Donate to us via Paypal!
You cannot teach a man anything; you can only help him find it within himself. - Galileo
Wednesday, March 03, 2021
 Need Help?
Members Online
Total Online: 125
Guests Online: 123
Members Online: 2

Registered Members: 133807
Newest Member: dacomir635
Latest Articles

View Thread

HellBound Hackers | Challenges | Application Cracking




Your avatar

Posts: 18
Location: /etc/passwd
Joined: 25.06.18
Posted on 04-07-18 05:43
I am kind of beginner. I have disassembled the code in radare2 and got a string called str.password but unable to see where does cmp register come for comparison or anywhere str.password is used?

RE: App-2

☆ Lucifer ☆

Posts: 2018
Location: Scotland
Joined: 20.02.08
Posted on 04-07-18 23:55
If we tell you exactly where to look there would be no challenge.
You need to follow the flow of the code to find out where it's comparing the string you entered as the password, against the one it has stored.

Radare2 is pretty good at decompiling most binaries, but it's not a one stop universal cracker that you can just feed any old app into, and out pops the password.

As a beginner you'd be better off switching to visual mode. That way you don't
remember too many commands or keep the program state in your mind. This will open it with a hexdump view of the loaded app, then you can see the output in the registers as you step through the code.

Pressing p will allow you to cycle through the rest of the visual mode views. Use F7 or s to step into and F8 or S to step over the current instruction. You can set breakpoints with F2 key.

Mastering that lot will allow you to crack most of the apps on HBH, except for ones where r2 would need to download a support package in order to allow it to load and read formats it doesn't already include.

Like I'm not sure if it can decompile swf or ActionScript and from memory, that may be needed for app2.

So your choices are simple, if you can't find the password in the code: either you need to get an update to work with .swf files,  or you could always just get a stand alone .swf decompiler.
U N ⓡⓔⓧ_ⓜⓤⓝⓓⓘ