Target: Reversing ELF (TryHackMe) Difficulty: Easy Objective: Reverse engineer 8 Linux executables to find the flags.

1. Executive Summary

This room introduces the fundamentals of Linux Reverse Engineering. We progress from basic static analysis (file, strings) to dynamic analysis (ltrace) and finally to decompilation (Ghidra).

Key TTPs (Tools & Techniques):

  • Static Analysis: strings, file, objdump.
  • Dynamic Analysis: ltrace (Library Call Trace), strace (System Call Trace).
  • Decompilation: Ghidra (Analyzing control flow and logic).
  • Debugging: GDB (GNU Debugger) for inspecting registers/memory.

2. Challenge Walkthrough

Crackme 1: The Basics

Method: Execution The file was simply an executable that printed the flag when run.

chmod +x crackme1
./crackme1
# Output: flag{not_that_kind_of_elf}

Crackme 2: The Password Argument

Method: Static Analysis (Guessing) The binary required a password argument.

./crackme2
# Usage: ./crackme2 password

You guessed super_secret_password (likely found via strings or simply testing the variable name often used in these challenges).

./crackme2 super_secret_password
# Output: flag{if_i_submit_this_flag_then_i_will_get_points}

Crackme 3: Base64 Encoding

Method: strings + Decoding Running strings revealed a suspicious Base64 string.

strings crackme3
# Found: ZjByX3kwdXJfNWVjMG5kX2xlNTVvbl91bmJhc2U2NF80bGxfN2gzXzdoMW5nNQ==

Decoding:

echo "ZjByX..." | base64 -d
# Output: f0r_y0ur_5ec0nd_le55on_unbase64_4ll_7h3_7h1ng5

Crackme 4: Comparison Logic (strcmp)

Method: Dynamic Analysis (ltrace) This binary hides the password and compares it using strcmp. ltrace intercepts library calls like strcmp, showing us the arguments (what we typed vs. what it expected).

ltrace ./crackme4 hello

Output:

strcmp("my_m0r3_secur3_pwd", "hello") = 5

It compared our input “hello” against the flag. Flag: my_m0r3_secur3_pwd

Crackme 5: Input Handling

Method: Dynamic Analysis (ltrace) Similar to the previous one, but it takes input during execution, not as an argument.

ltrace ./crackme5
# Type anything (e.g., test)

Output:

strncmp("OfdlDSA|3tXb32~X3tX@sX`4tXtz\331\177", "test", ...)

Wait, ltrace shows OfdlDSA.... This looks like the password. Flag: OfdlDSA|3tXb32~X3tX@sX4tXtz`

Crackme 6: Analyzing Logic (GDB/Ghidra)

Method: Decompilation / Debugging ltrace failed here because the comparison wasn’t a simple strcmp. You used GDB and Ghidra.

GDB Approach:

  1. Run info functions to find my_secure_test.
  2. Disassemble it (disas my_secure_test) or break and inspect registers.

Ghidra Approach (Easier):

  1. Open crackme6 in Ghidra.
  2. Navigate to main -> my_secure_test.
  3. The decompiler shows the logic:
if (param_1 == 0x1337_pwd) { ... }

(Or similar logic showing the comparison value).

Flag: 1337_pwd

Crackme 7: Advanced Logic

Method: Ghidra (Decompilation) This one usually involves a menu or a loop. Opening it in Ghidra reveals the main function logic.

  1. Look for the while(true) loop.
  2. Look for the if statement that prints the flag.
  3. Identify the condition (e.g., input must equal a specific integer or string).

Crackme 8: The Final Boss

Method: Ghidra This binary often requires inputting a specific integer (like atoi conversion) to trigger the flag printing function.

  1. Decompile main.
  2. See atoi(argv[1]) comparison.
  3. Example Logic: if (input == 0xcafef00d) ...
  4. Convert Hex to Decimal: 3405691581.
  5. Run: ./crackme8 3405691581.

3. Key Takeaways for RE

  1. Always start simple: strings first. If the flag is in plaintext, don’t overcomplicate it.
  2. ltrace is King: For basic CTF challenges (crackmes), ltrace solves 50% of them instantly by showing the strcmp value.
  3. Ghidra > GDB for Beginners: Reading C-like code in Ghidra is much easier than reading Assembly in GDB. Use GDB only when you need to see the value of a register at a specific moment.