Target: Reversing ELF (TryHackMe) Difficulty: Easy Objective: Reverse engineer 8 Linux executables to find the flags.
1. Executive Summary
This room introduces the fundamentals of Linux Reverse Engineering. We progress from basic static analysis (file, strings) to dynamic analysis (ltrace) and finally to decompilation (Ghidra).
Key TTPs (Tools & Techniques):
- Static Analysis:
strings,file,objdump. - Dynamic Analysis:
ltrace(Library Call Trace),strace(System Call Trace). - Decompilation: Ghidra (Analyzing control flow and logic).
- Debugging: GDB (GNU Debugger) for inspecting registers/memory.
2. Challenge Walkthrough
Crackme 1: The Basics
Method: Execution The file was simply an executable that printed the flag when run.
chmod +x crackme1
./crackme1
# Output: flag{not_that_kind_of_elf}Crackme 2: The Password Argument
Method: Static Analysis (Guessing) The binary required a password argument.
./crackme2
# Usage: ./crackme2 passwordYou guessed super_secret_password (likely found via strings or simply testing the variable name often used in these challenges).
./crackme2 super_secret_password
# Output: flag{if_i_submit_this_flag_then_i_will_get_points}Crackme 3: Base64 Encoding
Method: strings + Decoding
Running strings revealed a suspicious Base64 string.
strings crackme3
# Found: ZjByX3kwdXJfNWVjMG5kX2xlNTVvbl91bmJhc2U2NF80bGxfN2gzXzdoMW5nNQ==Decoding:
echo "ZjByX..." | base64 -d
# Output: f0r_y0ur_5ec0nd_le55on_unbase64_4ll_7h3_7h1ng5Crackme 4: Comparison Logic (strcmp)
Method: Dynamic Analysis (ltrace)
This binary hides the password and compares it using strcmp. ltrace intercepts library calls like strcmp, showing us the arguments (what we typed vs. what it expected).
ltrace ./crackme4 helloOutput:
strcmp("my_m0r3_secur3_pwd", "hello") = 5It compared our input “hello” against the flag.
Flag: my_m0r3_secur3_pwd
Crackme 5: Input Handling
Method: Dynamic Analysis (ltrace)
Similar to the previous one, but it takes input during execution, not as an argument.
ltrace ./crackme5
# Type anything (e.g., test)Output:
strncmp("OfdlDSA|3tXb32~X3tX@sX`4tXtz\331\177", "test", ...)Wait, ltrace shows OfdlDSA.... This looks like the password.
Flag: OfdlDSA|3tXb32~X3tX@sX4tXtz`
Crackme 6: Analyzing Logic (GDB/Ghidra)
Method: Decompilation / Debugging
ltrace failed here because the comparison wasn’t a simple strcmp. You used GDB and Ghidra.
GDB Approach:
- Run
info functionsto findmy_secure_test. - Disassemble it (
disas my_secure_test) or break and inspect registers.
Ghidra Approach (Easier):
- Open
crackme6in Ghidra. - Navigate to
main->my_secure_test. - The decompiler shows the logic:
if (param_1 == 0x1337_pwd) { ... }(Or similar logic showing the comparison value).
Flag: 1337_pwd
Crackme 7: Advanced Logic
Method: Ghidra (Decompilation)
This one usually involves a menu or a loop. Opening it in Ghidra reveals the main function logic.
- Look for the
while(true)loop. - Look for the
ifstatement that prints the flag. - Identify the condition (e.g., input must equal a specific integer or string).
Crackme 8: The Final Boss
Method: Ghidra
This binary often requires inputting a specific integer (like atoi conversion) to trigger the flag printing function.
- Decompile
main. - See
atoi(argv[1])comparison. - Example Logic:
if (input == 0xcafef00d) ... - Convert Hex to Decimal:
3405691581. - Run:
./crackme8 3405691581.
3. Key Takeaways for RE
- Always start simple:
stringsfirst. If the flag is in plaintext, don’t overcomplicate it. ltraceis King: For basic CTF challenges (crackmes),ltracesolves 50% of them instantly by showing thestrcmpvalue.- Ghidra > GDB for Beginners: Reading C-like code in Ghidra is much easier than reading Assembly in GDB. Use GDB only when you need to see the value of a register at a specific moment.