<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Megabeets</title><link>https://www.megabeets.net/</link><description>Recent content on Megabeets</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 07 Nov 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://www.megabeets.net/index.xml" rel="self" type="application/rss+xml"/><item><title>LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices</title><link>https://www.megabeets.net/publications/landfall-new-commercial-grade-android-spyware-in-e/</link><pubDate>Fri, 07 Nov 2025 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/landfall-new-commercial-grade-android-spyware-in-e/</guid><description/></item><item><title>When Avatars Come Alive: Understanding Hybrid Threat Actors</title><link>https://www.megabeets.net/publications/when-avatars-come-alive-understanding-hybrid-threa/</link><pubDate>Wed, 01 Oct 2025 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/when-avatars-come-alive-understanding-hybrid-threa/</guid><description/></item><item><title>AdaptixC2: A New Open-Source Framework Leveraged in Real-World Attacks</title><link>https://www.megabeets.net/publications/adaptixc2-a-new-open-source-framework-leveraged-in/</link><pubDate>Wed, 10 Sep 2025 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/adaptixc2-a-new-open-source-framework-leveraged-in/</guid><description/></item><item><title>Modern Approach to Attributing Hacktivist Groups</title><link>https://www.megabeets.net/publications/modern-approach-to-attributing-hacktivist-groups/</link><pubDate>Tue, 01 Oct 2024 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/modern-approach-to-attributing-hacktivist-groups/</guid><description>&lt;p>&lt;em>Virus Bulletin 2024 Conference Paper&lt;/em>&lt;/p></description></item><item><title>About</title><link>https://www.megabeets.net/pages/about/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/pages/about/</guid><description>&lt;script type="text/javascript" src="https://www.megabeets.net/js/carousel.js">&lt;/script>
&lt;link rel="stylesheet" href="https://www.megabeets.net/css/carousel.css">



&lt;div id="carousel10" class="carousel" duration="5000" items="1">
 &lt;ul>
 
 &lt;li id="c10_slide1" style="min-width: calc(100%/1); padding-bottom: 55%;">&lt;img src="https://www.megabeets.net/images/me.jpg" alt="" />&lt;div>&lt;div>&lt;/div>&lt;/div>&lt;/li>
 
 &lt;li id="c10_slide2" style="min-width: calc(100%/1); padding-bottom: 55%;">&lt;img src="https://www.megabeets.net/images/forbes2023.jpeg" alt="" />&lt;div>&lt;div>&lt;/div>&lt;/div>&lt;/li>
 
 &lt;/ul>
 &lt;ol>
 
 &lt;li>&lt;a href="#c10_slide1">&lt;/a>&lt;/li>
 
 &lt;li>&lt;a href="#c10_slide2">&lt;/a>&lt;/li>
 
 &lt;/ol>
 &lt;div class="prev">&amp;lsaquo;&lt;/div>
 &lt;div class="next">&amp;rsaquo;&lt;/div>
&lt;/div>
&lt;h2 id="-whoami">$ WHOAMI&lt;/h2>
&lt;p>Hey there!👋 I&amp;rsquo;m Itay Cohen. I&amp;rsquo;ve been fascinated by computers for as long as I can remember. Over time, I developed a fascination with cybersecurity and started teaching myself about hacking, reverse engineering and malware analysis. Most of my free time is dedicated for political and social activism and in general pursuing of what I see as just. I am an animal liberation activist and vegan. I read a lot, I’m a non-stop learner and I’ll always jump on an opportunity to solve a good challenge.&lt;/p></description></item><item><title>Darkbit Decoded: Analysis of an Iranian-Sponsored Attack</title><link>https://www.megabeets.net/publications/darkbit-decoded-analysis-of-an-iranian-sponsored-attack/</link><pubDate>Wed, 04 Oct 2023 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/darkbit-decoded-analysis-of-an-iranian-sponsored-attack/</guid><description>&lt;p>&lt;em>Virus Bulletin 2023 Conference Paper&lt;/em>&lt;/p></description></item><item><title>The Dragon Who Sold His Camaro: Analyzing Custom Router Implant</title><link>https://www.megabeets.net/publications/the-dragon-who-sold-his-camaro-analyzing-custom-ro/</link><pubDate>Tue, 16 May 2023 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/the-dragon-who-sold-his-camaro-analyzing-custom-ro/</guid><description/></item><item><title>Twisted Panda: Chinese APT espionage operation against Russian state-owned defense institutes</title><link>https://www.megabeets.net/publications/twisted-panda-chinese-apt-espionage-operation-agai/</link><pubDate>Thu, 19 May 2022 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/twisted-panda-chinese-apt-espionage-operation-agai/</guid><description/></item><item><title>EvilPlayout: Attack Against Iran’s State Broadcaster</title><link>https://www.megabeets.net/publications/evilplayout-attack-against-iran-s-state-broadcaste/</link><pubDate>Fri, 18 Feb 2022 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/evilplayout-attack-against-iran-s-state-broadcaste/</guid><description/></item><item><title>Indra — Hackers Behind Recent Attacks on Iran</title><link>https://www.megabeets.net/publications/indra-hackers-behind-recent-attacks-on-iran/</link><pubDate>Sat, 14 Aug 2021 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/indra-hackers-behind-recent-attacks-on-iran/</guid><description/></item><item><title>IndigoZebra APT continues to attack Central Asia with evolving tools</title><link>https://www.megabeets.net/publications/indigozebra-apt-continues-to-attack-central-asia-w/</link><pubDate>Thu, 01 Jul 2021 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/indigozebra-apt-continues-to-attack-central-asia-w/</guid><description/></item><item><title>The Story of Jian - How APT31 Stole and Used an Unknown Equation Group 0-Day</title><link>https://www.megabeets.net/publications/the-story-of-jian-how-apt31-stole-and-used-an-unkn/</link><pubDate>Mon, 22 Feb 2021 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/the-story-of-jian-how-apt31-stole-and-used-an-unkn/</guid><description/></item><item><title>SUNBURST, TEARDROP and the NetSec New Normal</title><link>https://www.megabeets.net/publications/sunburst-teardrop-and-the-netsec-new-normal/</link><pubDate>Tue, 22 Dec 2020 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/sunburst-teardrop-and-the-netsec-new-normal/</guid><description/></item><item><title>Bandook: Signed &amp; Delivered</title><link>https://www.megabeets.net/publications/bandook-signed-delivered/</link><pubDate>Thu, 26 Nov 2020 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/bandook-signed-delivered/</guid><description/></item><item><title>Pay2Key Ransomware Alert</title><link>https://www.megabeets.net/publications/pay2key-ransomware-alert/</link><pubDate>Fri, 06 Nov 2020 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/pay2key-ransomware-alert/</guid><description/></item><item><title>Exploit Developer Spotlight: The Story of PlayBit</title><link>https://www.megabeets.net/publications/exploit-developer-spotlight-the-story-of-playbit/</link><pubDate>Fri, 02 Oct 2020 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/exploit-developer-spotlight-the-story-of-playbit/</guid><description>&lt;p>&lt;em>Part of multi-publication entry&lt;/em>&lt;/p></description></item><item><title>Graphology of an Exploit - Hunting for exploits by looking for the author's fingerprints</title><link>https://www.megabeets.net/publications/graphology-of-an-exploit-hunting-for-exploits-by-l/</link><pubDate>Thu, 01 Oct 2020 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/graphology-of-an-exploit-hunting-for-exploits-by-l/</guid><description>&lt;p>&lt;em>Virus Bulletin 2020 Conference Paper&lt;/em>&lt;/p></description></item><item><title>Mapping the connections inside Russia’s APT Ecosystem</title><link>https://www.megabeets.net/blog/mapping-the-connections-inside-russias-apt-ecosystem/</link><pubDate>Sat, 04 Jul 2020 15:27:48 +0000</pubDate><guid>https://www.megabeets.net/blog/mapping-the-connections-inside-russias-apt-ecosystem/</guid><description>&lt;p>If the names Turla, Sofacy, and APT29 strike fear into your heart, you are not alone. These are known to be some of the most advanced, sophisticated and notorious APT groups out there – and not in vain. These Russian-attributed actors are part of a bigger picture in which Russia is one of the strongest powers in the cyber warfare today. Their advanced tools, unique approaches, and solid infrastructures suggest enormous and complicated operations that involve different military and government entities inside Russia. &lt;/p></description></item><item><title>Deobfuscating APT32 Flow Graphs with Cutter and Radare2</title><link>https://www.megabeets.net/blog/deobfuscating-apt32-flow-graphs-with-cutter-and-radare2/</link><pubDate>Sat, 04 Jul 2020 14:25:38 +0000</pubDate><guid>https://www.megabeets.net/blog/deobfuscating-apt32-flow-graphs-with-cutter-and-radare2/</guid><description>&lt;p>The Ocean Lotus group, also known as APT32, is a threat actor which has been known to target East Asian countries such as Vietnam, Laos and the Philippines. The group strongly focuses on Vietnam, especially private sector companies that are investing in a wide variety of industrial sectors in the country. While private sector companies are the group’s main targets, APT32 has also been known to target foreign governments, dissidents, activists, and journalists.&lt;/p></description></item><item><title>The Evolution of BackSwap</title><link>https://www.megabeets.net/blog/the-evolution-of-backswap/</link><pubDate>Sat, 04 Jul 2020 14:14:33 +0000</pubDate><guid>https://www.megabeets.net/blog/the-evolution-of-backswap/</guid><description>&lt;p>The BackSwap banker has been in the spotlight recently due to its unique and innovative techniques to steal money from victims while staying under the radar and remaining undetected. This malware was previously spotted targeting banks in Poland but has since moved entirely to focus on banks in Spain. The techniques used by it were thoroughly described by our fellow researchers at the &lt;a href="https://www.cert.pl/en/news/single/backswap-malware-analysis/">Polish CERT&lt;/a> and Michal Poslusny from ESET, who &lt;a href="https://www.welivesecurity.com/2018/05/25/backswap-malware-empty-bank-accounts/">revealed&lt;/a> and coined the malware’s name earlier this year. However after witnessing ongoing  improvements to its malicious techniques we decided to share this information to the wider research community.&lt;/p></description></item><item><title>Nazar: Spirits of the Past</title><link>https://www.megabeets.net/publications/nazar-spirits-of-the-past/</link><pubDate>Tue, 05 May 2020 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/nazar-spirits-of-the-past/</guid><description/></item><item><title>CONFidence Teaser CTF – Hidden Flag</title><link>https://www.megabeets.net/blog/confidence-teaser-ctf-hidden-flag/</link><pubDate>Sun, 15 Mar 2020 10:57:56 +0000</pubDate><guid>https://www.megabeets.net/blog/confidence-teaser-ctf-hidden-flag/</guid><description>&lt;p>During CONFidence Teaser CTF, one specific task caught my interest. Not because it was hard or complicated – it wasn’t, but because the concept behind it was interesting and relevant to my day-to-day work as a malware researcher.&lt;/p>
&lt;p>In this short article, I will show a &lt;strong>highly esoteric&lt;/strong>, not to say &lt;strong>trivial&lt;/strong>, concept in which you can leak the content of “sensitive” files on systems where scanning the files with Yara is allowed, but downloading the files is not possible. Not only that I’ll show how it was used, as an &lt;strong>intended solution&lt;/strong>, to solve the “Hidden Flag” challenge on the CTF, but will also demonstrate how it can be used to retrieve the data of TLP;RED, or un-downloadable files on premium services such as Hybrid-Analysis, where the major limitation is the bandwidth.&lt;/p></description></item><item><title>Vicious Panda: The COVID Campaign</title><link>https://www.megabeets.net/publications/vicious-panda-the-covid-campaign/</link><pubDate>Wed, 01 Jan 2020 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/vicious-panda-the-covid-campaign/</guid><description/></item><item><title>5 Ways to patch binaries with Cutter</title><link>https://www.megabeets.net/blog/5-ways-to-patch-binaries-with-cutter/</link><pubDate>Mon, 23 Dec 2019 16:34:36 +0000</pubDate><guid>https://www.megabeets.net/blog/5-ways-to-patch-binaries-with-cutter/</guid><description>&lt;p>I recently watched &lt;a href="https://www.youtube.com/watch?v=LyNyf3UM9Yc">a video&lt;/a> by LiveOverflow in which he showed how different tools are used to patch binaries. By demonstrating some of the features that Radare2, Ghidra, and Binary Ninja offer for the task, the viewer can get some sense of the things they can get from using these tools.&lt;/p>
&lt;p>While all these tools are great, and although Radare2 was showed there (and oh boy, things went wrong), there was one tool, which is dear to my heart, that wasn’t there – &lt;a href="https://cutter.re/">Cutter&lt;/a>.  Notwithstanding that it is the youngest member of the pack, Cutter is growing up very fast and when it has to do with binary patching – it does not stay behind.&lt;/p></description></item><item><title>Mapping the connections inside Russia's APT Ecosystem</title><link>https://www.megabeets.net/publications/mapping-the-connections-inside-russia-s-apt-ecosys/</link><pubDate>Tue, 24 Sep 2019 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/mapping-the-connections-inside-russia-s-apt-ecosys/</guid><description/></item><item><title>Cutter: The radare2 GUI</title><link>https://www.megabeets.net/publications/r2con2019/</link><pubDate>Sun, 01 Sep 2019 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/r2con2019/</guid><description/></item><item><title>Deobfuscating APT32 Flow Graphs with Cutter and Radare2</title><link>https://www.megabeets.net/publications/deobfuscating-apt32-flow-graphs-with-cutter-and-ra/</link><pubDate>Wed, 24 Apr 2019 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/deobfuscating-apt32-flow-graphs-with-cutter-and-ra/</guid><description/></item><item><title>The Evolution of BackSwap</title><link>https://www.megabeets.net/publications/the-evolution-of-backswap/</link><pubDate>Fri, 30 Nov 2018 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/the-evolution-of-backswap/</guid><description/></item><item><title>A Targeted Campaign Break-Down - Ryuk Ransomware</title><link>https://www.megabeets.net/publications/a-targeted-campaign-break-down-ryuk-ransomware/</link><pubDate>Mon, 20 Aug 2018 00:00:00 +0000</pubDate><guid>https://www.megabeets.net/publications/a-targeted-campaign-break-down-ryuk-ransomware/</guid><description/></item><item><title>Decrypting APT33’s Dropshot Malware with Radare2 and Cutter – Part 2</title><link>https://www.megabeets.net/blog/decrypting-apt33s-dropshot-malware-with-radare2-and-cutter-part-2/</link><pubDate>Mon, 18 Jun 2018 15:37:22 +0000</pubDate><guid>https://www.megabeets.net/blog/decrypting-apt33s-dropshot-malware-with-radare2-and-cutter-part-2/</guid><description>&lt;h2 id="prologue"> Prologue&lt;/h2>
&lt;p>Previously, in the first part of this article, we used Cutter, a GUI for radare2, to statically analyze APT33’s Dropshot malware. We also used radare2’s Python scripting capabilities in order to decrypt encrypted strings in Dropshot. If you didn’t read the first part yet, I suggest you do it &lt;a href="https://www.megabeets.net/decrypting-dropshot-with-radare2-and-cutter-part-1/">now&lt;/a>.&lt;/p>
&lt;p>Today’s article will be shorter, now that we are familiar with cutter and r2pipe, we can quickly analyze another interesting component of Dropshot — an encrypted resource that includes Dropshot’s actual payload. So without further ado, let’s start.&lt;/p>
&lt;p>&lt;a href="https://www.megabeets.n./cutter_logo_trimmed.png">&lt;img src="./cutter_logo_trimmed.png" />&lt;/a>&lt;/p>
&lt;h2 id="downloading-and-installing-cutter">Downloading and installing Cutter&lt;/h2>
&lt;p>Cutter is available for all platforms (Linux, OS X, Windows). You can download the latest release &lt;a href="https://github.com/radareorg/cutter/releases">here&lt;/a>. If you are using Linux, the fastest way to use Cutter is to use the AppImage file.&lt;/p>
&lt;p>If you want to use the newest version available, with new features and bug fixes, you should build Cutter from source by yourself. It isn’t a complicated task and it is the version I use.&lt;/p>
&lt;p>First, you must clone the repository:&lt;/p>
&lt;pre tabindex="0">&lt;code class="language-default" data-lang="default">git clone --recurse-submodules https://github.com/radareorg/cutter
cd cutter
&lt;/code>&lt;/pre>&lt;p>Building on Linux:&lt;/p>
&lt;pre tabindex="0">&lt;code class="language-default" data-lang="default">./build.sh
&lt;/code>&lt;/pre>&lt;p>Building on Windows:&lt;/p>
&lt;pre tabindex="0">&lt;code class="language-default" data-lang="default">prepare_r2.bat
build.bat
&lt;/code>&lt;/pre>&lt;p>If any of those do not work, check the more detailed instruction page &lt;a href="https://github.com/radareorg/cutter/blob/master/docs/Compiling.md">here&lt;/a>&lt;/p>
&lt;h2 id="dropshot-stonedrill">Dropshot \ StoneDrill&lt;/h2>
&lt;p>As in the last part, we’ll analyze Dropshot, which is also known by the name StoneDrill. It is a wiper malware associated with the APT33 group which targeted mostly organizations in Saudi Arabia. Dropshot is a sophisticated malware sample, that employed advanced anti-emulation techniques and has a lot of interesting functionalities. The malware is most likely related to the infamous &lt;a href="https://en.wikipedia.org/wiki/Shamoon">Shamoon malware&lt;/a>. Dropshot was analyzed thoroughly by &lt;a href="https://app.box.com/s/olc867zxc9nkjzm3wkjwi0b0e2awahtn">Kaspersky&lt;/a> and later on by &lt;a href="https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html">FireEye&lt;/a>. In this article, we’ll focus on decrypting the encrypted resource of Dropshot which contains the actual payload of the malware.&lt;/p>
&lt;p>The Dropshot sample can be downloaded from &lt;a href="https://github.com/ITAYC0HEN/A-journey-into-Radare2/blob/master/Part%203%20-%20Malware%20analysis/dropshot.exe.zip">here&lt;/a> &lt;span style="font-size: 12pt;">(password: &lt;em>infected&lt;/em>). I suggest you star (&lt;span style="color: #ffcc00;">★&lt;/span>) &lt;a href="https://github.com/ITAYC0HEN/A-journey-into-Radare2/">the repository&lt;/a> to get updates on more radare2 tutorials 🙂&lt;/span>&lt;/p>
&lt;p>&lt;span style="color: #ff0000;">&lt;strong>Please, be careful when using this sample. It is a real malware, and more than that, a wiper! Use with caution!&lt;/strong>&lt;/span>&lt;/p>
&lt;p>&lt;em>Since we’ll analyze Dropshot statically, you can use a Linux machine, as I did.&lt;/em>&lt;/p></description></item><item><title>‘Decrypting APT33’s Dropshot Malware with Radare2 and Cutter – Part 1’</title><link>https://www.megabeets.net/blog/decrypting-apt33s-dropshot-malware-with-radare2-and-cutter-part-1/</link><pubDate>Mon, 21 May 2018 14:12:27 +0000</pubDate><guid>https://www.megabeets.net/blog/decrypting-apt33s-dropshot-malware-with-radare2-and-cutter-part-1/</guid><description>&lt;h1 id="prologue">Prologue&lt;/h1>
&lt;p>As a reverse engineer and malware researcher, the tools I use are super important for me. I have invested hours and hours in creating the best malware analysis environment for myself and chose the best tools for me and my needs. For the last two years, radare2 is my go-to tool for a lot of reverse-engineering tasks such as automating RE related work, scripting, CTFing, exploitation and more. That said, I almost never used radare2 for malware analysis, or more accurately, for analysis of malware for Windows. The main reason was that radare2 command-line interface felt too clumsy, complicated and an over-kill. IDA Pro was simply better for these tasks, a quick inspection of functions, data structures, renaming, commenting, et cetera. It felt more intuitive for me and that what I was searching for while doing malware analysis. And then came Cutter.&lt;/p>
&lt;p>&lt;img src="./cutter_logo_smaller.png" alt="">&lt;/p>
&lt;p> &lt;/p>
&lt;h1 id="cutter">Cutter&lt;/h1>
&lt;p>Along the years, the radare2 community had tried to develop many different graphic-interfaces for radare2. None of them came even close to Cutter. Cutter is a QT C++ based GUI for radare2. In my opinion, it is the GUI that radare2 deserves. To quote from &lt;a href="https://github.com/radareorg/cutter">Cutter’s Github page&lt;/a>:&lt;/p>
&lt;blockquote>
&lt;p>Cutter is not aimed at existing radare2 users. It instead focuses on those whose are not yet radare2 users because of the learning curve, because they don’t like CLI applications or because of the difficulty…&lt;/p>
&lt;/blockquote>
&lt;p>Cutter is a young project, only one-year-old, and it is the official GUI of radare2 (the first and only GUI to be announced “official”). Cutter is a cross-platform GUI that aims to export radare2’s plenty of functionality into a user-friendly and modern GUI. In this post, I’ll show you some of Cutter’s features and how I work with it. To be honest, Cutter is intuitive so you probably won’t need me to show you around, but just in case.&lt;/p>
&lt;h4 id="downloading-and-installing-cutter">Downloading and installing Cutter&lt;/h4>
&lt;p>Cutter is available for all platforms (Linux, OS X, Windows). You can download the latest release &lt;a href="https://github.com/radareorg/cutter/releases">here&lt;/a>. If you are using Linux, the fastest way to use Cutter is to use the AppImage file.&lt;/p>
&lt;p>If you want to use the newest version available, with new features and bug fixes, you should build Cutter from source by yourself. It isn’t a complicated task and it is the version I use.&lt;/p>
&lt;p>First, you must clone the repository:&lt;/p>
&lt;pre tabindex="0">&lt;code class="language-default" data-lang="default">git clone --recurse-submodules https://github.com/radareorg/cutter
cd cutter
&lt;/code>&lt;/pre>&lt;p>Building on Linux:&lt;/p>
&lt;div class="highlight highlight-source-shell">
 ```default
./build.sh
```
&lt;pre>&lt;code>Building on Windows:
&lt;/code>&lt;/pre>
&lt;pre tabindex="0">&lt;code class="language-default" data-lang="default">prepare_r2.bat
build.bat
&lt;/code>&lt;/pre>&lt;/div>
&lt;p>If any of those do not work, check the more detailed instruction page &lt;a href="https://github.com/radareorg/cutter/blob/master/docs/Compiling.md">here&lt;/a>.&lt;/p>
&lt;h1 id="dropshot-stonedrill">Dropshot \ StoneDrill&lt;/h1>
&lt;p>Dropshot, also known as StoneDrill, is a wiper malware associated with the APT33 group which targeted mostly organizations in Saudi Arabia. Dropshot is a sophisticated malware sample, that employed advanced anti-emulation techniques and has a lot of interesting functionalities. The malware is most likely related to the infamous &lt;a href="https://en.wikipedia.org/wiki/Shamoon">Shamoon malware&lt;/a>. Dropshot was analyzed thoroughly by &lt;a href="https://app.box.com/s/olc867zxc9nkjzm3wkjwi0b0e2awahtn">Kaspersky&lt;/a> and later on by &lt;a href="https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html">FireEye&lt;/a>. In this article, we’ll focus on analyzing how Dropshot decrypted the strings inside it in order to evade analysis. In part 2 of this article, which will be published soon, we’ll focus on decrypting the encrypted resource of Dropshot which contains the actual payload of the malware.&lt;/p>
&lt;p>The Dropshot sample can be downloaded from &lt;a href="https://github.com/ITAYC0HEN/A-journey-into-Radare2/blob/master/Part%203%20-%20Malware%20analysis/dropshot.exe.zip">here&lt;/a> &lt;span style="font-size: 12pt;">(password: &lt;em>infected&lt;/em>). I suggest you star (&lt;span style="color: #ffcc00;">★&lt;/span>) &lt;a href="https://github.com/ITAYC0HEN/A-journey-into-Radare2/">the repository&lt;/a> to get updates on more radare2 tutorials 🙂&lt;/span>&lt;/p>
&lt;p>&lt;span style="color: #ff0000;">&lt;strong>Please, be careful when using this sample. It is a real malware, and more than that, a wiper! Use with caution!&lt;/strong>&lt;/span>&lt;/p>
&lt;p>&lt;em>Since we’ll analyze Dropshot statically, you can use a Linux machine, as I did.&lt;/em>&lt;/p></description></item><item><title>Solving PwCTF Prequel</title><link>https://www.megabeets.net/blog/solving-pwctf-prequel/</link><pubDate>Sat, 27 Jan 2018 18:08:32 +0000</pubDate><guid>https://www.megabeets.net/blog/solving-pwctf-prequel/</guid><description>&lt;h3 id="epilogue">Epilogue&lt;/h3>
&lt;p>PwCTF is an on-site CTF event in Israel. It will take part on January 29-31 in Cybertech Tel-Aviv 2018. Honestly I’ve never heard of it before but I thought I’ll give it a try and ended up to be &lt;strong>the first to finish the prequels&lt;/strong>. In the following writeup I’ll go step by step on how I solved each challenge. Here we go.&lt;/p>
&lt;p> &lt;/p>
&lt;h3 id="the-first-challenge">The first challenge&lt;/h3>
&lt;p>It was a morning time, I was eating my breakfast while reading messages on my security groups. One of the messages, by my friend &lt;a href="https://www.linkedin.com/in/netanelfisher/">Netanel Fisher&lt;/a>, announced of the opening of CTF Prequalification Challenge. They said “challenge” and immediately caught my attention. I cannot say “no” to a challenge. So, I thought to myself that I’ll sign up and see what challenges are there. I clicked on the link to the &lt;a href="https://prequal.pwctf.com">CTF’s website&lt;/a> and got into this lovely landing page:&lt;/p></description></item><item><title>Reversing a Self-Modifying Binary with radare2</title><link>https://www.megabeets.net/blog/reversing-a-self-modifying-binary-with-radare2/</link><pubDate>Sun, 14 Jan 2018 08:50:31 +0000</pubDate><guid>https://www.megabeets.net/blog/reversing-a-self-modifying-binary-with-radare2/</guid><description>&lt;h2 id="prologue">Prologue&lt;/h2>
&lt;p>It took me three months to finish writing this article. I had so many tasks on my to-do list that sadly this one was pushed down to the bottom of the list. Last weekend I made a promise to myself that until Sunday I’m going to finish writing it, I successfully kept my word and here it is, another radare2 tutorial.&lt;/p>
&lt;p>Today we’ll solve a very nice challenge, “packedup”, written by ad3l for r2con 2017 competition. It is not the first writeup that I publish from r2con competition, you can check out &lt;a href="https://www.megabeets.net/reverse-engineering-a-gameboy-rom-with-radare2/">“Reverse engineering a Gameboy ROM with radare2”&lt;/a> as well, make sure not to miss the cool swags I got from winning the competition.&lt;/p>
&lt;p>This article is aimed to those of you who are familiar with radare2. If you are not, I suggest you to start from &lt;a href="https://www.megabeets.net/a-journey-into-radare-2-part-1/">part 1&lt;/a> of my series &lt;em>“A Journey Into Radare2”.&lt;/em>&lt;/p>
&lt;p>So, without further ado, let’s dig into the binary.&lt;/p>
&lt;p>&lt;img src="././packedup_cover.png" alt="">&lt;/p>
&lt;p> &lt;/p>
&lt;h2 id="getting-radare2">Getting radare2&lt;/h2>
&lt;h3 id="installation">Installation&lt;/h3>
&lt;p>Radare2’s development is pretty quick – the project evolves every day, therefore it’s recommended to use the current git version over the stable one. Sometimes the stable version is less stable than the current git version!&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>$ git clone https://github.com/radare/radare2.git
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>$ &lt;span style="color:#fff;font-weight:bold">cd&lt;/span> radare2
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>$ ./sys/install.sh
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>If you don’t want to install the git version or you want the binaries for another machine (Windows, OS X, iOS, etc.) check out the &lt;a href="http://radare.org/r/down.html">download page at the radare2 website.&lt;/a>&lt;/p>
&lt;h3 id="updating">Updating&lt;/h3>
&lt;p>As I said before, it is highly recommended to always use the newest version of r2 from the git repository. All you need to do to update your r2 version from the git is to execute:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>$ ./sys/install.sh
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>And you’ll have the latest version from git. I usually update my version of radare2 in the morning with a scheduled task, so I can wake up to the latest version available. If you’re using radare2 often, I recommend you do the same.&lt;/p>
&lt;h2 id="packedup">packedup&lt;/h2>
&lt;p>You can download packedup from &lt;a href="https://github.com/ITAYC0HEN/A-journey-into-Radare2/blob/master/Generic/packedup%20-%20Self-modifying%20binary/packedup">here&lt;/a>. I suggest you to star (&lt;span style="color: #ffcc00;">★&lt;/span>) the repository to get updates about more radare2 tutorials 🙂&lt;/p>
&lt;p>First thing to do, obviously, is to execute the binary and get a basic feeling of what we are going to face.&lt;/p>
&lt;pre tabindex="0">&lt;code class="language-default" data-lang="default">$ ./packedup 
Welcome to packedup for r2crackmes :)
Flag &amp;lt;&amp;lt; MEGABEETS 
Try again!
&lt;/code>&lt;/pre>&lt;p>&lt;em>packedup&lt;/em> is executed, it requests us to give it a flag. It then probably does some calculations at the backend to see if the inputted flag is the right one. I entered “MEGABEETS” which is likely not the correct flag and finished with the fail message — “Try again!”.&lt;/p>
&lt;h3 id="reversing-time">Reversing time!&lt;/h3>
&lt;p>Now for our favorite part, let’s open the binary with radare2 and try to figure out how &lt;em>packedup&lt;/em> is checking the submitted flag:&lt;/p>
&lt;div style="overflow-x: auto; margin: 0 0 20px;">
 &lt;table style="background-color: #4a3446; color: #fff; font-family: terminal, monaco, monospace; font-size: 10pt; margin: 0px;">
 &lt;tr style="height: 19.8594px;">
 &lt;td style="height: 19.8594px;">
 &lt;span style="color: #468ee6;">&lt;span style="color: #ffff99;">$&lt;/span> &lt;span style="color: #ffffff;">r2&lt;/span> &lt;span style="color: #00ccff;">./packedup&lt;/span>&lt;br /> &lt;/span>— Here be dragons.&lt;span style="color: #468ee6;">&lt;br /> [0x004004d0]>&lt;/span> aaa&lt;br /> &lt;span style="color: #35d7c7;">[x]&lt;/span> Analyze all flags starting with sym. and entry0 (aa)&lt;br /> &lt;span style="color: #35d7c7;">[x]&lt;/span> Analyze len bytes of instructions for references (aar)&lt;br /> &lt;span style="color: #35d7c7;">[x]&lt;/span> Analyze function calls (aac)&lt;br /> &lt;span style="color: #468ee6;">[*]&lt;/span> Use -AA or aaaa to perform additional experimental analysis.&lt;br /> &lt;span style="color: #35d7c7;">[x]&lt;/span> Constructing a function name for fcn.* and sym.func.* functions (aan)
 &lt;/td>
 &lt;/tr>
 &lt;/table>
&lt;/div>
&lt;h3 id="analysis">Analysis&lt;/h3>
&lt;p>I usually begin with executing &lt;code>aa&lt;/code> (&lt;strong>a&lt;/strong>nalyze &lt;strong>a&lt;/strong>ll) or with &lt;code>aas&lt;/code> (to &lt;strong>a&lt;/strong>nalyze functions, &lt;strong>s&lt;/strong>ymbols and more). The name is misleading because there is a lot more to analyze (check &lt;code>aa?&lt;/code>) but it’s enough to start with for most of the binaries I examined. This time we’ll start straight with &lt;code>aaa&lt;/code> to make things simpler and due to the binary’s small size. You can also run radare2 with the &lt;code>-A&lt;/code> flag to analyze the binary straight at startup using &lt;code>aaa&lt;/code> (e.g &lt;code>r2 -A ./packedup&lt;/code>).&lt;/p>
&lt;blockquote>
&lt;p>&lt;strong>Note:&lt;/strong> as I mentioned in the previous posts, starting with &lt;code>aaa&lt;/code> is not always the recommended approach since analysis is very complicated process. I wrote more about it in &lt;a href="https://reverseengineering.stackexchange.com/a/16115/18698">this answer&lt;/a> — read it to better understand why.&lt;/p>
&lt;/blockquote>
&lt;h3 id="getting-information">Getting Information&lt;/h3>
&lt;p>So now that we opened our binary with radare2, we have been located automatically at the program’s entrypoint. But before we start working on the code itself It’s a good approach to get to know our binary characteristics. radare2 can show us the information we need using the &lt;code>i&lt;/code> command (I removed some information for the sake of readability):&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-batch" data-lang="batch">&lt;span style="display:flex;">&lt;span>[0x004004d0]&amp;gt; i
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>...
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>file ./packedup
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>format elf64
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>iorw false
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>mode -r-x
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>size 0x1878
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>humansz 6.1K
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#fff;font-weight:bold">type&lt;/span> EXEC (Executable file)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>arch x86
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>...
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>bintype elf
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>bits 64
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>...
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>endian little
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>...
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>intrp /lib64/ld-linux-x86-64.so.2
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>lang c
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>...
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>machine AMD x86-64 architecture
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>stripped true
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>...
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;blockquote>
&lt;p>The &lt;code>i&lt;/code> command used for getting info about the opened file. It’s a wrapper around &lt;code>rabin2&lt;/code> which is an information extractor tool in the radare2 framework. radare2 offers us tons amount of information about the binary. Check out &lt;code>i?&lt;/code> to list the information’s subcommands.&lt;/p>
&lt;/blockquote>
&lt;p>&lt;em>packedup&lt;/em> is a 64-bit stripped ELF binary. Cool. Let’s move on.&lt;/p></description></item><item><title>Reverse engineering a Gameboy ROM with radare2</title><link>https://www.megabeets.net/blog/reverse-engineering-a-gameboy-rom-with-radare2/</link><pubDate>Mon, 09 Oct 2017 18:32:50 +0000</pubDate><guid>https://www.megabeets.net/blog/reverse-engineering-a-gameboy-rom-with-radare2/</guid><description>&lt;h2 id="prologue"> Prologue&lt;/h2>
&lt;p>A month ago in Barcelona I was attending to &lt;a href="http://rada.re/con/2017/">r2con&lt;/a> for the first time. This is the official congress of the radare2 community where everyone can learn more about radare2 framework and dive deep into different aspects of reverse engineering, malware analysis, fuzzing, exploiting and more. It also the place where all of us, the contributors and developers of radare2, can meet, discuss and argue about every other line of code in the framework.&lt;/p>
&lt;p>This was the second congress of radare2, after the success of the first congress in last year which was also a celebration for radare’s 10 years old birthday. This year the conference was bigger, fancier and probably organized much better. r2con was four days long, starting at September 6 and lasted until September 9. The first two days were dedicated to training and took place at &lt;em>Universitat de Barcelona.&lt;/em> The other two days were talks days and took place at the &lt;em>MediaPro.&lt;/em>&lt;/p>
&lt;h2 id="crackmes-competition">Crackmes Competition&lt;/h2>
&lt;p>During r2con this year there was a Crackmes competition where all the attendees were given with the same 5 challenges and had to publish a writeups to all the challenges they had solved. The scoring was based on the quality of the writeups along with the quantity of solved challenges.&lt;/p>
&lt;p style="text-align: center;">
 &lt;span style="font-size: 14pt;">&lt;strong>I won the competition and got myself some cool swag!&lt;/strong>&lt;/span>
&lt;/p>
&lt;ul>
&lt;li>Flag of radare2&lt;/li>
&lt;li>&lt;a href="https://www.amazon.com/PoC-GTFO-MANUL-Laphroaig/dp/1593278802">POC | GTFO&lt;/a> book&lt;/li>
&lt;li>Orange PI with 3D printed case of r2con logo&lt;/li>
&lt;li>Radare2 stickers&lt;/li>
&lt;li>A beer 🍺&lt;/li>
&lt;/ul>
&lt;p>&lt;img src="././r2con17_swags.png" alt="">&lt;/p>
&lt;p>I thought of sharing some of my writeups with you, so you can taste a bit from what we had in the competition and so that others, coming from google, twitter and such, could learn how to use radare2 for solving different challenges. This article is aimed to those of you who are familiar with radare2. If you are not, I suggest you to start from &lt;a href="https://www.megabeets.net/a-journey-into-radare-2-part-1/">part 1&lt;/a> of my series &lt;em>“A Journy Into Radare2”.&lt;/em>&lt;/p>
&lt;h2 id="getting-radare2">Getting radare2&lt;/h2>
&lt;h3 id="installation">Installation&lt;/h3>
&lt;p>Radare2’s development is pretty quick – the project evolves every day, therefore it’s recommended to use the current git version over the stable one. Sometimes the stable version is less stable than the current git version!&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>$ git clone https://github.com/radare/radare2.git
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>$ &lt;span style="color:#fff;font-weight:bold">cd&lt;/span> radare2
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>$ ./sys/install.sh
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>If you don’t want to install the git version or you want the binaries for another machine (Windows, OS X, iOS, etc) check out the &lt;a href="http://radare.org/r/down.html">download page at the radare2 website.&lt;/a>&lt;/p>
&lt;h3 id="updating">Updating&lt;/h3>
&lt;p>As I said before, it is highly recommended to always use the newest version of r2 from the git repository. All you need to do to update your r2 version from the git is to execute:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>$ ./sys/install.sh
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>And you’ll have the latest version from git. I usually update my version of radare2 in the morning, while watching cat videos.&lt;/p>
&lt;blockquote class="twitter-tweet" data-lang="en">
 &lt;p dir="ltr" lang="en">
 Let&amp;#8217;s use radare2 to reverse engineer a Gameboy ROM!&lt;br /> Check it out @ &lt;a href="https://t.co/g1kYJuShzE">https://t.co/g1kYJuShzE&lt;/a>&lt;a href="https://twitter.com/radareorg?ref_src=twsrc%5Etfw">@radareorg&lt;/a> &lt;a href="https://twitter.com/hashtag/radare2?src=hash&amp;ref_src=twsrc%5Etfw">#radare2&lt;/a> &lt;a href="https://t.co/7FJOB3SdKS">pic.twitter.com/7FJOB3SdKS&lt;/a>
 &lt;/p>
&lt;pre>&lt;code>— Itay Cohen (@megabeets_) &amp;lt;a href=&amp;quot;https://twitter.com/megabeets_/status/917464989027454976?ref_src=twsrc%5Etfw&amp;quot;&amp;gt;October 9, 2017&amp;lt;/a&amp;gt;
&lt;/code>&lt;/pre>
&lt;/blockquote>
&lt;h2 id="playing-with-gameboy-rom">Playing with Gameboy ROM&lt;/h2>
&lt;p>This post will describe how I solved &lt;a href="https://github.com/ITAYC0HEN/A-journey-into-Radare2/blob/master/Generic/Reversing%20Gameboy%20ROM/simple.gb">&lt;em>simple.gb&lt;/em>&lt;/a>, a Gameboy ROM challenge written by &lt;em>@condret&lt;/em>. It was actually my first time reversing a Gameboy ROM — and it was awesome!&lt;/p>
&lt;p>First thing I did was to open the binary in radare2 and check for its architecture and format:&lt;/p>
&lt;div style="overflow-x: auto; margin: 0 0 20px;">
 &lt;table style="background-color: #4a3446; color: #fff; font-family: terminal, monaco, monospace; font-size: 10pt;">
 &lt;tr style="height: 19.8594px;">
 &lt;td style="height: 19.8594px;">
 &lt;span style="font-weight: 400;">&lt;span style="color: #ffff99;">$&lt;/span> r2 simple.gb&lt;/span>&lt;br /> &amp;#8212; For a full list of commands see `strings /dev/urandom`&lt;br /> &lt;span style="color: #468ee6;">[&lt;span style="font-weight: 400;">0x00000100&lt;/span>]>&lt;/span> i~format&lt;br /> &lt;span style="font-weight: 400;">format   ningb&lt;/span>&lt;br /> &lt;span style="color: #468ee6;">[0x00000100]>&lt;/span> i~machine&lt;br /> &lt;span style="font-weight: 400;">machine  &lt;/span>&lt;span style="font-weight: 400; color: #00ccff;">Gameboy&lt;/span>
 &lt;/td>
 &lt;/tr>
 &lt;/table>
&lt;/div>
&lt;blockquote>
&lt;p>&lt;span style="font-weight: 400;">The &lt;code>i&lt;/code> command gives us &lt;/span>&lt;strong>i&lt;/strong>&lt;span style="font-weight: 400;">nformation about the binary. Check &lt;code>i?&lt;/code> for more commands.&lt;/span>&lt;/p>
&lt;p>Tilde (&lt;code>~&lt;/code>) is r2’s internal grep.&lt;/p>
&lt;/blockquote>
&lt;p>Surprise, surprise, it is a Gameboy ROM — dah. &lt;span style="font-weight: 400;">After reading a bit about its &lt;/span>&lt;a href="http://marc.rawer.de/Gameboy/Docs/GBCPUman.pdf">&lt;span style="font-weight: 400;">instruction set&lt;/span>&lt;/a> &lt;span style="font-weight: 400;">we should go to the mission. &lt;/span>&lt;/p>
&lt;p>The obvious thing to do is open the ROM in an Gameboy emulator. &lt;span style="font-weight: 400;">I downloaded the good old emulator I used back in the days when I played Pokemon: &lt;/span>&lt;a href="https://sourceforge.net/projects/vba">&lt;span style="font-weight: 400;">VisualBoy Advance&lt;/span>&lt;/a>&lt;span style="font-weight: 400;">.&lt;/span>&lt;/p>
&lt;p>&lt;span style="font-weight: 400;">Let’s open the ROM in our emulator and see what we have:&lt;/span>&lt;/p>
&lt;p>&lt;img src="././pokemonGold_VGA.png" alt="">&lt;/p>
&lt;p>&lt;span style="font-weight: 400;">&lt;br /> Woops, wrong file. Bad habits… Let’s try again:&lt;/span>&lt;/p>
&lt;p>&lt;img src="././simple_gb_screenshot1.png" alt="">&lt;/p>
&lt;p>&lt;span style="font-weight: 400;">Cool! It’s a simple game where, by using the arrow keys, you increase/decrease 5 digits. We ‘simply’ need to find the correct password.&lt;/span>&lt;/p></description></item><item><title>A journey into Radare 2 – Part 2: Exploitation</title><link>https://www.megabeets.net/blog/a-journey-into-radare-2-part-2-exploitation/</link><pubDate>Sat, 02 Sep 2017 16:37:46 +0000</pubDate><guid>https://www.megabeets.net/blog/a-journey-into-radare-2-part-2-exploitation/</guid><description>&lt;h2 style="text-align: left;">
 Prologue
&lt;/h2>
&lt;h2 id="helllo">helllo&lt;/h2>
&lt;p>asf&lt;/p>
&lt;h3 id="world">world&lt;/h3>
&lt;p>fas&lt;/p>
&lt;p>Welcome back to the second part of our journey into the guts of radare2! In this part we’ll cover more of the features of radare2, this time with the focus on binary exploitation.&lt;/p>
&lt;p>A lot of you waited for the second part, so here it is! Hope to publish the next part faster, much faster. If you didn’t read the &lt;strong>&lt;a href="https://www.megabeets.net/a-journey-into-radare-2-part-1/">first part&lt;/a>&lt;/strong> of the series I highly recommend you to do so. It describes the basics of radare2 and explains many of the commands that I’ll use here.&lt;/p>
&lt;p>In this part of the series we’ll focus on exploiting a simple binary. radare2 has many features which will help us in exploitation, such as mitigation detection, ROP gadget searching, random patterns generation, register telescoping and more. You can find a Reference Sheet at the end of this post. Today I’ll show you some of these great features and together we’ll use radare2 to bypass &lt;a href="https://en.wikipedia.org/wiki/NX_bit">&lt;code>nx&lt;/code>&lt;/a> protected binary on an &lt;code>&amp;lt;code&amp;gt;&lt;/code>&lt;/code>&lt;a href="https://en.wikipedia.org/wiki/Address_space_layout_randomization">ASLR&lt;/a> enabled system. I assume that you are already familiar with the following prerequisites:&lt;/p>
&lt;ul>
&lt;li>&lt;span style="font-size: 16px;">Assembly code&lt;/span>&lt;/li>
&lt;li>Exploit mitigations (NX, ASLR)&lt;/li>
&lt;li>&lt;a href="https://en.wikipedia.org/wiki/Call_stack">Stack structure&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://en.wikipedia.org/wiki/Buffer_overflow">Buffer Overflow&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://en.wikipedia.org/wiki/Return-oriented_programming">Return Oriented Programming&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://en.wikipedia.org/wiki/X86_calling_conventions">x86 Calling Conventions&lt;/a>&lt;/li>
&lt;/ul>
&lt;p>It’s really important to be familiar with these topics because I won’t get deep into them, or even won’t briefly explain some of them.&lt;/p>
&lt;h2 id="r2_part1_2-e1504441308664png">&lt;img src="././r2_part1_2-e1504441308664.png" alt="">&lt;/h2>
&lt;h2 id="updating-radare2">Updating radare2&lt;/h2>
&lt;p>First of all, let’s update radare2 to its newest git version:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>$ git clone https://github.com/radare/radare2.git &lt;span style="color:#007f7f"># clone radare2 if you didn&amp;#39;t do it yet for some reason.&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>$ &lt;span style="color:#fff;font-weight:bold">cd&lt;/span> radare2
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>$ ./sys/install.sh
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>We have a long journey ahead so while we’re waiting for the update to finish, let’s get some motivation boost — cute cats video!&lt;/p>
&lt;p style="text-align: center;">
&lt;/p>
&lt;h2 id="getting-familiar-with-our-binary">Getting familiar with our binary&lt;/h2>
&lt;p>You can download the binary from &lt;a href="https://github.com/ITAYC0HEN/A-journey-into-Radare2/blob/master/Part%202%20-%20Exploitation/megabeets_0x2">here&lt;/a>, and the source from &lt;a href="https://github.com/ITAYC0HEN/A-journey-into-Radare2/blob/master/Part%202%20-%20Exploitation/megabeets_0x2.c">here&lt;/a>.&lt;br>
If you want to compile the source by yourself, use the following command:&lt;/p>
&lt;pre tabindex="0">&lt;code class="language-default" data-lang="default">$ gcc -m32 -fno-stack-protector -no-pie megabeets_0x2.c -o megabeets_0x2
&lt;/code>&lt;/pre>&lt;p>Our binary this time is quite similar to the one from the previous post with a few slight changes to the &lt;code>main()&lt;/code> function:&lt;/p>
&lt;ul>
&lt;li>Compiled without &lt;code>-z execstac&lt;/code> to enable &lt;code>NX bit&lt;/code>&lt;/li>
&lt;li>Receives user input with &lt;code>scanf&lt;/code> and not from program’s arguments&lt;/li>
&lt;li>Uses mostly &lt;code>puts&lt;/code> to print to screen&lt;/li>
&lt;li>Little changes to the program’s output&lt;/li>
&lt;/ul>
&lt;p>This was the previous &lt;code>main()&lt;/code>:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-c" data-lang="c">&lt;span style="display:flex;">&lt;span>&lt;span style="color:#fff;font-weight:bold">int&lt;/span> main(&lt;span style="color:#fff;font-weight:bold">int&lt;/span> argc, &lt;span style="color:#fff;font-weight:bold">char&lt;/span> *argv[])
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>{
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> printf(&lt;span style="color:#0ff;font-weight:bold">&amp;#34;&lt;/span>&lt;span style="color:#0ff;font-weight:bold">\n&lt;/span>&lt;span style="color:#0ff;font-weight:bold"> .:: Megabeets ::.&lt;/span>&lt;span style="color:#0ff;font-weight:bold">\n&lt;/span>&lt;span style="color:#0ff;font-weight:bold">&amp;#34;&lt;/span>);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> printf(&lt;span style="color:#0ff;font-weight:bold">&amp;#34;Think you can make it?&lt;/span>&lt;span style="color:#0ff;font-weight:bold">\n&lt;/span>&lt;span style="color:#0ff;font-weight:bold">&amp;#34;&lt;/span>);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">if&lt;/span> (argc &amp;gt;= &lt;span style="color:#ff0;font-weight:bold">2&lt;/span> &amp;amp;&amp;amp; beet(argv[&lt;span style="color:#ff0;font-weight:bold">1&lt;/span>]))
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> printf(&lt;span style="color:#0ff;font-weight:bold">&amp;#34;Success!&lt;/span>&lt;span style="color:#0ff;font-weight:bold">\n\n&lt;/span>&lt;span style="color:#0ff;font-weight:bold">&amp;#34;&lt;/span>);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">else&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> printf(&lt;span style="color:#0ff;font-weight:bold">&amp;#34;Nop, Wrong argument.&lt;/span>&lt;span style="color:#0ff;font-weight:bold">\n\n&lt;/span>&lt;span style="color:#0ff;font-weight:bold">&amp;#34;&lt;/span>);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">return&lt;/span> &lt;span style="color:#ff0;font-weight:bold">0&lt;/span>;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>}
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>And now &lt;code>main&lt;/code> looks like this:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-c" data-lang="c">&lt;span style="display:flex;">&lt;span>&lt;span style="color:#fff;font-weight:bold">int&lt;/span> main(&lt;span style="color:#fff;font-weight:bold">int&lt;/span> argc, &lt;span style="color:#fff;font-weight:bold">char&lt;/span> *argv[])
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>{
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">char&lt;/span> *input; 
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> puts(&lt;span style="color:#0ff;font-weight:bold">&amp;#34;&lt;/span>&lt;span style="color:#0ff;font-weight:bold">\n&lt;/span>&lt;span style="color:#0ff;font-weight:bold"> .:: Megabeets ::.&lt;/span>&lt;span style="color:#0ff;font-weight:bold">\n&lt;/span>&lt;span style="color:#0ff;font-weight:bold">&amp;#34;&lt;/span>);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> puts(&lt;span style="color:#0ff;font-weight:bold">&amp;#34;Show me what you got:&amp;#34;&lt;/span>);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> 
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> scanf(&lt;span style="color:#0ff;font-weight:bold">&amp;#34;%ms&amp;#34;&lt;/span>, &amp;amp;input);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">if&lt;/span> (beet(input))
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> printf(&lt;span style="color:#0ff;font-weight:bold">&amp;#34;Success!&lt;/span>&lt;span style="color:#0ff;font-weight:bold">\n\n&lt;/span>&lt;span style="color:#0ff;font-weight:bold">&amp;#34;&lt;/span>);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">else&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> puts(&lt;span style="color:#0ff;font-weight:bold">&amp;#34;Nop, Wrong argument.&lt;/span>&lt;span style="color:#0ff;font-weight:bold">\n\n&lt;/span>&lt;span style="color:#0ff;font-weight:bold">&amp;#34;&lt;/span>);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">return&lt;/span> &lt;span style="color:#ff0;font-weight:bold">0&lt;/span>;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>}
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>The functionality of the binary is pretty simple and we went through it in the previous post — It asks for user input, performs &lt;code>rot13&lt;/code> on the input and compares it with the result of &lt;code>rot13&lt;/code> on the string “Megabeets”. Id est, the input should be ‘Zrtnorrgf’.&lt;/p>
&lt;pre tabindex="0">&lt;code class="language-myshell" data-lang="myshell">$ ./megabeets_0x2 

 .:: Megabeets ::.

Show me what you got:
blablablabla
Nop, Wrong argument.

$ ./megabeets_0x2 

 .:: Megabeets ::.

Show me what you got:
Zrtnorrgf
Success!
&lt;/code>&lt;/pre>&lt;p>It’s all well and good but today our post is not about cracking a simple Crackme but about exploiting it. Wooho! Let’s get to the work.&lt;/p>
&lt;blockquote class="twitter-tweet" data-lang="en">
 &lt;p dir="ltr" lang="en">
 The second part of &amp;#8220;A journey into &lt;a href="https://twitter.com/hashtag/radare2?src=hash">#radare2&lt;/a>&amp;#8221; is finally out &amp;#8211; and this time: Exploitation! Check it out @ &lt;a href="https://t.co/sKH1YhxJwK">https://t.co/sKH1YhxJwK&lt;/a>&lt;a href="https://twitter.com/radareorg">@radareorg&lt;/a>
 &lt;/p>
&lt;pre>&lt;code>— Itay Cohen (@megabeets_) &amp;lt;a href=&amp;quot;https://twitter.com/megabeets_/status/904381915964346372&amp;quot;&amp;gt;September 3, 2017&amp;lt;/a&amp;gt;
&lt;/code>&lt;/pre>
&lt;/blockquote>
&lt;h2 id="understanding-the-vulnerability">Understanding the vulnerability&lt;/h2>
&lt;p>As with every exploitation challenge, it is always a good habit to check the binary for implemented security protections. We can do it with &lt;code>rabin2&lt;/code> which I demonstrated in the last post or simply by executing &lt;code>i&lt;/code> from inside radare’s shell. Because we haven’t opened the binary with radare yet, we’ll go for the &lt;code>rabin2&lt;/code> method:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-batch" data-lang="batch">&lt;span style="display:flex;">&lt;span>$ rabin2 -I megabeets_0x2
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>arch x86
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>binsz 6072
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>bintype elf
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>bits 32
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>canary false
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>class ELF32
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>crypto false
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>endian little
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>havecode true
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>intrp /lib/ld-linux.so.2
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>lang c
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>linenum true
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>lsyms true
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>machine Intel 80386
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>maxopsz 16
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>minopsz 1
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>nx true
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>os linux
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>pcalign 0
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>pic false
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>relocs true
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>relro partial
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>rpath NONE
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>static false
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>stripped false
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>subsys linux
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>va true
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>As you can see in the marked lines, the binary is &lt;code>NX&lt;/code> protected which means that we won’t have an executable stack to rely on. Moreover, the file isn’t protected with &lt;a href="https://en.wikipedia.org/wiki/Stack_buffer_overflow#Stack_canaries">&lt;code>canaries&lt;/code>&lt;/a> , &lt;a href="https://en.wikipedia.org/wiki/Position-independent_code">&lt;code>pic&lt;/code>&lt;/a>  or &lt;a href="https://tk-blog.blogspot.co.il/2009/02/relro-not-so-well-known-memory.html">&lt;code>relro&lt;/code>&lt;/a>.&lt;/p></description></item><item><title>A journey into Radare 2 – Part 1: Simple crackme</title><link>https://www.megabeets.net/blog/a-journey-into-radare-2-part-1-simple-crackme/</link><pubDate>Mon, 27 Mar 2017 09:30:58 +0000</pubDate><guid>https://www.megabeets.net/blog/a-journey-into-radare-2-part-1-simple-crackme/</guid><description>&lt;blockquote class="wp-block-quote">
 &lt;strong>Update (2020): &lt;/strong>Since writing this article, it has become, in a way, the go-to tutorial for learning radare2. Your feedback was amazing and I am very happy for the opportunity to teach new people about radare2.
&lt;pre>&lt;code>A lot has changed since I wrote this tutorial, both with radare2 and with me. I am now, for several years, a core member in the radare2 team and a maintainer of &amp;lt;a href=&amp;quot;https://cutter.re/&amp;quot;&amp;gt;Cutter&amp;lt;/a&amp;gt;, a modern, GUI-based, reverse engineering framework that is powered by radare2.

This is an updated version of the original tutorial. I will keep it updated every now and then to make sure it is up-to-date with the changes in radare2.

Enjoy!
&lt;/code>&lt;/pre>
&lt;/blockquote>
&lt;hr class="wp-block-separator is-style-dots" />
&lt;h2 id="prologue">Prologue&lt;/h2>
&lt;p>I was playing a lot with radare2 in the past years, ever since I began participating in CTFs and got deeper into RE and exploitation challenges. I found radare2 very helpful with many CTFs tasks and my solutions had shortened significantly. It’s also my go-to tool for malware analysis tasks such as configuration retrievals. Sadly, I believe that only few people are familiar with radare2. It might be because they’re afraid to break out of their comfort zone (IDA Pro, x64dbg, Ghidra, OllyDBG, gdb) or they have simply not heard of it. Either way, I honestly believe that you must include radare2 in your toolbox.&lt;/p>
&lt;p>Because I got really enthusiastic about the project and I want more and more researchers to be familiar with it, use it and hopefully contribute to the project, I decided to create a series of articles and use-cases of r2. Since these articles aim to teach you the basics of radare2, its features, and capabilities, I’ll explain much more than you actually need to know in order to solve each task.&lt;/p>
&lt;p>&lt;img src="r2_part1_1.png" alt="">&lt;br>
Welcome to IDA 10.0. (see radare2/doc/fortunes.fun for more fortunes)&lt;/p>
&lt;h2 id="radare2">radare2&lt;/h2>
&lt;p>radare2 is an open-source framework for reverse engineering and binary analysis which implements a rich command-line interface for disassembling, analyzing data, patching binaries, comparing data, searching, replacing, visualizing and more. It has great scripting capabilities, it runs on all major platforms (GNU/Linux, Windows, *BSD, iOS, OSX, Solaris…) and it supports tons of architectures and file formats. But maybe above all of its features stands the ideology – radare2 is absolutely free.&lt;/p>
&lt;p>This framework is composed of a set of utilities that can be used either together from r2 shell or independently – We’ll get familiar with tools such as &lt;code>rahash2&lt;/code>, &lt;code>rabin2&lt;/code> and &lt;code>ragg2&lt;/code>. Together they create one of the most powerful toolsets in the field of static and dynamic analysis, hex editing and exploitation (in the following articles I’ll dive deeper into developing exploits using radare2).&lt;/p>
&lt;p>It is important to note that r2’s learning curve is pretty steep – although it has an amazing GUI called &lt;a href="https://cutter.re">Cutter&lt;/a>, which I co-maintain, it is still young to compete with more mature RE applications such as IDA or Ghidra. The CLI, however, including its Visual Mode, is still the core of radare2 and where its power lays. Because of its complexity, I’ll try to make things as clear and simple as I can.&lt;/p>
&lt;p>&lt;img src="r2_learning_curve.png" alt="">&lt;br>
This is more or less how r2 learning curve works.&lt;/p>
&lt;figure class="wp-block-embed-twitter wp-block-embed is-type-rich is-provider-twitter">
&lt;div class="wp-block-embed__wrapper">
 &lt;blockquote class="twitter-tweet" data-width="550" data-dnt="true">
 &lt;p lang="en" dir="ltr">
 Finally published the first part in a series of articles: A journey into radare2.&lt;br />Check it out @ &lt;a href="https://t.co/MybNPqq2CH">https://t.co/MybNPqq2CH&lt;/a>&lt;a href="https://twitter.com/radareorg?ref_src=twsrc%5Etfw">@radareorg&lt;/a> &lt;a href="https://twitter.com/hashtag/radare2?src=hash&amp;ref_src=twsrc%5Etfw">#radare2&lt;/a>
 &lt;/p>&amp;mdash; Itay Cohen🌱 (@megabeets_) 
&lt;pre>&lt;code>&amp;lt;a href=&amp;quot;https://twitter.com/megabeets_/status/846314627059400704?ref_src=twsrc%5Etfw&amp;quot;&amp;gt;March 27, 2017&amp;lt;/a&amp;gt;
&lt;/code>&lt;/pre>
 &lt;/blockquote>
&lt;/div>&lt;/figure> 
&lt;h2 id="getting-radare2">Getting radare2&lt;/h2>
&lt;h3 id="installation">Installation&lt;/h3>
&lt;p>Radare2’s development is pretty quick – the project evolves every day. Therefore it’s recommended to use the current git version over the release one. Sometimes the release version is less stable than the current git version because of bug fixes!&lt;/p>
&lt;pre tabindex="0">&lt;code>git clone https://github.com/radare/radare2.git
cd radare2
./sys/install.sh
&lt;/code>&lt;/pre>&lt;p>If you don’t want to install the git version or you want the binaries for another machine (Windows, OS X, iOS, etc) &lt;a href="https://github.com/radareorg/radare2/tags" target="_blank" aria-label="undefined (opens in a new tab)" rel="noreferrer noopener">download the release from github.&lt;/a>&lt;/p>
&lt;h3 id="updating">Updating&lt;/h3>
&lt;p>As I said before, it is highly recommended to always use the newest version of r2 from the git repository. All you need to do to update your r2 version from the git is to execute:&lt;/p>
&lt;pre tabindex="0">&lt;code>./sys/install.sh
&lt;/code>&lt;/pre>&lt;p>And you’ll have the latest version from git. I usually update my version of radare2 in the morning, while watching cat videos.&lt;/p>
&lt;h3 id="uninstalling">Uninstalling&lt;/h3>
&lt;p>I Can’t think of a reason for you to uninstall radare2 so early in the article but if you do want to, you can simply execute:&lt;/p>
&lt;pre tabindex="0">&lt;code>make uninstall
make purge
&lt;/code>&lt;/pre>&lt;h2 id="getting-started">Getting Started&lt;/h2>
&lt;p>&lt;strong>[!]&lt;/strong> Download the first challenge from &lt;a href="https://github.com/ITAYC0HEN/A-journey-into-Radare2/blob/master/Part%201%20-%20Simple%20crackme/megabeets_0x1">here&lt;/a>.&lt;/p>
&lt;p>Now that radare2 is installed on your system and you have downloaded the binary, we are ready to start exploring the basic usage of radare2. I’ll work on a Linux machine but most of the commands and explanations (if not all of them) would be the same for Windows machines and others.&lt;/p>
&lt;h3 id="command-line-arguments">Command Line Arguments&lt;/h3>
&lt;p>As most command-line utilities, the best approach to reveal the list of the possible arguments is to execute the program with the &lt;code>-h&lt;/code> flag.&lt;/p>
&lt;pre tabindex="0">&lt;code>r2 -h
&lt;/code>&lt;/pre>&lt;p>I won’t paste here the full output. Instead, I’ll point out those which I usually use in my daily work:&lt;/p>
&lt;pre tabindex="0">&lt;code>Usage: r2 [-ACdfLMnNqStuvwzX] [-P patch] [-p prj] [-a arch] [-b bits] [-i file]
 [-s addr] [-B baddr] [-m maddr] [-c cmd] [-e k=v] file|pid|-|--|=
 - same as &amp;#39;r2 malloc://512&amp;#39;
 -a [arch] set asm.arch
 -A run &amp;#39;aaa&amp;#39; command to analyze all referenced code
 -b [bits] set asm.bits
 -B [baddr] set base address for PIE binaries
 -c &amp;#39;cmd..&amp;#39; execute radare command
 -d debug the executable &amp;#39;file&amp;#39; or running process &amp;#39;pid&amp;#39;
 -i [file] run script file
 -k [OS/kern] set asm.os (linux, macos, w32, netbsd, ...)
 -l [lib] load plugin file
 -p [prj] use project, list if no arg, load if no file
 -w open file in write mode
&lt;/code>&lt;/pre></description></item><item><title>[Pragyan CTF] New Avenger</title><link>https://www.megabeets.net/blog/pragyan-ctf-new-avenger/</link><pubDate>Sun, 05 Mar 2017 07:32:29 +0000</pubDate><guid>https://www.megabeets.net/blog/pragyan-ctf-new-avenger/</guid><description>&lt;h2 id="description">Description:&lt;/h2>
&lt;blockquote>
&lt;div class="challenge-description">
 &lt;strong>New Avenger |&lt;/strong> Stego 300 pts
&lt;/div>
&lt;div class="challenge-description">
 The Avengers are scouting for a new member. They have travelled all around the world, looking for suitable candidates for the new position.&lt;br /> Finally, they have found the perfect candidate. But, they are in a bad situation. They do not know who the guy is behind the mask.&lt;br /> Can you help the Avengers to uncover the identity of the person behind the mask ?
&lt;/div>
&lt;div class="challenge-description">
&lt;/div>
&lt;div class="challenge-files">
 &lt;div>
 &lt;span class="challenge-attachment">&lt;a class="has-tooltip" title="" href="https://ctf.pragyan.org/download?file_key=759243671b88bc6c3024e12c1fa580fb4017e7e93f70f0bbe4cbaf3e1ed293bc&amp;team_key=a500afc4a171f394f280518fefd78d62f976bf8303f77f3431573fce01c983cb" data-toggle="tooltip" data-placement="right" data-original-title="2.57 MB">avengers.gif&lt;/a> &lt;/span>
 &lt;/div>
&lt;/div>
&lt;/blockquote>
&lt;div>
&lt;/div>
&lt;div>
 Those of you who read my blog frequently are already know how much I&amp;#8217;m into superheroes. Give me a challenge with superheroes and you bought me. Although I&amp;#8217;m more DC guy, this challenge was with the Marvels and still it was awesome! We&amp;#8217;re given with a gif file. I ran `binwalk` on it to find whether it contains another files within.
&lt;/div>
&lt;div>
 ```diff
Megabeets$ binwalk avengers.gif
&lt;h2 id="decimal---------hex-------------description">DECIMAL HEX DESCRIPTION&lt;/h2>
&lt;p>0 0x0 GIF image data, version 8&amp;quot;9a&amp;quot;, 500 x 272
885278 0xD821E Zip archive data, at least v2.0 to extract, compressed size: 13422, uncompressed size: 13780, name: &amp;ldquo;1_image.jpg&amp;rdquo;
898769 0xDB6D1 Zip archive data, at least v1.0 to extract, compressed size: 1796904, uncompressed size: 1796904, name: &amp;ldquo;image_2.zip&amp;rdquo;&lt;/p></description></item><item><title>[Pragyan CTF] Roller Coaster Ride</title><link>https://www.megabeets.net/blog/pragyan-ctf-roller-coaster-ride/</link><pubDate>Sun, 05 Mar 2017 07:32:28 +0000</pubDate><guid>https://www.megabeets.net/blog/pragyan-ctf-roller-coaster-ride/</guid><description>&lt;h2 id="description">Description:&lt;/h2>
&lt;blockquote>
&lt;p>Bobby has been into Reverse Engineering and Binary Exploitation lately.&lt;br>
One day, he went to an amusement park in his city. It was very famouse for its Roller Coaster Rides.&lt;br>
But, Bobby, being 12 years old, was not allowed on those rides, as it was open for people who were 14 years or older.&lt;br>
This made Bobby very angry. On reaching home, he hacked into the servers of the amusement park, got hold of the validation software for the Roller Coaster rides, and modified it, so that nobody is allowed to have a ride on those Roller Coasters.&lt;/p></description></item><item><title>[Pragyan CTF] Lost Friends</title><link>https://www.megabeets.net/blog/pragyan-ctf-lost-friends/</link><pubDate>Sun, 05 Mar 2017 07:32:22 +0000</pubDate><guid>https://www.megabeets.net/blog/pragyan-ctf-lost-friends/</guid><description>&lt;h2 id="description">Description:&lt;/h2>
&lt;blockquote>
&lt;p>&lt;strong>Lost Friends&lt;/strong> **| **Stego 300&lt;/p>
&lt;p>Moana and her friends were out on a sea voyage, spending their summer joyously.&lt;br>
Unfortnately, they came across Charybdis, the sea monster. Charybdis, furious over having&lt;br>
unknown visitors, wreaked havoc on their ship. The ship was lost.&lt;/p>
&lt;p>Luckily, Moana survived, and she was swept to a nearby island. But, since then, she has not seen her&lt;br>
friends. Moana has come to you for help. She believes that her friends are still alive, and that you are the&lt;br>
only one who can help her find them&lt;/p></description></item><item><title>[Pragyan CTF] The Vault</title><link>https://www.megabeets.net/blog/pragyan-ctf-the-vault/</link><pubDate>Sun, 05 Mar 2017 07:32:17 +0000</pubDate><guid>https://www.megabeets.net/blog/pragyan-ctf-the-vault/</guid><description>&lt;h2 id="description">Description:&lt;/h2>
&lt;blockquote>
&lt;div class="challenge-description">
 [!@# a-z $%^ A-Z &amp;* 0-9] [1,3]
&lt;/div>
&lt;div class="challenge-files">
 &lt;div>
 &lt;span class="challenge-attachment">&lt;a class="has-tooltip" title="" href="https://ctf.pragyan.org/download?file_key=e6ddbdba43b6d7d9261769def938d922071984306d03af07005853c26d0739a4&amp;team_key=a500afc4a171f394f280518fefd78d62f976bf8303f77f3431573fce01c983cb" data-toggle="tooltip" data-placement="right" data-original-title="1.15 KB">file&lt;/a>&lt;/span>
 &lt;/div>
&lt;/div>
&lt;/blockquote>
&lt;div>
&lt;/div>
&lt;div>
&lt;/div>
&lt;div>
 All we got is a file and regular expression.
&lt;/div>
&lt;div>
 Lets run &lt;code>file&lt;/code> command on the file to determine its type:
&lt;/div>
&lt;div>
 ```diff
$ file ./file.kdb
file: Keepass password database 1.x KDB, 3 groups, 4 entries, 50000 key transformation rounds
```
&lt;pre>&lt;code>The file is KDB file which is Keepass password database. Keepass is a famous opensource password manager.

I tried open it using KeePassX for windows, but we need a password to open the database. The password probably should match the regex, so I generated a dictionary with all the possible passwords (more then 300,000 words).
&lt;/code>&lt;/pre>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-python" data-lang="python">&lt;span style="display:flex;">&lt;span>&lt;span style="color:#fff;font-weight:bold">import&lt;/span> string
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#fff;font-weight:bold">import&lt;/span> itertools
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#007f7f"># strings match the regex&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>chars = string.lowercase + string.uppercase + string.digits + &lt;span style="color:#0ff;font-weight:bold">&amp;#39;!@#$%^&amp;amp;*&amp;#39;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>f = &lt;span style="color:#fff;font-weight:bold">open&lt;/span>(&lt;span style="color:#0ff;font-weight:bold">&amp;#39;dict.txt&amp;#39;&lt;/span>,&lt;span style="color:#0ff;font-weight:bold">&amp;#39;a&amp;#39;&lt;/span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>all_permutations = &lt;span style="color:#fff;font-weight:bold">list&lt;/span>(itertools.permutations(chars,&lt;span style="color:#ff0;font-weight:bold">1&lt;/span>))+ &lt;span style="color:#fff;font-weight:bold">list&lt;/span>(itertools.permutations(chars,&lt;span style="color:#ff0;font-weight:bold">2&lt;/span>))+ &lt;span style="color:#fff;font-weight:bold">list&lt;/span>(itertools.permutations(chars,&lt;span style="color:#ff0;font-weight:bold">3&lt;/span>))
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#fff;font-weight:bold">for&lt;/span> p in all_permutations:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> f.write(&lt;span style="color:#0ff;font-weight:bold">&amp;#39;&amp;#39;&lt;/span>.join(p)+&lt;span style="color:#0ff;font-weight:bold">&amp;#39;&lt;/span>&lt;span style="color:#0ff;font-weight:bold">\n&lt;/span>&lt;span style="color:#0ff;font-weight:bold">&amp;#39;&lt;/span>)
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;pre>&lt;code>&amp;amp;nbsp;
&lt;/code>&lt;/pre>
&lt;/div>
&lt;p>And I the ran John the Ripper to crack the password and went to eat lunch.&lt;/p></description></item><item><title>[Pragyan CTF] The Karaboudjan</title><link>https://www.megabeets.net/blog/pragyan-ctf-the-karaboudjan/</link><pubDate>Sun, 05 Mar 2017 07:32:09 +0000</pubDate><guid>https://www.megabeets.net/blog/pragyan-ctf-the-karaboudjan/</guid><description>&lt;h2 id="description">Description&lt;/h2>
&lt;blockquote>
&lt;p>**The Karaboudjan | **Forensics 150 pts&lt;/p>
&lt;p>Captain Haddock is on one of his ship sailing journeys when he gets stranded off the coast of North Korea. He finds shelter off a used nuke and decides to use the seashells to engrave a message on a piece of paper. Decrypt the message and save Captain Haddock.&lt;/p>
&lt;p>-&amp;gt;-.&amp;gt;-.—.–&amp;gt;-.&amp;gt;.&amp;gt;+.–&amp;gt;–..++++.&lt;/p>
&lt;hr class="bbcode_rule" />
&lt;p>.+++.&lt;/p>
&lt;hr class="bbcode_rule" />
&lt;p>.-&amp;gt;-.-&amp;gt;-.++++++++++.+&amp;gt;+++.++.-[-&amp;gt;+++&amp;lt;]&amp;gt;+.+++++.++++++++++..++++[-&amp;gt;+++&amp;lt;]&amp;gt;.–.-&amp;gt;–.&amp;gt;.&lt;/p>
&lt;p>&lt;a class="has-tooltip" title="" href="https://ctf.pragyan.org/download?file_key=c279a3923f124ea36dc67a930a55c996ae14b0661a86f7e61a2db0690d97bd4e&amp;team_key=a500afc4a171f394f280518fefd78d62f976bf8303f77f3431573fce01c983cb" data-toggle="tooltip" data-placement="right" data-original-title="0.28 KB">clue.zip&lt;/a>&lt;/p>
&lt;/blockquote>
&lt;p> &lt;/p>
&lt;p>This was funny challenge, I struggled with that Brainfuck but all it was is just brainfuck. Nothing more, we don’t need it to solve the challenge. Sorry guys.&lt;/p></description></item><item><title>[Pragyan CTF] Evil Corp</title><link>https://www.megabeets.net/blog/pragyan-ctf-evil-corp/</link><pubDate>Sun, 05 Mar 2017 07:31:41 +0000</pubDate><guid>https://www.megabeets.net/blog/pragyan-ctf-evil-corp/</guid><description>&lt;h2 id="description">Description:&lt;/h2>
&lt;blockquote>
&lt;p>fsociety has launched another attack at Evil Corp. However, Evil Corp has decided to encrypt the .dat file with a CBC cipher. Reports reveal that it is not AES and the key is relatively simple, but the IV might be long. And remember, fsociety and evilcorp are closely linked.&lt;/p>
&lt;p>&lt;strong>Hint!&lt;/strong> Snakes serve the fsociety. Hmmm.&lt;/p>
&lt;p>&lt;strong>Hint!&lt;/strong> fsociety and evilcorp are too close, even 16 characters long together. Damn&lt;/p>
&lt;p>&lt;span class="challenge-attachment">&lt;a class="has-tooltip" title="" href="https://ctf.pragyan.org/download?file_key=9939cbc839f8a6439780e2c2eef012464762a396a860469e87f675e1502d0fe5&amp;team_key=a500afc4a171f394f280518fefd78d62f976bf8303f77f3431573fce01c983cb" data-toggle="tooltip" data-placement="right" data-original-title="17.72 KB">fsociety_new.dat&lt;/a> &lt;/span>&lt;/p></description></item><item><title>[Pragyan CTF] Supreme Leader</title><link>https://www.megabeets.net/blog/pragyan-ctf-supreme-leader/</link><pubDate>Sun, 05 Mar 2017 07:31:37 +0000</pubDate><guid>https://www.megabeets.net/blog/pragyan-ctf-supreme-leader/</guid><description>&lt;h2 id="description">Description:&lt;/h2>
&lt;blockquote>
&lt;p>North Korea reportedly has a bioweapon in the making. Hack into their database and steal it.&lt;/p>
&lt;p>Link : &lt;a href="http://139.59.62.216/supreme_leader">http://139.59.62.216/supreme_leader&lt;/a>&lt;/p>
&lt;/blockquote>
&lt;p>For the second web challenge we’re given with a URL, lets open it.&lt;/p>
&lt;img src="./supreme_leader.png" /> 
&lt;p>Cute Kim 🙂&lt;/p>
&lt;p>Now let’d dump the headers of the response using &lt;code>curl&lt;/code>:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-diff" data-lang="diff">&lt;span style="display:flex;">&lt;span>Megabeets$ curl -D - http://139.59.62.216/supreme_leader/
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>HTTP/1.1 200 OK
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Date: Sun, 05 Mar 2017 08:47:14 GMT
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Server: Apache/2.4.7 (Ubuntu)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>X-Powered-By: PHP/5.5.9-1ubuntu4.20
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Set-Cookie: KimJongUn=2541d938b0a58946090d7abdde0d3890_b8e2e0e422cae4838fb788c891afb44f; expires=Sun, 05-Mar-2017 08:47:24 GMT; Max-Age=10
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Set-Cookie: KimJongUn=TooLateNukesGone; expires=Sun, 05-Mar-2017 08:47:25 GMT; Max-Age=10
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Vary: Accept-Encoding
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Content-Length: 1117
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Content-Type: text/html
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p> &lt;/p></description></item><item><title>[Pragyan CTF] Answer To Everything</title><link>https://www.megabeets.net/blog/pragyan-ctf-answer-to-everything/</link><pubDate>Sun, 05 Mar 2017 07:30:52 +0000</pubDate><guid>https://www.megabeets.net/blog/pragyan-ctf-answer-to-everything/</guid><description>&lt;h2 id="description">Description:&lt;/h2>
&lt;blockquote>
&lt;p>Shal has got a binary. It contains the name of a wise man and his flag. He is unable to solve it.&lt;/p>
&lt;p>Submit the flag to unlock the secrets of the universe.&lt;/p>
&lt;p>&lt;span class="challenge-attachment">&lt;a class="has-tooltip" title="" href="https://ctf.pragyan.org/download?file_key=b4e11f9e9abf06eaff141e61d46e57668c1c47d0e4f0db05072de131a07c0af2&amp;team_key=a500afc4a171f394f280518fefd78d62f976bf8303f77f3431573fce01c983cb" data-toggle="tooltip" data-placement="right" data-original-title="8.52 KB">main.exe&lt;/a>&lt;/span>&lt;/p>
&lt;/blockquote>
&lt;p>In this challenge we have a binary, I ran &lt;code>file&lt;/code> command on it:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-diff" data-lang="diff">&lt;span style="display:flex;">&lt;span>Megabeets$ file ./main.exe
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>main.exe: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=4b9b47b7eac612e0c367f0e3a9878eb1f09b841d, not stripped
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>root:/mnt/d/
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p> &lt;/p></description></item><item><title>[Pragyan CTF] Interstellar</title><link>https://www.megabeets.net/blog/pragyan-ctf-interstellar/</link><pubDate>Sun, 05 Mar 2017 07:30:32 +0000</pubDate><guid>https://www.megabeets.net/blog/pragyan-ctf-interstellar/</guid><description>&lt;h2 id="description">Description:&lt;/h2>
&lt;blockquote>
&lt;p>&lt;strong>Forensics 150 pts&lt;/strong>&lt;/p>
&lt;p>Dr. Cooper, on another one of his endless journeys encounter a mysterious planet . However when he tried to land on it, the ship gave way and he was left stranded on the planet . Desperate for help, he relays a message to the mothership containing the details of the people with him . Their HyperPhotonic transmission is 10 times the speed of light, so there is no delay in the message . However, a few photons and magnetic particles interefered with the transmission, causing it to become as shown in the picture . Can you help the scientists on the mothership get back the original image?&lt;/p></description></item><item><title>[Pragyan CTF] Game of Fame</title><link>https://www.megabeets.net/blog/pragyan-ctf-game-of-fame/</link><pubDate>Sun, 05 Mar 2017 07:30:05 +0000</pubDate><guid>https://www.megabeets.net/blog/pragyan-ctf-game-of-fame/</guid><description>&lt;h2 id="description">Description:&lt;/h2>
&lt;blockquote>
&lt;p>p xasc. a zdmik qtng. yiy uist. easc os iye iq trmkbumk. gwv wolnrg kaqcs vi rlr.&lt;/p>
&lt;p>&lt;strong>Hint!&lt;/strong> Robert Sedgewick&lt;/p>
&lt;/blockquote>
&lt;p>To be honest, this challenge was pretty simple. I decrypted the text using online &lt;a href="https://www.guballa.de/vigenere-solver">Vigenere cipher&lt;/a> decrypter, which is the first cipher I try in suchcases, just after Caesar cipher.&lt;/p>
&lt;p>The key was “pragyan” and the result was: &lt;em>“a game. a movie star. his wife. &lt;strong>name of the cs textbook&lt;/strong>. the winner takes it all.”&lt;/em>&lt;/p></description></item><item><title>[33C3 CTF] pay2win Writeup</title><link>https://www.megabeets.net/blog/33c3-ctf-pay2win-writeup/</link><pubDate>Thu, 29 Dec 2016 20:01:12 +0000</pubDate><guid>https://www.megabeets.net/blog/33c3-ctf-pay2win-writeup/</guid><description>&lt;h3 id="description">&lt;strong>Description:&lt;/strong>&lt;/h3>
&lt;blockquote>
&lt;p>pay2win – Web&lt;br>
Do you have enough money to buy the &lt;a href="http://78.46.224.78:5000/">flag&lt;/a>?&lt;/p>
&lt;/blockquote>
&lt;div class="panel panel-primary">
&lt;/div>
&lt;p>This challenge was pretty tricky to understand at the beginning. I solved it with a quick and simple workaround that allowed me to solve the challenge without fully understand it. Once I got the flag I understood the whole story. So as with all the stories, we need to begin from the start.&lt;/p>
&lt;p>We’re given with a website in where we can buy two products: ‘cheap’ (13.37 USD) and ‘flag’ (31337.42 USD). We, of course, want to buy the ‘cheap’ one because we don’t want to spend our money on some leet flag with the answer to life, the universe and blah blah. So — the ‘cheap’ it is.&lt;/p></description></item><item><title>[33C3 CTF] The 0x90s called Writeup</title><link>https://www.megabeets.net/blog/33c3-ctf-the-0x90s-called-writeup/</link><pubDate>Thu, 29 Dec 2016 20:00:28 +0000</pubDate><guid>https://www.megabeets.net/blog/33c3-ctf-the-0x90s-called-writeup/</guid><description>&lt;h3 id="description">&lt;strong>Description:&lt;/strong>&lt;/h3>
&lt;blockquote>
&lt;p>&lt;strong>The 0x90s called – PWN&lt;/strong>&lt;/p>
&lt;p>The 0x90s called, they want their vulns back!&lt;br>
&lt;a href="http://78.46.224.70:8080/">Pwn this and get the flag.&lt;/a> Who would’ve thought?&lt;br>
If you want to try it locally first, &lt;a href="https://33c3ctf.ccc../qemu-xmas-slackware.tar.xz">check this out&lt;/a>.&lt;/p>
&lt;/blockquote>
&lt;p>This challenge was pretty simple and obvious. We are given with a website that is requesting a ‘proof of work’ from us to reduce the load on their infrastructure. We need to press start and then we get a port to which we can connect using &lt;code>netcat&lt;/code>, username and password. We connect to the server and search for the flag.&lt;/p></description></item><item><title>Fantastic Malware and Where to Find Them</title><link>https://www.megabeets.net/blog/fantastic-malware-and-where-to-find-them/</link><pubDate>Wed, 12 Oct 2016 16:39:36 +0000</pubDate><guid>https://www.megabeets.net/blog/fantastic-malware-and-where-to-find-them/</guid><description>&lt;p>&lt;span style="font-size: 12pt;">We, as malware analysts, are always in need of new samples to analyze in order to learn, train or develop new techniques and defenses. One of the most common questions I get is “Where to find malware to analyze?” so I’m sharing here my private collection of repositories, databases and lists which I use on a daily basis. Some of them are updated frequently and some of them are not. The short description under each link wasn’t written by me, it was written by the owners of the repositories.&lt;/span>&lt;/p></description></item><item><title>[H4CK1T 2016] Crypt00perator – Ethiopia Writeup</title><link>https://www.megabeets.net/blog/h4ck1t-2016-crypt00perator-ethiopia-writeup/</link><pubDate>Mon, 03 Oct 2016 22:07:32 +0000</pubDate><guid>https://www.megabeets.net/blog/h4ck1t-2016-crypt00perator-ethiopia-writeup/</guid><description>&lt;h3 style="padding-left: 30px;">
 &lt;strong>Description:&lt;/strong>
&lt;/h3>
&lt;blockquote>
&lt;p>Long time ago one security module has been written. But for now its sources have been missed somehow. We have forgotten th3 access k3y, which, as we remember, has been hardcoded inside the module. Help us to recollect th3 k3y!11&lt;br>
&lt;a href="https://ctf.com.ua/data/attachments/crypt0_0perator_56e0a9f07f54b3634ab5cc2b30e5b29e.exe">crypt0_0perator_56e0a9f07f54b3634ab5cc2b30e5b29e.exe&lt;/a>&lt;/p>
&lt;p>&lt;span style="font-weight: 400;">h4ck1t{…}&lt;/span>&lt;/p>
&lt;/blockquote>
&lt;p>This is a pretty basic reverse challenge. We can solve it in many different ways but I will show you only two of them. The first one is the quickest method that will work only for this challenge, and the second is for those of you who want to understand better how to solve such challenges in the future.&lt;/p></description></item><item><title>[H4CK1T 2016] QRb00k – Russia Writeup</title><link>https://www.megabeets.net/blog/h4ck1t-2016-qrb00k-russia-writeup/</link><pubDate>Mon, 03 Oct 2016 00:35:37 +0000</pubDate><guid>https://www.megabeets.net/blog/h4ck1t-2016-qrb00k-russia-writeup/</guid><description>&lt;h3 id="description">&lt;strong>Description:&lt;/strong>&lt;/h3>
&lt;blockquote>
&lt;p>&lt;strong>Task: QRb00k – Russia – W3b – 400&lt;/strong>&lt;br>
&lt;span style="font-weight: 400;">The secured messenger was developed in Canada, it’s using systems with qr keys for communicating, it allows to read other people’s messages only to this key holders. But is it true? And you have to figure it out …&lt;/span>&lt;br>
&lt;a href="http://hack-quest.com/">&lt;span style="font-weight: 400;">http://hack-quest.com&lt;/span>&lt;/a>&lt;/p>
&lt;/blockquote>
&lt;p>This was a very good web challenge. It took me quite a time to fully understand it but was absolutely worth of its 400 points.&lt;/p></description></item><item><title>[H4CK1T 2016] ch17ch47 – Germany Writeup</title><link>https://www.megabeets.net/blog/h4ck1t-2016-ch17ch47-germany-writeup/</link><pubDate>Mon, 03 Oct 2016 00:30:10 +0000</pubDate><guid>https://www.megabeets.net/blog/h4ck1t-2016-ch17ch47-germany-writeup/</guid><description>&lt;h3 id="description">&lt;strong>Description:&lt;/strong>&lt;/h3>
&lt;blockquote>
&lt;p>&lt;strong>ch17ch47 – Germany – 200 – Forensics&lt;/strong>&lt;br>
&lt;span style="font-weight: 400;">Find out who is the recipient of the information from the agent.&lt;/span>&lt;br>
&lt;a href="http://ctf.com.ua/data/attachments/CorpUser.zip">&lt;span style="font-weight: 400;">http://ctf.com.ua/data/attachments/CorpUser.zip&lt;/span>&lt;/a>&lt;/p>
&lt;/blockquote>
&lt;p>This challenge was &lt;a href="http://www.megabeets.net/h4ck1t-2016-1n51d3r5-j0b-canada/">second&lt;/a> in this CTF which took me no more then five simple and basic commands in order to get the flag.&lt;/p>
&lt;p>I roughly follow the same simple system whenever I face a new challenge. This system has prove itself again and again in almost any kind of challenge in different levels.&lt;/p></description></item><item><title>[H4CK1T 2016] 1magePr1son- Mozambique Writeup</title><link>https://www.megabeets.net/blog/h4ck1t-2016-1magepr1son-mozambique-writeup/</link><pubDate>Mon, 03 Oct 2016 00:10:42 +0000</pubDate><guid>https://www.megabeets.net/blog/h4ck1t-2016-1magepr1son-mozambique-writeup/</guid><description>&lt;h3 id="description">&lt;strong>Description:&lt;/strong>&lt;/h3>
&lt;blockquote>
&lt;p>&lt;strong>Task: 1magePr1son- Nozambique- Stego- 150&lt;/strong>&lt;/p>
&lt;p>&lt;span style="font-weight: 400;">Implementing of the latest encryption system as always brought a set of problems for one of the known FSI services: they have lost the module which is responsible for decoding information. And some information has been already ciphered! Your task for today: to define a cryptoalgorithm and decode the message.&lt;/span>&lt;br>
&lt;span style="font-weight: 400;">&lt;a href="https://ctf.com.ua/data/attachments/planet_982680d78ab9718f5a335ec05ebc4ea2.png.zip">https://ctf.com.ua/data/attachments/planet_982680d78ab9718f5a335ec05ebc4ea2.png.zip&lt;/a>&lt;/span>&lt;br>
&lt;span style="font-weight: 400;">h4ck1t{str(flag).upper()}&lt;/span>&lt;br>
&lt;a href="https://ctf.com.ua/data/attachments/planet_982680d78ab9718f5a335ec05ebc4ea2.png.zip">&lt;span style="font-weight: 400;">https://ctf.com.ua/data/attachments/planet_982680d78ab9718f5a335ec05ebc4ea2.png.zip&lt;/span>&lt;/a>&lt;/p>
&lt;/blockquote>
&lt;p>For the start we are given with a wallpaper image named &lt;em>planet.png&lt;/em> (2560×1850)&lt;/p></description></item><item><title>[H4CK1T 2016] v01c3_0f_7h3_fu7ur3 – Australia Writeup</title><link>https://www.megabeets.net/blog/h4ck1t-2016-v01c3_0f_7h3_fu7ur3-australia-writeup/</link><pubDate>Sun, 02 Oct 2016 23:02:06 +0000</pubDate><guid>https://www.megabeets.net/blog/h4ck1t-2016-v01c3_0f_7h3_fu7ur3-australia-writeup/</guid><description>&lt;h3 id="description">&lt;strong>Description:&lt;/strong>&lt;/h3>
&lt;blockquote>
&lt;p>&lt;strong>v01c3_0f_7h3_fu7ur3 – Australia – 300 – Network&lt;/strong>&lt;br>
&lt;span style="font-weight: 400;">The captured data contains encrypted information. Decrypt it.&lt;/span>&lt;br>
&lt;span style="font-weight: 400;">&lt;a href="http://ctf.com.ua/data/attachments/wireshark_8764d640d217fd346e2db2b5c38dde13.pcap">&lt;a href="http://ctf.com.ua/data/attachments/wireshark_8764d640d217fd346e2db2b5c38dde13.pcap">http://ctf.com.ua/data/attachments/wireshark_8764d640d217fd346e2db2b5c38dde13.pcap&lt;/a>&lt;/a>&lt;/span>&lt;/p>
&lt;/blockquote>
&lt;p>The first thing I do when I face a pcap challenge is, of course, open it in Wireshark. If it looks normal (and not, for example, &lt;a href="http://www.megabeets.net/asis-ctf-skyblue/">Bluetooth traffic&lt;/a>) I then run ‘&lt;em>foremost&lt;/em>‘ on the file. ‘&lt;em>foremost&lt;/em>‘ is searching for a known files in a given file by file headers, footers etc, and then extract it to ‘output’ folder in the directory.&lt;br>
So foremost found several files in the PCAP from several sources like http and ftp traffic&lt;/p></description></item><item><title>[H4CK1T 2016] Belarus – Electronicon Writeup</title><link>https://www.megabeets.net/blog/h4ck1t-2016-belarus-electronicon-writeup/</link><pubDate>Sun, 02 Oct 2016 22:23:53 +0000</pubDate><guid>https://www.megabeets.net/blog/h4ck1t-2016-belarus-electronicon-writeup/</guid><description>&lt;h3 id="description">&lt;strong>Description:&lt;/strong>&lt;/h3>
&lt;blockquote>
&lt;p>&lt;strong>Belarus – Electronicon – PPC – 250 pts&lt;/strong>&lt;br>
EN: This task is one of the methods for the psychological attacks. It is intended for people who don’t have heart diseases and reached 18 years 😉&lt;/p>
&lt;p>h4ck1t{flag.upper()}&lt;/p>
&lt;p>&lt;a href="https://ctf.com.ua/data/attachments/pain.txt">paint.txt&lt;/a>&lt;/p>
&lt;/blockquote>
&lt;p>As the attached file says, it was real pain. I opened the file in the browser and saw this horrible thing:&lt;/p>
&lt;img src="./h4ck1t_belarus_1.png" /> 
&lt;p>Looks bad and it crashed my browser. This text file was too big for it to handle. So I opened it on Notepad++ and it was’t any better:&lt;/p></description></item><item><title>[H4CK1T 2016] 1n51d3r’5 j0b – Canada Writeup</title><link>https://www.megabeets.net/blog/h4ck1t-2016-1n51d3r5-j0b-canada-writeup/</link><pubDate>Sun, 02 Oct 2016 21:26:53 +0000</pubDate><guid>https://www.megabeets.net/blog/h4ck1t-2016-1n51d3r5-j0b-canada-writeup/</guid><description>&lt;h3 id="description">&lt;strong>Description:&lt;/strong>&lt;/h3>
&lt;blockquote>
&lt;p>&lt;strong>1n51d3r’5 j0b – Canada – 300 – Forensics&lt;/strong>&lt;br>
&lt;span style="font-weight: 400;">Tommy wrote a program. It seems he has hidden from us important information. Find out what Tommy hides.&lt;/span>&lt;br>
&lt;a href="http://ctf.com.ua/data/attachments/Tommy_2e00c18e3a480959ba5fb4f65ff7f2b7.zip">&lt;span style="font-weight: 400;">http://ctf.com.ua/data/attachments/Tommy_2e00c18e3a480959ba5fb4f65ff7f2b7.zip&lt;/span>&lt;/a>&lt;/p>
&lt;/blockquote>
&lt;p>Oh god, this challenge was so fun. The easiest 300 point I’ve ever got. I’m sure it wasn’t the expected solution but it works so who am I to complain. Three commands, that’s all.&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>Megabeets:/tmp/h4ckit/canada# unzip Tommy_2e00c18e3a480959ba5fb4f65ff7f2b7.zip
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Archive: Tommy_2e00c18e3a480959ba5fb4f65ff7f2b7.zip
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> creating: 300/
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> inflating: 300/out.txt
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> inflating: 300/parse
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Megabeets:/tmp/h4ckit/canada# ll
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>total &lt;span style="color:#ff0;font-weight:bold">628&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>drwxrwxrwx &lt;span style="color:#ff0;font-weight:bold">2&lt;/span> root root &lt;span style="color:#ff0;font-weight:bold">0&lt;/span> Oct &lt;span style="color:#ff0;font-weight:bold">3&lt;/span> 00:22 ./
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>drwxrwxrwx &lt;span style="color:#ff0;font-weight:bold">2&lt;/span> root root &lt;span style="color:#ff0;font-weight:bold">0&lt;/span> Oct &lt;span style="color:#ff0;font-weight:bold">2&lt;/span> 16:04 ../
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>drwxrwxrwx &lt;span style="color:#ff0;font-weight:bold">2&lt;/span> root root &lt;span style="color:#ff0;font-weight:bold">0&lt;/span> Sep &lt;span style="color:#ff0;font-weight:bold">24&lt;/span> 18:17 300/
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>-rwxrwxrwx &lt;span style="color:#ff0;font-weight:bold">1&lt;/span> root root &lt;span style="color:#ff0;font-weight:bold">634168&lt;/span> Sep &lt;span style="color:#ff0;font-weight:bold">28&lt;/span> 20:42 Tommy_2e00c18e3a480959ba5fb4f65ff7f2b7.zip*
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Megabeets:/tmp/h4ckit/canada# strings /300/parse | grep -i h4ck1t{
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>...h4ck1t{T0mmy_g0t_h1s_Gun}...
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>I don’t even know what the challenge is about. Just moved to the next challenge without asking any unnecessary questions.&lt;/p></description></item><item><title>[H4CK1T 2016] HellMath – Mongolia Writeup</title><link>https://www.megabeets.net/blog/h4ck1t-2016-hellmath-mongolia-writeup/</link><pubDate>Sun, 02 Oct 2016 21:14:57 +0000</pubDate><guid>https://www.megabeets.net/blog/h4ck1t-2016-hellmath-mongolia-writeup/</guid><description>&lt;h3 id="description">&lt;strong>Description:&lt;/strong>&lt;/h3>
&lt;blockquote>
&lt;p>&lt;strong>HellMath – Mongolia – 100 – PPC –&lt;/strong> &lt;strong>NEW&lt;/strong>&lt;/p>
&lt;p>&lt;span style="font-weight: 400;">EN: Somebody thinks that you are able to calculate well. Is it true? Pass this task, prove the abilities and maybe we will recommend you to one of the most secret missions in this war.&lt;/span>&lt;/p>
&lt;p>&lt;span style="font-weight: 400;"># nc ctf.com.ua 9988 #&lt;/span>&lt;/p>
&lt;/blockquote>
&lt;p>This one was a tricky question. Sometime we tend to think too complicated that we forget the basics of the basics.&lt;/p></description></item><item><title>[H4CK1T 2016] Pentest – Mexico Writeup</title><link>https://www.megabeets.net/blog/h4ck1t-2016-pentest-mexico-writeup/</link><pubDate>Sun, 02 Oct 2016 20:54:26 +0000</pubDate><guid>https://www.megabeets.net/blog/h4ck1t-2016-pentest-mexico-writeup/</guid><description>&lt;h3 id="description">&lt;strong>Description:&lt;/strong>&lt;/h3>
&lt;blockquote>
&lt;p>&lt;strong>Task: Remote pentest – Mexico – 150 – Web&lt;/strong>&lt;/p>
&lt;p>&lt;span style="font-weight: 400;">Our foreign partners have some problems with qualified staff in the field of information technology, we decided to help them and to conduct remote testing of their new website. Your task is to find a hole in the system and grab some information to confirm the hack .Good luck !&lt;/span>&lt;br>
&lt;a href="http://91.231.84.36:9150/">&lt;span style="font-weight: 400;">http://91.231.84.36:9150/&lt;/span>&lt;/a>&lt;/p>
&lt;/blockquote>
&lt;p>YAY! Web challenge! If you are following my blog &lt;span style="font-size: 10pt;">&lt;em>(If not, the subscribe form is on left)&lt;/em>&lt;/span> you already know how much I love web challenges, It’s either easy points or great puzzle.&lt;/p></description></item><item><title>[H4CK1T 2016] PhParanoid – Malaysia Writeup</title><link>https://www.megabeets.net/blog/h4ck1t-2016-phparanoid-malaysia-writeup/</link><pubDate>Sun, 02 Oct 2016 20:35:48 +0000</pubDate><guid>https://www.megabeets.net/blog/h4ck1t-2016-phparanoid-malaysia-writeup/</guid><description>&lt;p> &lt;/p>
&lt;h3 id="description">&lt;strong>Description&lt;/strong>:&lt;/h3>
&lt;blockquote>
&lt;p>&lt;strong>Task: PhParanoid – Malaysia – 225 – Rever$e&lt;/strong>&lt;/p>
&lt;p>&lt;span style="font-weight: 400;">EN: I am so paranoid! I try to hide everything from this mad world! I have already obfuscated my calculator sources, my javascript site sources and I`m not going to stop! And u will never know what I hide, haha!&lt;/span>&lt;/p>
&lt;/blockquote>
&lt;p>In this challenge we got &lt;em>Phb&lt;/em>, i.e php file that compiled using BCompiler (PHP Bytecode Compiler). We can Decompile it using &lt;a href="https://bitbucket.org/xdasm/decompiler/issues/49/bcompiler-list">this&lt;/a>.&lt;/p></description></item><item><title>[H4CK1T 2016] Hex0gator – Paraguay Writeup</title><link>https://www.megabeets.net/blog/h4ck1t-2016-hex0gator-paraguay-writeup/</link><pubDate>Sun, 02 Oct 2016 20:33:31 +0000</pubDate><guid>https://www.megabeets.net/blog/h4ck1t-2016-hex0gator-paraguay-writeup/</guid><description>&lt;h3 id="description">&lt;strong>Description:&lt;/strong>&lt;/h3>
&lt;blockquote>
&lt;p>EN: All Experts of The Silver Shield Project can’t decipher the intercepted data. Who knows, maybe you can do it?&lt;br>
&lt;a href="https://ctf.com.ua/data/attachments/100_00edb54bed7e46bd5cdb7c06059881c2">&lt;span style="font-weight: 400;">100_00edb54bed7e46bd5cdb7c06059881c2&lt;/span>&lt;/a>&lt;/p>
&lt;/blockquote>
&lt;p> &lt;/p>
&lt;p>In this PPC 250 pts challenge we got only one file. Let’s run &lt;em>File&lt;/em> command on it to determine it’s type.&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>Megabeets:/tmp/h4ckit/paraguay# file 100_00edb54bed7e46bd5cdb7c06059881c2
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>100_00edb54bed7e46bd5cdb7c06059881c2: Zip archive data, at least v2.0 to extract
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p> &lt;/p>
&lt;p>This is a zip file which contains another folder within. The folder contains a file named ‘&lt;em>99&lt;/em>‘. Let’s extract it and figure out it’s type:&lt;/p></description></item><item><title>[H4CK1T 2016] T3legr4m – United States Writeup</title><link>https://www.megabeets.net/blog/h4ck1t-2016-t3legr4m-united-states-writeup/</link><pubDate>Sun, 02 Oct 2016 20:29:27 +0000</pubDate><guid>https://www.megabeets.net/blog/h4ck1t-2016-t3legr4m-united-states-writeup/</guid><description>&lt;h3 id="description">&lt;strong>Description:&lt;/strong>&lt;/h3>
&lt;blockquote>
&lt;p>&lt;strong>T3legr4m – United States – 50 – J0y&lt;/strong>&lt;br>
&lt;span style="font-weight: 400;">Join us in SUPER TOP SECRET telegram chat!!&lt;/span>&lt;br>
&lt;span style="font-weight: 400;">&lt;a href="https://telegram.me/hackitctf">https://telegram.me/hackitctf&lt;/a>&lt;/span>&lt;/p>
&lt;/blockquote>
&lt;p>In order to solve this challenge you need to join the &lt;a href="https://telegram.org/">Telegram&lt;/a> group and go to Group Info.&lt;/p>
&lt;p>The group description is the flag:&lt;/p>
&lt;div id="attachment_486" style="width: 478px" class="wp-caption alignnone">
 &lt;img src="./h4ck1t_usa.png" />
 &lt;p id="caption-attachment-486" class="wp-caption-text">
 H4CK1T T3legr4m
 &lt;/p>
&lt;/div>
&lt;p>&lt;strong>Flag:&lt;/strong> &lt;em>h4ck1t{fr33_4nd_$ecur3!}&lt;/em>&lt;/p></description></item><item><title>[CSAW 2016] Gametime Writeup</title><link>https://www.megabeets.net/blog/csaw-2016-gametime-writeup/</link><pubDate>Sun, 18 Sep 2016 22:03:30 +0000</pubDate><guid>https://www.megabeets.net/blog/csaw-2016-gametime-writeup/</guid><description>&lt;h4 id="description">&lt;strong>Description:&lt;/strong>&lt;/h4>
&lt;blockquote>
&lt;p>&lt;em>Guess what time it is! That’s right! Gametime! Wowwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww!!!!!!!!!!!!&lt;/em>&lt;/p>
&lt;p>&lt;em>Author: Brad Antoniewicz&lt;/em>&lt;/p>
&lt;p>&lt;em>note: flag is not in &lt;code>flag{}&lt;/code> format&lt;/em>&lt;/p>
&lt;p>&lt;em>&lt;a class="chal-file" href="https://ctf.csaw.io/stat./121e6daf97e57856de8183ba1e56e55b/gametime.exe" target="_blank">gametime.exe&lt;/a>&lt;/em>&lt;/p>
&lt;/blockquote>
&lt;div class="chal-files">
&lt;/div>
&lt;div class="chal-files">
 To be honest, I downloaded the file, played the game once and got the key. It is possible for humans to win the game, or maybe it&amp;#8217;s just my Super-Vegan powers LOL.
&lt;/div>
&lt;div class="chal-files">
 But I wanted, of course, to get the key using RE. I opened IDA and searched for interesting strings.
&lt;/div>
&lt;div class="chal-files">
&lt;/div>
&lt;div class="chal-files">
 ```asm
.rdata:00A17858 00000014 C \rGet ready to play\n 
.rdata:00A1786C 00000034 C \rZOMGZOMGOZMGKZOMGZOMGOZMGZOMGZOMGOZMGZOMGZOMGOZMG\n 
... 
.rdata:00A17970 00000033 C \rZOMGZOMG YOU DID IT!!! ZOMGOZMG\n 
.rdata:00A179A4 00000033 C \rZOMGZOMGOZMGZOMGZOMGOZMGZOMGZOMGOZMGZOMGZOMGOZMG\n 
... 
.rdata:00A179E0 0000000F C key is %s (%s) 
.rdata:00A179F4 0000002C C \nWhen you see an 's', press the space bar\n\n 
.rdata:00A17A20 0000002C C \nWhen you see an '%c', press the '%c' key\n\n 
.rdata:00A17A50 00000010 C key is %s (%s)\r 
.rdata:00A17A60 0000002B C \rUDDER FAILURE! http://imgur.com/4Ajx21P \n 
.rdata:00A17A8C 00000024 C \r \r 
.rdata:00A17AB0 0000002A C UDDER FAILURE! http://imgur.com/4Ajx21P \n 
.rdata:00A17ADC 00000005 C %02x 
.rdata:00A17AEC 00000034 C \r\tZOMGZOMGOZMGZOMGZOMGOZMGZOMGZOMGOZMGZOMGZOMGOZMG\n 
.rdata:00A17B20 00000010 C \tkey is %s (%s) 
.rdata:00A17B30 00000034 C \r\tZOMGZOMG ZOMGZOMG\n 
.rdata:00A17B64 00000034 C \r\tZOMGZOMG TAP TAP REVOLUTION!!!!!!! ZOMGZOMG\n 
.rdata:00A17B98 00000036 C \r\tZOMGZOMGOZMGZOMGZOMGOZMGZOMGZOMGOZMGZOMGZOMGOZMG\n\n\n
.rdata:00A17BD0 00000020 C \r\t R U READDY?!\n\n\n 
.rdata:00A17BF0 0000001D C \rThe game is starting in...\n 
.rdata:00A17C10 00000033 C \rTRAINING COMPLETE! \n 
.rdata:00A17C48 0000002A C \rNow you know everything you need to know 
.rdata:00A17C74 0000001F C \n\n\nfor the rest of your life!\n 
.rdata:00A17C94 0000000D C LETS PLAY !\n 
.rdata:00A17CA4 00000016 C \rooooh, you fancy!!!\n 
.rdata:00A17CBC 00000011 C NIIICE JOB)!!!!\n 
.rdata:00A17CD0 00000012 C \rTURBO TIME! \n
```
&lt;pre>&lt;code>I highlighted the important lines: The success message (I know, I got it when I played) and the failure messages. Using X-Refs I found where the failure messages are printed out and patched the program to jump to the success instead. Notice that you&amp;amp;#8217;ll need to change &amp;lt;strong&amp;gt;two&amp;lt;/strong&amp;gt; functions.

&amp;lt;strong&amp;gt;1st jump to change:&amp;lt;/strong&amp;gt;

&amp;lt;img src=&amp;quot;./gametime_1.png&amp;quot; /&amp;gt;

&amp;lt;strong&amp;gt;2nd jump to change:&amp;lt;/strong&amp;gt;

&amp;lt;img src=&amp;quot;./gametime_2.png&amp;quot; /&amp;gt;
&lt;/code>&lt;/pre>
&lt;/div>
&lt;p>Now apply the patches to the program and run it. Let the game play alone and the key will be printed.&lt;/p></description></item><item><title>[CSAW 2016] Key Writeup</title><link>https://www.megabeets.net/blog/csaw-2016-key-writeup/</link><pubDate>Sun, 18 Sep 2016 22:02:54 +0000</pubDate><guid>https://www.megabeets.net/blog/csaw-2016-key-writeup/</guid><description>&lt;h4 id="description">&lt;strong>Description:&lt;/strong>&lt;/h4>
&lt;blockquote>
&lt;p>&lt;em>So I like to make my life difficult, and instead of a password manager, I make challenges that keep my secrets hidden. I forgot how to solve this one and it is the key to my house… Can you help me out? It’s getting a little cold out here.&lt;/em>&lt;/p>
&lt;p>&lt;em>NOTE: Flag is not in normal flag format.&lt;/em>&lt;/p>
&lt;div class="chal-files">
 &lt;em>&lt;a class="chal-file" href="https://ctf.csaw.io/stat./6c3bc1cb1618348f549dd059ed2bf23d/key.exe" target="_blank">key.exe&lt;/a>&lt;/em>
&lt;/div>
&lt;/blockquote>
&lt;div class="chal-files">
&lt;/div>
&lt;div class="chal-files">
 Running the file we end up with a message: &amp;#8220;?W?h?a?t h?a?p?p?e?n?&amp;#8221;
&lt;/div>
&lt;div class="chal-files">
 Let&amp;#8217;s open the exe in IDA and view it&amp;#8217;s strings looking for interesting strings.
&lt;/div>
&lt;div class="chal-files">
&lt;/div>
&lt;div class="chal-files">
 ```asm
.rdata:00AB52B8 00000029 C C:\\Users\\CSAW2016\\haha\\flag_dir\\flag.txt
.rdata:00AB52E4 00000016 C ?W?h?a?t h?a?p?p?e?n? 
.rdata:00AB52FC 00000021 C |------------------------------| 
.rdata:00AB5320 00000021 C |==============================| 
.rdata:00AB5344 00000021 C \\ /\\ /\\ /\\ /\\==============| 
.rdata:00AB5368 00000021 C \\/ \\/ \\/ \\/ \\=============| 
.rdata:00AB538C 00000021 C |-------------| 
.rdata:00AB53B0 00000015 C Congrats You got it! 
.rdata:00AB53C8 00000012 C =W=r=o=n=g=K=e=y=
```
&lt;pre>&lt;code>We have 4 interesting strings:
&lt;/code>&lt;/pre>
 &lt;ul>
 &lt;li>
 &lt;strong>A path: &lt;/strong>C:\\Users\\CSAW2016\\haha\\flag_dir\\flag.txt
 &lt;/li>
 &lt;li>
 &lt;strong>The known message: &lt;/strong>?W?h?a?t h?a?p?p?e?n?
 &lt;/li>
 &lt;li>
 &lt;strong>Good key: &lt;/strong>Congrats You got it!
 &lt;/li>
 &lt;li>
 &lt;strong>Bad key:&lt;/strong> =W=r=o=n=g=K=e=y=
 &lt;/li>
 &lt;/ul>
&lt;pre>&lt;code>Visiting the function that uses the path string (X-ref) we understand the program is trying to read the key from it, if it doesn&amp;amp;#8217;t exists we would get: ?W?h?a?t h?a?p?p?e?n?

I Created the txt file with &amp;amp;#8220;aaa&amp;amp;#8221; inside and ran again, this time I set a breakpoint before the decision whether to jump to the success or failure message.

&amp;lt;img src=&amp;quot;./asm_key_csaw.png&amp;quot; /&amp;gt;

Now let&amp;amp;#8217;s see what we have in what seem like the comparison function.

Stepping the lines we can see that my &amp;amp;#8220;aaa&amp;amp;#8221; is compared with a string.

&amp;lt;img src=&amp;quot;./csaw_key_eax.png&amp;quot; /&amp;gt;

This string is the key &amp;amp;#8220;&amp;lt;em&amp;gt;idg_cni~bjbfi|gsxb&amp;lt;/em&amp;gt;&amp;amp;#8221; and also the flag to the challenge.

&amp;amp;nbsp;
&lt;/code>&lt;/pre>
 &lt;div class="nf-post-footer">
 &lt;p style="text-align: right">
 &lt;a href="https://www.megabeets.net/vegan/">&lt;img src="./megabeets_inline_logo.png" />Eat Veggies&lt;/a>
 &lt;/p></description></item><item><title>[CSAW 2016] Sleeping Guard Writeup</title><link>https://www.megabeets.net/blog/csaw-2016-sleeping-guard-writeup/</link><pubDate>Sun, 18 Sep 2016 22:02:43 +0000</pubDate><guid>https://www.megabeets.net/blog/csaw-2016-sleeping-guard-writeup/</guid><description>&lt;p>&lt;strong>Description:&lt;/strong>&lt;/p>
&lt;blockquote>
&lt;p>&lt;em>Only true hackers can see the image in this magic PNG….&lt;/em>&lt;br>
&lt;em>nc crypto.chal.csaw.io 8000&lt;/em>&lt;/p>
&lt;p>&lt;em>Author: Sophia D’Antoine&lt;/em>&lt;br>
&lt;em>&lt;a class="chal-file" href="https://ctf.csaw.io/stat./69a76e75bc0277cb8ead3782870dee13/sleeping_dist.py" target="_blank">sleeping_dist.py&lt;/a>&lt;/em>&lt;/p>
&lt;/blockquote>
&lt;p>We are given with python script, Netcat command and a hint about a PNG file. Let’s run Netcat and see what we will get:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-vim" data-lang="vim">&lt;span style="display:flex;">&lt;span>[Megabeets] &lt;span style="color:#0ff;font-weight:bold">/tmp/&lt;/span>CSAW/clam# nc crypto.chal.csaw.io &lt;span style="color:#ff0;font-weight:bold">8000&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#ff0;font-weight:bold">3&lt;/span>j&lt;span style="color:#ff0;font-weight:bold">8&lt;/span>PL&lt;span style="color:#ff0;font-weight:bold">1&lt;/span>JLRUFleSEyHicFOl&lt;span style="color:#ff0;font-weight:bold">9&lt;/span>BXrdleSGXX&lt;span style="color:#ff0;font-weight:bold">2&lt;/span>lBaF&lt;span style="color:#ff0;font-weight:bold">9&lt;/span>EZRcjeSE&lt;span style="color:#0ff;font-weight:bold">/UwgAJR5BX/&lt;/span>rqct1eUm9BaH8iFxkoeSFFcW9B6NtBX7FleSG&lt;span style="color:#0ff;font-weight:bold">/v29BHW9BX6EFeSEFz29Bfy/&lt;/span>d5RpZeSE&lt;span style="color:#0ff;font-weight:bold">/Xh8JMSxBX1kReSEtI26fDkA5X0tkIEhrDxsZJRN7PCQIV0BbOA0kRicsL0tleSE/&lt;/span>axd7EDIxMi4RGAFHOgMvG2U5YmkEHU5
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>...
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&amp;lt;alot of base64 text here&amp;gt;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>...
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>We received a base64 encoded text from the server. It is probably our image so let’s decode it and save it to file:&lt;/p></description></item><item><title>[CSAW 2016] mfw Writeup</title><link>https://www.megabeets.net/blog/csaw-2016-mfw-writeup/</link><pubDate>Sun, 18 Sep 2016 22:02:18 +0000</pubDate><guid>https://www.megabeets.net/blog/csaw-2016-mfw-writeup/</guid><description>&lt;h4 id="description">&lt;strong>Description:&lt;/strong>&lt;/h4>
&lt;blockquote>
&lt;p>Hey, I made my first website today. It’s pretty cool and web7.9.&lt;br>
&lt;a href="http://web.chal.csaw.io:8000/">http://web.chal.csaw.io:8000/&lt;/a>&lt;/p>
&lt;/blockquote>
&lt;p> &lt;/p>
&lt;p>Entering the site, the first thing that comes to mind is a LFI attack. The site is including a page which is requested in the URL.&lt;/p>
&lt;p>The following table describes the possible respond pages:&lt;/p>
&lt;table style="width: 945px;">
 &lt;tr>
 &lt;td style="width: 418.869px;">
 &lt;strong>URL&lt;/strong>
 &lt;/td>
&lt;pre>&lt;code>&amp;lt;td style=&amp;quot;width: 484.131px;&amp;quot;&amp;gt;
 &amp;lt;strong&amp;gt;Result&amp;lt;/strong&amp;gt;
&amp;lt;/td&amp;gt;
&lt;/code>&lt;/pre>
 &lt;/tr>
 &lt;tr>
 &lt;td style="width: 418.869px;">
 http://web.chal.csaw.io:8000/?page=home
 &lt;/td>
&lt;pre>&lt;code>&amp;lt;td style=&amp;quot;width: 484.131px;&amp;quot;&amp;gt;
 The &amp;amp;#8220;home&amp;amp;#8221; page is shown.
&amp;lt;/td&amp;gt;
&lt;/code>&lt;/pre>
 &lt;/tr>
 &lt;tr>
 &lt;td style="width: 418.869px;">
 http://web.chal.csaw.io:8000/?page=about
 &lt;/td>
&lt;pre>&lt;code>&amp;lt;td style=&amp;quot;width: 484.131px;&amp;quot;&amp;gt;
 The &amp;amp;#8220;about&amp;amp;#8221; page is shown.
&amp;lt;/td&amp;gt;
&lt;/code>&lt;/pre>
 &lt;/tr>
 &lt;tr>
 &lt;td style="width: 418.869px;">
 http://web.chal.csaw.io:8000/?page=contact
 &lt;/td>
&lt;pre>&lt;code>&amp;lt;td style=&amp;quot;width: 484.131px;&amp;quot;&amp;gt;
 The &amp;amp;#8220;contact&amp;amp;#8221; page is shown.
&amp;lt;/td&amp;gt;
&lt;/code>&lt;/pre>
 &lt;/tr>
 &lt;tr>
 &lt;td style="width: 418.869px;">
 http://web.chal.csaw.io:8000/?page=Megabeets
 &lt;/td>
&lt;pre>&lt;code>&amp;lt;td style=&amp;quot;width: 484.131px;&amp;quot;&amp;gt;
 Just a message saying: &amp;amp;#8220;That file doesn&amp;amp;#8217;t exist!&amp;amp;#8221;
&amp;lt;/td&amp;gt;
&lt;/code>&lt;/pre>
 &lt;/tr>
 &lt;tr>
 &lt;td style="width: 418.869px;">
 http://web.chal.csaw.io:8000/?page=flag
 &lt;/td>
&lt;pre>&lt;code>&amp;lt;td style=&amp;quot;width: 484.131px;&amp;quot;&amp;gt;
 An empty page is shown &amp;lt;strong&amp;gt;inside &amp;lt;/strong&amp;gt;the website.
&amp;lt;/td&amp;gt;
&lt;/code>&lt;/pre>
 &lt;/tr>
 &lt;tr>
 &lt;td style="width: 418.869px;">
 http://web.chal.csaw.io:8000/?page=../../../../etc/passwd
 &lt;/td>
&lt;pre>&lt;code>&amp;lt;td style=&amp;quot;width: 484.131px;&amp;quot;&amp;gt;
 Just a message saying: &amp;amp;#8220;Detected hacking attempt!&amp;amp;#8221;
&amp;lt;/td&amp;gt;
&lt;/code>&lt;/pre>
 &lt;/tr>
&lt;/table>
&lt;p>Looking at the source code i saw the following comment:&lt;/p></description></item><item><title>[CSAW 2016] PWN: Warmup Writeup</title><link>https://www.megabeets.net/blog/csaw-2016-pwn-warmup-writeup/</link><pubDate>Sun, 18 Sep 2016 22:01:55 +0000</pubDate><guid>https://www.megabeets.net/blog/csaw-2016-pwn-warmup-writeup/</guid><description>&lt;h4 id="description">&lt;strong>Description:&lt;/strong>&lt;/h4>
&lt;blockquote>
&lt;p>&lt;em>So you want to be a pwn-er huh? Well let’s throw you an easy one 😉&lt;/em>&lt;br>
&lt;em>nc pwn.chal.csaw.io 8000&lt;/em>&lt;/p>
&lt;p>&lt;em>&lt;a class="chal-file" href="https://ctf.csaw.io/stat./8ef117ec4c05f79aebdf043f3d003c2b/warmup" target="_blank">warmup&lt;/a>&lt;/em>&lt;/p>
&lt;/blockquote>
&lt;p>Let’s connect to the server and play with it a little bit:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>[Meabeets] /tmp/CSAW/Warmup# nc pwn.chal.csaw.io &lt;span style="color:#ff0;font-weight:bold">8000&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>-Warm Up-
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>WOW:0x40060d
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&amp;gt;Beet
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>[Meabeets] /tmp/CSAW/Warmup# nc pwn.chal.csaw.io &lt;span style="color:#ff0;font-weight:bold">8000&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>-Warm Up-
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>WOW:0x40060d
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&amp;gt;Beetttttttttttttttttttttt
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>[Meabeets] /tmp/CSAW/Warmup# nc pwn.chal.csaw.io &lt;span style="color:#ff0;font-weight:bold">8000&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>-Warm Up-
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>WOW:0x40060d
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&amp;gt;aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>The program says “WOW:” followed by a memory address. This address is probably the address of the function we need to execute. Let’s open IDA to view the code:&lt;/p></description></item><item><title>[CSAW 2016] Clams Don’t Dance Writeup</title><link>https://www.megabeets.net/blog/csaw-2016-clams-dont-dance-writeup/</link><pubDate>Sun, 18 Sep 2016 22:01:40 +0000</pubDate><guid>https://www.megabeets.net/blog/csaw-2016-clams-dont-dance-writeup/</guid><description>&lt;h3 id="description">&lt;strong>Description:&lt;/strong>&lt;/h3>
&lt;blockquote>
&lt;p>Find the clam and open it to find the pearl.&lt;br>
&lt;a class="chal-file" href="https://ctf.csaw.io/stat./dd1c652598c176078e3b558a01f5d9a2/out.img" target="_blank">out.img&lt;/a>&lt;/p>
&lt;/blockquote>
&lt;p>We are given with a file. I ran &lt;code>file&lt;/code> command on it to figure it’s file type:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>[Megabeets] /tmp/CSAW/clam# file out.img
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>out.img: x86 boot sector
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Ok, we have raw image file which will probably contain file/s with the flag. I’ll show 2 methods, choose your preferred one.&lt;/p>
&lt;h3 id="method-1-autopsy">&lt;strong>Method 1: Autopsy&lt;/strong>&lt;/h3>
&lt;p>Open &lt;a href="http://www.sleuthkit.org/autopsy/">Autopsy&lt;/a> (my favorite forensics software, it’s free and heartily recommended) and choose the “Create New Case” on the Welcome window. You can also create a new case from the “File” menu.&lt;/p></description></item><item><title>[CSAW 2016] Regexpire Writeup</title><link>https://www.megabeets.net/blog/csaw-2016-regexpire-writeup/</link><pubDate>Sun, 18 Sep 2016 22:01:11 +0000</pubDate><guid>https://www.megabeets.net/blog/csaw-2016-regexpire-writeup/</guid><description>&lt;p>&lt;strong>Description:&lt;/strong>&lt;/p>
&lt;blockquote>
&lt;p>&lt;em>I thought I found a perfect match but she ended up being my regEx girlfriend.&lt;/em>&lt;/p>
&lt;p>&lt;em>nc misc.chal.csaw.io 8001&lt;/em>&lt;/p>
&lt;/blockquote>
&lt;p>It wasn’t so hard, I asked google for the best way to generate matched string to a given pattern and wrote the following script. The only headache was when my generator used newlines (“\n”) so I removed them.&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-python" data-lang="python">&lt;span style="display:flex;">&lt;span>&lt;span style="color:#fff;font-weight:bold">from&lt;/span> pwn &lt;span style="color:#fff;font-weight:bold">import&lt;/span> *
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#fff;font-weight:bold">import&lt;/span> rstr
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#fff;font-weight:bold">import&lt;/span> exrex
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#fff;font-weight:bold">from&lt;/span> time &lt;span style="color:#fff;font-weight:bold">import&lt;/span> sleep
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#fff;font-weight:bold">import&lt;/span> re
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#007f7f"># conect to server&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>r = remote(&lt;span style="color:#0ff;font-weight:bold">&amp;#39;misc.chal.csaw.io&amp;#39;&lt;/span>, &lt;span style="color:#ff0;font-weight:bold">8001&lt;/span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#007f7f"># Print the question string&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#fff;font-weight:bold">print&lt;/span> r.recvline()
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#007f7f"># Counter&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>i=&lt;span style="color:#ff0;font-weight:bold">1&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#fff;font-weight:bold">while&lt;/span> &lt;span style="color:#fff;font-weight:bold">True&lt;/span>:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>	&lt;span style="color:#007f7f"># Recieve the regex pattern&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> reg = r.recvline()[:-&lt;span style="color:#ff0;font-weight:bold">1&lt;/span>]
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">print&lt;/span> &lt;span style="color:#0ff;font-weight:bold">&amp;#34;&lt;/span>&lt;span style="color:#0ff;font-weight:bold">%d&lt;/span>&lt;span style="color:#0ff;font-weight:bold"> -------&lt;/span>&lt;span style="color:#0ff;font-weight:bold">\n&lt;/span>&lt;span style="color:#0ff;font-weight:bold">&amp;#34;&lt;/span>%i
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">print&lt;/span> reg
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">print&lt;/span> &lt;span style="color:#0ff;font-weight:bold">&amp;#34;-------&lt;/span>&lt;span style="color:#0ff;font-weight:bold">\n&lt;/span>&lt;span style="color:#0ff;font-weight:bold">&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> ans=rstr.xeger(reg).replace(&lt;span style="color:#0ff;font-weight:bold">&amp;#39;&lt;/span>&lt;span style="color:#0ff;font-weight:bold">\n&lt;/span>&lt;span style="color:#0ff;font-weight:bold">&amp;#39;&lt;/span>,&lt;span style="color:#0ff;font-weight:bold">&amp;#39;&amp;#39;&lt;/span>) &lt;span style="color:#007f7f"># Remove newlines!&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#007f7f"># ans=exrex.getone(reg).replace(&amp;#39;\n&amp;#39;,&amp;#39;&amp;#39;) # Another possible option&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> r.sendline(ans)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> i+=&lt;span style="color:#ff0;font-weight:bold">1&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>	sleep(&lt;span style="color:#ff0;font-weight:bold">0.2&lt;/span>)
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>And after 1000 tests we got the flag: &lt;em>flag{^regularly_express_&lt;wbr />yourself$}&lt;/em>&lt;/p></description></item><item><title>[CSAW 2016] Coinslot Writeup</title><link>https://www.megabeets.net/blog/csaw-2016-coinslot-writeup/</link><pubDate>Sun, 18 Sep 2016 22:00:33 +0000</pubDate><guid>https://www.megabeets.net/blog/csaw-2016-coinslot-writeup/</guid><description>&lt;h4 id="description">&lt;strong>Description:&lt;/strong>&lt;/h4>
&lt;blockquote>
&lt;p>&lt;em>#Hope #Change #Obama2008&lt;/em>&lt;/p>
&lt;p>&lt;em>nc misc.chal.csaw.io 8000&lt;/em>&lt;/p>
&lt;/blockquote>
&lt;p>Let’s connect to the server and see what will happen:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>[Megabeets] /tmp/CSAW/Coinslot# nc misc.chal.csaw.io &lt;span style="color:#ff0;font-weight:bold">8000&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>$0.07
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>$10,000 bills: &lt;span style="color:#ff0;font-weight:bold">0&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>$5,000 bills: &lt;span style="color:#ff0;font-weight:bold">0&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>$1,000 bills: &lt;span style="color:#ff0;font-weight:bold">0&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>$500 bills: &lt;span style="color:#ff0;font-weight:bold">0&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>$100 bills: &lt;span style="color:#ff0;font-weight:bold">0&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>...
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>...
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>So, the server is displaying a wanted amount of money and we need to calculate the number of bills and coins given the amount. All we need is writing a simple python script and a coffee break because it will take about 10 minutes for the flag to come up 🙁&lt;/p></description></item><item><title>[CSAW 2016] Kill Writeup</title><link>https://www.megabeets.net/blog/csaw-2016-kill-writeup/</link><pubDate>Sun, 18 Sep 2016 22:00:14 +0000</pubDate><guid>https://www.megabeets.net/blog/csaw-2016-kill-writeup/</guid><description>&lt;div class="chal-body">
 &lt;strong>Description:&lt;/strong>
 &lt;blockquote>
 &lt;p>
 &lt;em>Is kill can fix? Sign the autopsy file?&lt;/em>&lt;br /> &lt;em> &lt;a class="chal-file" href="https://ctf.csaw.io/stat./a23ef5ecca7f30b77f59f21dba413b07/kill.pcapng" target="_blank">kill.pcapng&lt;/a>&lt;/em>
 &lt;/p>
 &lt;/blockquote>
&lt;/div>
&lt;p>This challenge was the first in the Forensics category and was very very simple. We are given with what seems like a corrupted &lt;code>pcapng&lt;/code> file, I wasn’t able to open it in &lt;code>Wireshark&lt;/code> nor &lt;code>Tcpdump&lt;/code>. I ran &lt;code>strings&lt;/code> on it with a hope to find the flag:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>[Megabeets] /tmp/CSAW/kill# strings kill.pcapng | grep -i flag
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>=flag{roses_r_blue_violets_r_r3d_mayb3_harambae_is_not_kill}
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>And to my great surprise I got it, the flag was written plain-text in the file.&lt;/p></description></item><item><title>[ASIS CTF] SecuPrim Writeup</title><link>https://www.megabeets.net/blog/asis-ctf-secuprim-writeup/</link><pubDate>Sun, 11 Sep 2016 17:02:35 +0000</pubDate><guid>https://www.megabeets.net/blog/asis-ctf-secuprim-writeup/</guid><description>&lt;blockquote>
&lt;p>&lt;em>&lt;strong>Description:&lt;/strong>&lt;/em>&lt;br>
&lt;em>Test your might.&lt;/em>&lt;br>
&lt;em>secuprim.asis-ctf.ir 42738&lt;/em>&lt;/p>
&lt;/blockquote>
&lt;p>Who doesn’t love a good PPC challenge? We provided with only a URL and Port so I ran Netcat and faced a bot detection system asking me for ‘X’. The message said that |X|=4. I gave the 2 possible options for absolute value of 4 and those were wrong answers.&lt;/p>
&lt;pre tabindex="0">&lt;code class="language-default" data-lang="default">[Megabeets]$ nc secuprim.asis-ctf.ir 42738
Bot detection: Are you ready?
ASIS needs proof of work to start the Math challenge.
SHA256(X + &amp;#34;YNT7TFm4gVadh44qNzwQdG&amp;#34;).hexdigest() = &amp;#34;9a1f5add2c9198721d5efe3ba4512866...&amp;#34;,
X is a string of alphanumeric and |X| = 4
Enter X: 4
Sorry, Bad proof of work!

[Megabeets]$ nc secuprim.asis-ctf.ir 42738
Bot detection: Are you ready?
ASIS needs proof of work to start the Math challenge.
SHA256(X + &amp;#34;tu1uQei0DpFfmmKaF1rdAH&amp;#34;).hexdigest() = &amp;#34;1b4d598ef4e9e86dc1adb7d862e7b35f...&amp;#34;,
X is a string of alphanumeric and |X| = 4
Enter X: -4
Sorry, Bad proof of work!
&lt;/code>&lt;/pre>&lt;p>Well, if |X| isn’t for ‘absolute value of()’ then it must be ‘length of()’. You can notice that both the string appended to X and the SHA256 result are changing in every connection. I wrote a python code to calculate the answer. You can find it in the script embedded below.  After answering I got another test which I’ve been asked to solve 30 times (with a different value each time):&lt;/p></description></item><item><title>[ASIS CTF] Sky Blue Writeup</title><link>https://www.megabeets.net/blog/asis-ctf-sky-blue-writeup/</link><pubDate>Sun, 11 Sep 2016 17:01:39 +0000</pubDate><guid>https://www.megabeets.net/blog/asis-ctf-sky-blue-writeup/</guid><description>&lt;blockquote>
&lt;p>&lt;em>&lt;strong>Description&lt;/strong>&lt;/em>&lt;br>
&lt;em>Why is the &lt;a href="http://asis-ctf.ir/tasks/blue.txz_3a987ff102f69adcdad1ced41f9fdff2cba1a7e9">sky blue&lt;/a>?&lt;/em>&lt;/p>
&lt;/blockquote>
&lt;p> &lt;/p>
&lt;p>We are given a PCAP file containing some Bluetooth traffic. The flag has probably been transmitted between the devices. Let’s see what files has been sent.&lt;/p>
&lt;pre tabindex="0">&lt;code class="language-default" data-lang="default">[Megabeets]$: binwalk -e blue.pcap

DECIMAL       HEXADECIMAL     DESCRIPTION
--------------------------------------------------------------------------------
40535         0x9E57          PNG image, 1400 x 74, 8-bit colormap, non-interlaced
&lt;/code>&lt;/pre>&lt;p>Binwalk found a PNG image but couldn’t export it. I opened Wireshark and searched for the string “PNG” in the packet bytes. I found the 7 packets containing the PNG and exported their packet bytes (i.e Only the &lt;strong>DATA&lt;/strong>, without the header bytes of each packet: 02 0C 20 FC 03 F8 03 47 00 63 EF E6 07). I then concatenated the output files using HxD,&lt;/p></description></item><item><title>[ASIS CTF] Smallest MD5 Writeup</title><link>https://www.megabeets.net/blog/asis-ctf-smallest-md5-writeup/</link><pubDate>Sun, 11 Sep 2016 17:00:53 +0000</pubDate><guid>https://www.megabeets.net/blog/asis-ctf-smallest-md5-writeup/</guid><description>&lt;blockquote>
&lt;p>&lt;em>&lt;strong>Description&lt;/strong>&lt;/em>&lt;br>
&lt;em>I have lied that I have found the smallest MD5 hash possible, to win a bet.&lt;/em>&lt;br>
&lt;em>Now the other guy is pissed off and wants to know where have I got this hash from. What results to this hash? Please help!&lt;/em>&lt;/p>
&lt;/blockquote>
&lt;p>Just search Google for “MD5 minimum record” an you’ll find your &lt;a href="http://0xf.kr/md5/">answer&lt;/a>: &lt;em>08ni(g0u3ada_JiyongYoun-HLETRD&lt;/em>&lt;/p></description></item><item><title>[ASIS CTF] CTF 101 Writeup</title><link>https://www.megabeets.net/blog/asis-ctf-ctf-101-writeup/</link><pubDate>Sun, 11 Sep 2016 17:00:43 +0000</pubDate><guid>https://www.megabeets.net/blog/asis-ctf-ctf-101-writeup/</guid><description>&lt;blockquote>
&lt;p>&lt;em>**Description:**&lt;a href="http://www.megabeets.net/wp-admin/profile.php">http://www.megabeets.net/wp-admin/profile.php&lt;/a>&lt;br>
Watch your heads!&lt;/em>&lt;/p>
&lt;/blockquote>
&lt;p>The description is telling the whole story. Simply look in the response’s header and you’ll find the flag. In order to do that open the browser’s Developer Tools (F12), bring to focus the Network tab and click the challenge. The HTTP requests will show up on the left panel. Select the request and the &lt;strong>Flag&lt;/strong> header will be displayed on the right panel.&lt;/p>
&lt;div class="header-name">
 &lt;img src="./asisct101flag.png" />
&lt;/div>
&lt;p> &lt;/p>
&lt;p>Decode the string with base64 and reveal the flag.&lt;/p></description></item><item><title>[TWCTF-2016: Web] Global Page Writeup</title><link>https://www.megabeets.net/blog/twctf-2016-web-global-page-writeup/</link><pubDate>Mon, 05 Sep 2016 00:01:54 +0000</pubDate><guid>https://www.megabeets.net/blog/twctf-2016-web-global-page-writeup/</guid><description>&lt;blockquote>
&lt;p>**Challenge description: **&lt;br>
&lt;em>Welcome to TokyoWesterns’ &lt;a href="http://globalpage.chal.ctf.westerns.tokyo/">CTF&lt;/a>!&lt;/em>&lt;/p>
&lt;/blockquote>
&lt;hr>
&lt;p>&lt;span style="font-weight: 400;">As I entered the challenge I faced a three items list – two links and a strikethrough word:&lt;/span>.&lt;/p>
&lt;ul>
&lt;li>&lt;span style="font-size: 10pt;">&lt;em>&lt;a href="http://globalpage.chal.ctf.westerns.tokyo/?page=tokyo">Tokyo&lt;/a>&lt;/em>&lt;/span>&lt;/li>
&lt;li>&lt;span style="font-size: 10pt;">&lt;em>&lt;del>Westerns&lt;/del>&lt;/em>&lt;/span>&lt;/li>
&lt;li>&lt;span style="font-size: 10pt;">&lt;em>&lt;a href="http://globalpage.chal.ctf.westerns.tokyo/?page=ctf">CTF&lt;/a>&lt;/em>&lt;/span>&lt;/li>
&lt;/ul>
&lt;p>&lt;span style="font-weight: 400;">I clicked the &lt;/span>&lt;em>&lt;span style="font-weight: 400;">tokyo&lt;/span>&lt;/em> &lt;span style="font-weight: 400;">link, which was actually a GET request with a parameter named &lt;/span>&lt;em>&lt;span style="font-weight: 400;">page &lt;/span>&lt;/em>&lt;span style="font-weight: 400;">in index.php. In response I got a page with PHP error and information from Wikipedia about Tokyo, printed in Hebrew – my mother tongue.&lt;/span>&lt;/p></description></item><item><title>[TWCTF-2016: Crypto] Twin Primes Writeup</title><link>https://www.megabeets.net/blog/twctf-2016-crypto-twin-primes-writeup/</link><pubDate>Mon, 05 Sep 2016 00:00:52 +0000</pubDate><guid>https://www.megabeets.net/blog/twctf-2016-crypto-twin-primes-writeup/</guid><description>&lt;blockquote>
&lt;p>&lt;strong>Challenge description:&lt;/strong>&lt;br>
&lt;em>Decrypt it.&lt;/em>&lt;br>
&lt;a href="https://twctf7qygt6ujk.azureedge.n./twin-primes.7z-39a1a147cbf55d4d944f8eacdbdf4ee7a967dd70ef0eaaa0a1cee5c58c641483">twin-primes.7z&lt;/a>{.attachment}&lt;/p>
&lt;/blockquote>
&lt;hr>
&lt;p>We have 4 files in the archive:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>encrypt.py&lt;/strong> – A Python script uses RSA algorithm to encrypt the flag&lt;/li>
&lt;li>&lt;strong>encryped&lt;/strong> – The encrypted message&lt;/li>
&lt;li>&lt;strong>key 1&lt;/strong> – n, and e of one of the keys used in the encryption process&lt;/li>
&lt;li>&lt;strong>key 2&lt;/strong> – n, and e of the other key used in the encryption process&lt;/li>
&lt;/ul>
&lt;p>Are you ready for your math lesson? Here we go.&lt;br>
After reading encrypt.py we know that:&lt;/p></description></item><item><title>[TWCTF-2016: PPC] Make a Palindrome! Writeup</title><link>https://www.megabeets.net/blog/twctf-2016-ppc-make-a-palindrome-writeup/</link><pubDate>Mon, 05 Sep 2016 00:00:46 +0000</pubDate><guid>https://www.megabeets.net/blog/twctf-2016-ppc-make-a-palindrome-writeup/</guid><description>&lt;p>&lt;strong>Challenge description:&lt;/strong>&lt;/p>
&lt;blockquote>
&lt;p>Your task is to make a palindrome string by rearranging and concatenating given words.&lt;/p>
&lt;p>Input Format: N &amp;lt;Word_1&amp;gt; &amp;lt;Word_2&amp;gt; &amp;hellip; &amp;lt;Word_N&amp;gt;&lt;br>
Answer Format: Rearranged words separated by space.&lt;br>
Each words contain only lower case alphabet characters.&lt;/p>
&lt;p>Example Input: 3 ab cba c&lt;br>
Example Answer: ab c cba&lt;/p>
&lt;p>You have to connect to ppc1.chal.ctf.westerns.tokyo:31111(TCP) to answer the problem.&lt;/p>
&lt;p>$ nc ppc1.chal.ctf.westerns.tokyo 31111&lt;/p>
&lt;ul>
&lt;li>
&lt;p>Time limit is 3 minutes&lt;/p>
&lt;/li>
&lt;li>
&lt;p>The maximum number of words is 10.&lt;/p></description></item><item><title>[TWCTF-2016: Misc] glance Writeup</title><link>https://www.megabeets.net/blog/twctf-2016-misc-glance-writeup/</link><pubDate>Mon, 05 Sep 2016 00:00:28 +0000</pubDate><guid>https://www.megabeets.net/blog/twctf-2016-misc-glance-writeup/</guid><description>&lt;blockquote>
&lt;p>&lt;strong>Challenge description&lt;/strong>&lt;br>
&lt;em>I saw &lt;a href="https://twctf7qygt6ujk.azureedge.n./glance.gif-994bd85cd3c2f37c1cd1d520a506abbbe459ac7dc2fedd39bf04c99a04abcb9f">this&lt;/a> through a gap of the door on a train.&lt;/em>&lt;/p>
&lt;/blockquote>
&lt;p>In order to view the flag you should split the frames of the gif and view it all together. Just paste the url in &lt;a href="http://ezgif.com/split">this&lt;/a> site.&lt;/p>
&lt;p>Result:&lt;br>
&lt;img src="./glance.png" />&lt;/p></description></item><item><title>[TWCTF-2016: Web] Rescue Data 1: deadnas Writeup</title><link>https://www.megabeets.net/blog/twctf-2016-web-rescue-data-1-deadnas-writeup/</link><pubDate>Mon, 05 Sep 2016 00:00:18 +0000</pubDate><guid>https://www.megabeets.net/blog/twctf-2016-web-rescue-data-1-deadnas-writeup/</guid><description>&lt;blockquote>
&lt;p>&lt;strong>Challenge description:&lt;/strong>&lt;/p>
&lt;p>&lt;em>Today, our 3-disk NAS has failed. Please recover flag.&lt;/em>&lt;br>
&lt;em>&lt;a href="https://twctf7qygt6ujk.azureedge.n./deadnas.7z-b1651b1230b507235cbb9c6f7e98ccc437f5f3675d02a5e70951e2cbcf9df407">deadnas.7z&lt;/a>{.attachment}&lt;/em>&lt;/p>
&lt;/blockquote>
&lt;hr>
&lt;p>We are given an archive containing 3 files:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>D:&lt;span style="color:#0ff;font-weight:bold">\M&lt;/span>egabeets&lt;span style="color:#0ff;font-weight:bold">\d&lt;/span>eadnas&amp;gt; dir 
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Directory of D:&lt;span style="color:#0ff;font-weight:bold">\M&lt;/span>egabeets&lt;span style="color:#0ff;font-weight:bold">\d&lt;/span>eadnas
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> .
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> ..
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>524,288 disk0
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#ff0;font-weight:bold">12&lt;/span> disk1
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>524,288 disk2
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>3 Disk NAS and one has failed? This challenge is obviously about &lt;a href="http://blog.open-e.com/how-does-raid-5-work/">RAID 5&lt;/a>. I was asked to find a way to recover the failed disk and there is no simpler way than just XOR disk0 with disk2 and recreate the original disk1. If you are right now in your “WTF?!” mode you better go read about RAID 5 until you understand how it works.&lt;/p></description></item><item><title>[TWCTF-2016: Reverse] Reverse Box Writeup</title><link>https://www.megabeets.net/blog/twctf-2016-reverse-reverse-box-writeup/</link><pubDate>Sun, 04 Sep 2016 23:58:28 +0000</pubDate><guid>https://www.megabeets.net/blog/twctf-2016-reverse-reverse-box-writeup/</guid><description>&lt;p>Guest post by Shak.&lt;/p>
&lt;blockquote>
&lt;p>&lt;strong>Challenge description&lt;/strong>&lt;br>
$ ./reverse_box ${FLAG}&lt;br>
&lt;span style="font-weight: 400;">95eeaf95ef94234999582f722f492f72b19a7aaf72e6e776b57aee722fe77ab5ad9aaeb156729676ae7a236d99b1df4a&lt;/span>&lt;span style="font-weight: 400;">&lt;br /> &lt;/span>&lt;a href="https://twctf7qygt6ujk.azureedge.n./reverse_box.7z-f1ffb64d2a0848fdccd02ed63f0f2de6937545fa294ee530d73bf2c1fec27691">&lt;span style="font-weight: 400;">reverse_box.7z&lt;/span>&lt;/a>&lt;/p>
&lt;/blockquote>
&lt;hr>
&lt;p>&lt;span style="font-weight: 400;">This challenge is a binary which expects one argument and then spits out a string. We get the output of the binary for running it with the flag. Let’s fiddle with that for start.&lt;/span>&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>./reverse_box &lt;span style="color:#ff0;font-weight:bold">0000&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#ff0;font-weight:bold">28282828&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>&lt;span style="font-weight: 400;">The binary probably prints a hex value replacing each character. It is also clear that it is a unique value for each character. we must be dealing with some kind of substitution cipher. After running it again with the exact same argument, we get a different output, so the substitution is also randomized somehow. &lt;/span>&lt;/p></description></item><item><title>[TWCTF-2016: PWN] judgement Writeup</title><link>https://www.megabeets.net/blog/twctf-2016-pwn-judgement-writeup/</link><pubDate>Sun, 04 Sep 2016 23:54:32 +0000</pubDate><guid>https://www.megabeets.net/blog/twctf-2016-pwn-judgement-writeup/</guid><description>&lt;p>Guest post by Shak.&lt;/p>
&lt;blockquote>
&lt;p>&lt;strong>Challenge description:&lt;/strong>&lt;br>
&lt;em>Host : pwn1.chal.ctf.westerns.tokyo&lt;/em>&lt;br>
&lt;em>Port : 31729&lt;/em>&lt;br>
&lt;a href="https://twctf7qygt6ujk.azureedge.n./judgement-4da7533784aa31b96ca158fbda9677ee8507781ead6625dc6d577fd5d2ff697c">judgement&lt;/a>{.attachment}&lt;/p>
&lt;/blockquote>
&lt;hr>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>[Megabeets]$ nc pwn1.chal.ctf.westerns.tokyo &lt;span style="color:#ff0;font-weight:bold">31729&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Flag judgment system
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Input flag &amp;gt;&amp;gt; FLAG
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>FLAG
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Wrong flag...
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>&lt;span style="font-weight: 400;">Let’s check the binary. The following function is reading the flag from a local file on the server, so this binary will not reveal the flag, but further examining it might.&lt;/span>&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-c" data-lang="c">&lt;span style="display:flex;">&lt;span>&lt;span style="color:#fff;font-weight:bold">int&lt;/span> &lt;span style="color:#fff;font-weight:bold">__cdecl&lt;/span> load_flag(&lt;span style="color:#fff;font-weight:bold">char&lt;/span> *filename, &lt;span style="color:#fff;font-weight:bold">char&lt;/span> *s, &lt;span style="color:#fff;font-weight:bold">int&lt;/span> n)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>{
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">int&lt;/span> result; &lt;span style="color:#007f7f">// eax@2
&lt;/span>&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#007f7f">&lt;/span> FILE *stream; &lt;span style="color:#007f7f">// [sp+18h] [bp-10h]@1
&lt;/span>&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#007f7f">&lt;/span> &lt;span style="color:#fff;font-weight:bold">char&lt;/span> *v5; &lt;span style="color:#007f7f">// [sp+1Ch] [bp-Ch]@5
&lt;/span>&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#007f7f">&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> stream = fopen(filename, &lt;span style="color:#0ff;font-weight:bold">&amp;#34;r&amp;#34;&lt;/span>);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">if&lt;/span> ( stream ) {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">if&lt;/span> ( fgets(s, n, stream) ) {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> v5 = strchr(s, &lt;span style="color:#ff0;font-weight:bold">10&lt;/span>);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">if&lt;/span> ( v5 )
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> *v5 = &lt;span style="color:#ff0;font-weight:bold">0&lt;/span>;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> result = &lt;span style="color:#ff0;font-weight:bold">1&lt;/span>;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">else&lt;/span> { result = &lt;span style="color:#ff0;font-weight:bold">0&lt;/span>;}
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">else&lt;/span> { result = &lt;span style="color:#ff0;font-weight:bold">0&lt;/span>; }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#fff;font-weight:bold">return&lt;/span> result;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>}
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>&lt;span style="font-weight: 400;">Next we can see the main function which gets our input and compares it to the flag. &lt;/span>&lt;/p></description></item><item><title>[CTF(x) 2016 : WEB] Harambehub – 100 pts Writeup</title><link>https://www.megabeets.net/blog/ctfx-2016-web-harambehub-100-pts-writeup/</link><pubDate>Sun, 28 Aug 2016 21:37:46 +0000</pubDate><guid>https://www.megabeets.net/blog/ctfx-2016-web-harambehub-100-pts-writeup/</guid><description>&lt;p>&lt;strong>Challenge description:&lt;/strong>&lt;br>
&lt;em>This website was created in honor of harambe: &lt;a href="http://problems.ctfx.io:7003">http://problems.ctfx.io:7003&lt;/a>&lt;/em>&lt;br>
&lt;em>Problem author: omegablitz&lt;/em>&lt;br>
&lt;a href="https://gist.github.com/ITAYC0HEN/5df90c37fcdd78196778475e67011f7a">HarambeHub.java&lt;/a>&lt;br>
&lt;a href="https://gist.github.com/ITAYC0HEN/ad92229f6ae7f5fdf3c47ec752959b7e"> &lt;em>User.java&lt;/em>&lt;/a>&lt;/p>
&lt;p>This challenge was the second in the Web category and it actually was the first time I’ve ever seen something like that. We are given with a url, which returns an empty page and two source-files written in Java for Spark Framework. Make sure you read the given source-files before you continue.&lt;/p>
&lt;p>The main file, HarambeHub.java, contains two methods which are actually get() and post() routes to two different pages, as you can see below:&lt;/p></description></item><item><title>[CTF(x) 2016 : WEB] north korea – 50 pts Writeup</title><link>https://www.megabeets.net/blog/ctfx-2016-web-north-korea-50-pts-writeup/</link><pubDate>Sun, 28 Aug 2016 16:47:54 +0000</pubDate><guid>https://www.megabeets.net/blog/ctfx-2016-web-north-korea-50-pts-writeup/</guid><description>&lt;p>&lt;strong>Description:&lt;/strong>&lt;br>
&lt;em>What is North Korea hiding?&lt;br>
&lt;a href="http://problems.ctfx.io:7002/">http://problems.ctfx.io:7002/&lt;/a>&lt;/em>&lt;/p>
&lt;p>Entering the URL I faced with only a sentence:&lt;br>
“We, the Democratic People’s Republic of Korea, have developed a revolutionary new security standard. The West doesn’t stand a chance.”&lt;/p>
&lt;p>That’s all? I took a look at the source code (ctrl+u) to see if something is hiding, and indeed I saw a hidden button and a simple script:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#e5e5e5;background-color:#000;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-js" data-lang="js">&lt;span style="display:flex;">&lt;span>&amp;lt;button hidden type=&lt;span style="color:#0ff;font-weight:bold">&amp;#34;button&amp;#34;&lt;/span>&amp;gt;Retrieve nuclear codes&amp;lt;&lt;span style="color:#f00">/button&amp;gt;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&amp;lt;span&amp;gt;&amp;lt;&lt;span style="color:#f00">/span&amp;gt;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&amp;lt;script type=&lt;span style="color:#0ff;font-weight:bold">&amp;#34;text/javascript&amp;#34;&lt;/span>&amp;gt;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>$(&lt;span style="color:#fff;font-weight:bold">function&lt;/span>() {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>	$(&lt;span style="color:#0ff;font-weight:bold">&amp;#34;button&amp;#34;&lt;/span>).click(&lt;span style="color:#fff;font-weight:bold">function&lt;/span>() {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>		$.get(&lt;span style="color:#0ff;font-weight:bold">&amp;#39;code&amp;#39;&lt;/span>, &lt;span style="color:#fff;font-weight:bold">function&lt;/span>(code) {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>			$(&lt;span style="color:#0ff;font-weight:bold">&amp;#39;span&amp;#39;&lt;/span>).text(code);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>		});
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>	});
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>});
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&amp;lt;&lt;span style="color:#f00">/script&amp;gt;&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p style="text-align: left;">
 I clicked the button and it gave me the content of “http://problems.ctfx.io:7002/code” which was a message: “Nice try kiddo”.&lt;br /> Well, I took a look again at the first message: “&amp;#8230;The West doesn&amp;#8217;t stand a chance.”. What about the north? What if i”ll set the X-Forwarded-For to &lt;a href="https://en.wikipedia.org/wiki/Internet_in_North_Korea#IP_address_ranges">North Korea’s IP&lt;/a>? &lt;a href="https://en.wikipedia.org/wiki/X-Forwarded-For" target="_blank">X-Forwarded-For &lt;/a>is the conventional way of identifying the originating IP address of the user connecting to the web server coming from either a HTTP proxy, load balancer.
&lt;/p></description></item><item><title>XOR Files With Python</title><link>https://www.megabeets.net/blog/xor-files-with-python/</link><pubDate>Fri, 27 Nov 2015 08:08:59 +0000</pubDate><guid>https://www.megabeets.net/blog/xor-files-with-python/</guid><description>&lt;p>This is a simple script, written in Python, that perform a logical exclusion, XOR, on two files and saves the result in the destination file. It is one of the most simple and effective tool in my forensics-toolbox. I used this tool several times for example to recover data from a broken RAID 5 or deobfuscate an obfuscated binary or image. The usage is very simple and intuitive.&lt;br>
You can find the full code and examples in the &lt;a href="https://github.com/ITAYC0HEN/XOR-Files">repository&lt;/a>.&lt;/p></description></item><item><title>XOR Files With Powershell</title><link>https://www.megabeets.net/blog/xor-files-with-powershell/</link><pubDate>Mon, 02 Nov 2015 18:24:21 +0000</pubDate><guid>https://www.megabeets.net/blog/xor-files-with-powershell/</guid><description>&lt;p>Today I’m sharing with you one of the most simple and effective tool in my forensics-toolbox. A simple script, written in Powershell, that perform a logical exclusion, XOR, on two files and saves the result in the destination file. I used this tool several times for example  to  recover data from a broken RAID 5 or deobfuscate an obfuscated binary or image. The usage is very simple and intuitive.&lt;br>
You can find the full code and examples in the &lt;a href="https://github.com/ITAYC0HEN/XOR-Files">repository&lt;/a>.&lt;/p></description></item><item><title>Private: [Root-Me] Javascript – Authentication Writeup</title><link>https://www.megabeets.net/blog/private-root-me-javascript-authentication-writeup/</link><pubDate>Thu, 02 Apr 2015 10:24:52 +0000</pubDate><guid>https://www.megabeets.net/blog/private-root-me-javascript-authentication-writeup/</guid><description>&lt;p>Recently I found &lt;a href="http://root-me.org/">this&lt;/a> incredible project called &lt;strong>Root-Me&lt;/strong> which contains, among other things, over 200 challenges in different levels and topics of the cyber-security field. If you’re into hacking challenges and wargames I recommend you to check this site out.&lt;/p>
&lt;p>I decided to document my solutions for some of the challenges and share it with you, so that beginners can learn and become better hackers. The first challenge we’re going to solve is called **Javascript – Authentication. **That’s the easiest one in the Web-Client category. The challenge, like almost all of the other basic challenges in this category uses a web designing code called HTML (Hyper Text Markup Language) and Javascript along with some others client-side languages. If you know very little or nothing about HTML or Javascript I heartily recommend you read about it either in a book or online.&lt;/p></description></item></channel></rss>