a collection of Linux commands that I have found useful. So, here we go:</p>
<h3 id="open-ports">Open Ports</h3>
<p><em>Note: will keep it updated from time to time.</em></p>]]></description>
</item>
<item>
    <title>Capture the Flag (CTF)</title>
    <link>https://www.mustakim.info/posts/session-1-introduction-miscellaneous/</link>
    <pubDate>Tue, 31 Aug 2021 22:50:32 -0400</pubDate>
    <author>mustakcsecuet@gmail.com (Mustakimur Khandaker)</author>
    <guid>https://www.mustakim.info/posts/session-1-introduction-miscellaneous/</guid>
    <description><![CDATA[<p>On behalf of the Institute of Cybersecurity and Privacy, UGA, I would like to invite you to join us in our upcoming UGA Capture The Flag (CTF) Workshop. This workshop will be open to all UGA Computer Science and CyberSecurity&amp;Privacy students who are interested in learning practical cybersecurity skills and potentially joining the UGA CTF team.</p>
<p><strong>Session #1: Introduction &amp; Miscellaneous:</strong>
Slides: <a href="/wp-content/uploads/2021/09/Intro-to-Workshop.pdf" rel="">http://www.mustakim.info/wp-content/uploads/2021/09/Intro-to-Workshop.pdf</a>
Discussed:
– <a href="https://gctf-2018.appspot.com/#beginners/misc-letter" target="_blank" rel="noopener noreffer ">https://gctf-2018.appspot.com/#beginners/misc-letter</a>
– <a href="https://otterctf.com/challenges#PDFuck!" target="_blank" rel="noopener noreffer ">https://otterctf.com/challenges#PDFuck!</a>
– <a href="https://otterctf.com/challenges#ReCurse" target="_blank" rel="noopener noreffer ">https://otterctf.com/challenges#ReCurse</a>
Exercise:
– <a href="http://ctf.cs.uga.edu:8000/challenges#re%7c%7c%7c%7c%7c%7c-1" target="_blank" rel="noopener noreffer ">http://ctf.cs.uga.edu:8000/challenges#re||||||-1</a>
– <a href="http://ctf.cs.uga.edu:8000/challenges#Experience-2" target="_blank" rel="noopener noreffer ">http://ctf.cs.uga.edu:8000/challenges#Experience-2</a>
Refer:</p>]]></description>
</item>
<item>
    <title>Secure Programming [CSCI 8245]</title>
    <link>https://www.mustakim.info/posts/secure-programming-csci-8245/</link>
    <pubDate>Tue, 04 May 2021 13:23:29 -0400</pubDate>
    <author>mustakcsecuet@gmail.com (Mustakimur Khandaker)</author>
    <guid>https://www.mustakim.info/posts/secure-programming-csci-8245/</guid>
    <description><![CDATA[<p>This is a special course I teach at the University of Georgia every Spring semester. This is a senior grad class. In this course, students will first learn about security threats of unsafe language and program analysis methods to identify software vulnerabilities. Later, the class will continue based on the fastest-growing memory-safe language (i.e. Rust) and explore how it guarantees memory, thread, and type safety besides some of the advanced features. Please, take a look at the <a href="/uga_secure_programming/syllabus.pdf" rel="">syllabus</a> for details. An expected class schedule can be found here.</p>]]></description>
</item>
<item>
    <title>CyberSecurity [CSCI 4250/6250]</title>
    <link>https://www.mustakim.info/posts/cybersecurity-csci-4250-6250/</link>
    <pubDate>Sun, 02 May 2021 21:13:19 -0400</pubDate>
    <author>mustakcsecuet@gmail.com (Mustakimur Khandaker)</author>
    <guid>https://www.mustakim.info/posts/cybersecurity-csci-4250-6250/</guid>
    <description><![CDATA[<p>This is a regular course I teach at the University of Georgia every Fall semester. This is a combined class (i.e. both undergrads and grads students are welcome). This is an introductory class on cybersecurity where we mostly focus on software, system, web, and network security with a minor in cryptography, mobile, hardware, IoT, AI security, and data privacy. Please, take a look at the <a href="/uga_cyber_security/syllabus.pdf" rel="">syllabus</a> for details. An expected class schedule can be found <a href="/uga_cyber_security/class%20schedule%20-%202021.pdf" rel="">here</a>.</p>]]></description>
</item>
<item>
    <title>Building Your Own Clang LibTool: A Step-by-Step Tutorial</title>
    <link>https://www.mustakim.info/posts/clang-libtool/</link>
    <pubDate>Fri, 22 Feb 2019 23:20:34 -0400</pubDate>
    <author>mustakcsecuet@gmail.com (Mustakimur Khandaker)</author>
    <guid>https://www.mustakim.info/posts/clang-libtool/</guid>
    <description><![CDATA[<p>Technically, Clang receives an Abstract Syntax Tree (AST), build by Clang Parser (clang/Parse/*), not the input C/C++ code (although Parser is part of Clang code base). There is obviously a Lexer in between this process, but neither Lexer nor Parser is our focus in this tutorial. Clang is responsible to convert the AST to LLVM IR which is implemented in Clang CodeGen. Once source code is translated to LLVM IR, all instrumentation have to be in LLVM IR. It is certainly easy to instrument in fine-grain language like LLVM-IR then complicated top-level source code. But in certain cases (e.g. code formatter, code documentation etc.), it is expected to modify the source code (overwrite the source file).</p>]]></description>
</item>
<item>
    <title>System and Software Security Research Conference</title>
    <link>https://www.mustakim.info/posts/system-and-software-security-research-conference/</link>
    <pubDate>Tue, 18 Dec 2018 18:18:37 -0400</pubDate>
    <author>mustakcsecuet@gmail.com (Mustakimur Khandaker)</author>
    <guid>https://www.mustakim.info/posts/system-and-software-security-research-conference/</guid>
    <description><![CDATA[<p>Several conferences focus on security, including top-tier and flagship events, where publishing your work should be a priority. Additionally, individual top-tier systems and software conferences can also be good choices for publishing your research. I have categorized the conferences accordingly:</p>
<h4 id="top-tier-security-conference">Top-tier Security Conference</h4>
<p>* IEEE Symposium on Security and Privacy (S&amp;P/Oakland)
* ACM Computer and Communications Security (CCS) 
* USENIX Security Symposium (USENIX Security)
* Network and Distributed System Security Symposium (NDSS)</p>]]></description>
</item>
<item>
    <title>SVF: Interprocedural Static Value-Flow Analysis in LLVM</title>
    <link>https://www.mustakim.info/posts/svf-interprocedural-static-value-flow-analysis-in-llvm/</link>
    <pubDate>Sun, 09 Dec 2018 18:27:12 -0400</pubDate>
    <author>mustakcsecuet@gmail.com (Mustakimur Khandaker)</author>
    <guid>https://www.mustakim.info/posts/svf-interprocedural-static-value-flow-analysis-in-llvm/</guid>
    <description><![CDATA[<p>SVF is a static analysis framework implemented in LLVM that allows value-flow construction and pointer analysis to be performed in an iterative manner (sparse analysis – analysis conducted into stages, from overapproximate analysis to precise, expensive analysis). It uses (default) points-to information from Andersen’s analysis and constructs an interprocedural memory SSA (Static-Single Assignment) form where def-use chains of both top-level and address-taken variables are included. From the design perspective, the SVF can be seen as two modules: pointer analysis and memory SSA. To be capable of allowing another points-to analysis than Andersen’s, the design of pointer analysis is split into three parts: Graph, Rules, and Solver. To give control of scalability and precision, the memory SSA is designed to allow users to partition memory into a set of regions. Comparing to previous work, SVF takes a big leap by constructing an interprocedural value-flow graph. To identify bugs, it is an important requirement to be able to analyze a program across its procedural boundaries.</p>]]></description>
</item>
<item>
    <title>Road Trips Summer’19: Florida ↔ California</title>
    <link>https://www.mustakim.info/posts/summar-trip-plan/</link>
    <pubDate>Sun, 02 Dec 2018 21:21:48 -0400</pubDate>
    <author>mustakcsecuet@gmail.com (Mustakimur Khandaker)</author>
    <guid>https://www.mustakim.info/posts/summar-trip-plan/</guid>
    <description><![CDATA[<p>In summer 2019, I went to Silicon Valley for my internship at Baidu USA. I decided to make a road trip with my 2005 Nissan Altima. All alone, the trip was awesome and adventurous.</p>
<h5 id="to-silicon-valley">To Silicon Valley</h5>
<h5 id="to-florida-state">To Florida State</h5>
<iframe allowfullscreen="" frameborder="0" height="450" src="https://www.google.com/maps/embed?pb=!1m54!1m8!1m3!1d13609613.356457619!2d-112.1981976!3d33.6141379!3m2!1i1024!2i768!4f13.1!4m43!3e0!4m5!1s0x808fb6478cdf8b83%3A0x337759f3563e8d34!2s598+E+Arbor+Ave%2C+Sunnyvale%2C+CA+94085-3766%2C+USA!3m2!1d37.3865608!2d-122.0161042!4m5!1s0x80cddc1300936035%3A0xa6accfbcff04a560!2sKingman%2C+AZ!3m2!1d35.189443!2d-114.0530065!4m5!1s0x87220addd309837b%3A0xc0d3f8ceb8d9f6fd!2sAlbuquerque%2C+NM!3m2!1d35.0843859!2d-106.65042199999999!4m5!1s0x87ad8a547ef8d281%3A0x33a21274d14f3a9d!2sOklahoma+City%2C+OK!3m2!1d35.4675602!2d-97.5164276!4m5!1s0x88874c2e29de5fa1%3A0xe7f1cc40fb3d9d4f!2sTupelo%2C+MS!3m2!1d34.257606599999995!2d-88.7033859!4m5!1s0x88f5045d6993098d%3A0x66fede2f990b630b!2sAtlanta%2C+GA!3m2!1d33.7489954!2d-84.3879824!4m5!1s0x88ecf4674e9f0455%3A0x4ca1eee4c3b33fef!2s2616+Mission+Rd%2C+Tallahassee%2C+FL!3m2!1d30.457426599999998!2d-84.33434659999999!5e0!3m2!1sen!2sus!4v1561276804892!5m2!1sen!2sus" style="border:0" width="600"></iframe>]]></description>
</item>
<item>
    <title>Overwrite GOT Entry from Buffer Overlapping</title>
    <link>https://www.mustakim.info/posts/buffer-overflow-over-the-function/</link>
    <pubDate>Wed, 28 Feb 2018 22:44:55 -0400</pubDate>
    <author>mustakcsecuet@gmail.com (Mustakimur Khandaker)</author>
    <guid>https://www.mustakim.info/posts/buffer-overflow-over-the-function/</guid>
    <description><![CDATA[<h3 id="problem-description">Problem description</h3>
<p>First of all, the CTF is from pwnable.kr (problem name: passcode). The problem description is as follows:
“Mommy told me to make a passcode based login system. My initial C code was compiled without any error! Well, there was some compiler warning, but who cares about that?”
There is ssh to the problem server where you can find:</p>
<p>We have 3 files including the flag file which can only be read by the user or group root. The other text file is a source code “passcode.c” which we can view. There is one executable that is compiled from the source code provided. This executable has read accessibility to the flag. However, the source code looks following:</p>]]></description>
</item>
</channel>
</rss>
