---
title: "Hacking In-Vehicle Infotainment Systems with OFRAK @DEFCON31"
description: "Red Balloon Security attended DEF CON 31 in Las Vegas, Nevada where we contributed two challenges to the Car Hacking Village Capture the Flag (CTF) competition."
author: "Neil Durkin"
date: "2023-08-28T21:52:49+00:00"
language: "en-US"
canonical_url: "https://xckd6kzuxte054o.onstatic.studio/ofrak-at-defcon31/"
source_url: "https://xckd6kzuxte054o.onstatic.studio/ofrak-at-defcon31/"
content_type: "text/markdown"
---

[![CHV CTF — ELF “.shellcode” section highlighted (syscall randomization)](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/2025/08/image7_2025-08-20_02_24_49.634949.png-1024x368.png)](https://xckd6kzuxte054o.onstatic.studio/2025-def-con-chv-ctf/)










###

                                        [Hacking Randomized Linux Kernel Images at the DEF CON 33 Car Hacking Village](https://xckd6kzuxte054o.onstatic.studio/2025-def-con-chv-ctf/)





                                    [Conferences](https://xckd6kzuxte054o.onstatic.studio/category/blog/conferences/), [Research](https://xckd6kzuxte054o.onstatic.studio/category/blog/research/)















###

                            [Hacking Randomized Linux Kernel Images at the DEF CON 33 Car Hacking Village](https://xckd6kzuxte054o.onstatic.studio/2025-def-con-chv-ctf/)







                            August 21, 2025






                            Red Balloon Security’s DEF CON 33 Car Hacking Village CTF write-up: unpacking firmware, cracking a repeating-key XOR, and exploiting a buffer overflow on ARM64 to ROP into mprotect() and execute shellcode—despite randomized Linux syscall numbers.







                            [Read More](https://xckd6kzuxte054o.onstatic.studio/2025-def-con-chv-ctf/)
