Share how awesome the crackme was or where you struggle to finish it! Stay polite and do not spoil the solution/flag!
Please keep the comments section English-only.
Author:
kamil123
Language:
C/C++
Upload:
2026-09-28 19:13
Platform:
Windows
Difficulty:
6.0
Quality:
4.0
Arch:
x86-64
Downloads:
22
Size:
24.00 KB
Writeups:
0
Comments:
1
Description
A hard custom-VM crackme: the password is validated inside a small custom register virtual machine. The VM bytecode is encrypted, uses a permuted opcode map, and the opcode stream is additionally keyed at runtime, so a static dump alone is not enough; the validation program contains opaque predicates, decoy blocks and junk instructions. Goal: find the password (a fixed string - no keygen). How to run: run crackme.exe (Windows console application) and type a password when prompted. The program prints a success message when the password is accepted. Notes: - Anti-debugging is part of the challenge: when a debugger is present, every password is rejected (including the correct one). Under a debugger the process may also keep the debugger waiting on exit - that is intentional. - Hiding plugins are detected: if ScyllaHide (or a similar plugin's hook library) is active, the program notices the injected module and/or the inline hooks on ntdll/kernel32/user32 entry points and terminates itself immediately. - The program verifies its own code against the on-disk image, so software breakpoints or patches on the validation functions are detected and cause silent rejection. A background watchdog re-checks continuously. - Fully solvable with static analysis. No packing, no network access, statically linked, no dependencies. Good luck!
Labels ?