Posts

Showing posts with the label binary exploit

TryHackMe - Reversing Elf - Walkthrough

Image
Introduction Today we're going to be doing a walkthrough for the Reversing ELF room hosted at https://tryhackme.com/room/ reverselfiles . For this walkthrough, we'll be using one virtual machine (VMs), a Kali Linux VM as our attacking machine. Task 1 - Crackme1 Questions What is the flag? Download the Task 1 Task File Copy it to your working directory Give the file executable permissions Run the file chmod +x crackme1 ./crackme1 Task 2 - Crackme2 Questions What is the super secret password ? Give the file executable permissions Run Ltrace on the file with a test string chmod +x crackme2 ltrace ./crackme2 test ./crackme2 passwordFoundInPreviousStep Task 3 - Crackme3 Questions What is the flag? Give the file executable permissions Run strings on the file Echo the base64 string you found, pipe it into Base64 decode chmod +x crackme3 strings crackme3 echo “ base64stringFoundInPreviousStep ” | base64 -d Task 4 - Crackme4 Questions What is the password ? Give the file execu...

NahamCon2021 CTF - Ret2basic - Writeup

Image
Introduction Today we're doing a CTF writeup for the Ret2basic challenge from the NahamCon2021 CTF. Ret2basic is a binary exploit challenge, and after we start the challenge we received a string we can use to interact with the challenge: We also have to download the binary file associated with the challenge so we can enumerate it. After we download the file, we chmod it to make it executable, then start it up: chmod +x ret2basic ./ret2basic Now, in another terminal, we start up edb : edb Then from the file tab, we Attach , then select our running ret2basic process. Now we want to identify the functions in the binary. From the Plugins tab, we select SymbolViewer : In this list, we can see all of the functions the ret2basic binary calls, as well as their associated memory address. One in particular catches our eye: This is most likely the function and memory address we want to instruct the RIP register to go to after we find the correct offset buffer to control it. Before we f...