| Tricky challenge or is it ? |
Here is my approach to this-
step 1: Bypass the debugger detection by setting the call to that code section (which contains ptrace, puts,etc) as nop.
step 2: Once the debugger (gdb) can enter the execution, just set a breakpoint at strcmp@plt.
step 3: Once entered strcmp@plt, just access the register contents using-
x/s %rdi (user input) &
x/s %rsi (the password which strcmp compares with)
(order can be switched based on how strcmp is called)
[as per calling conventions, the arguments for strcmp have to enter the two registers. ]
This worked because luckily the xor decryption is done before comparison and then directly strcmp is used, which can be exploited.
Hence, no manual decryption is needed.
|
2026-09-30 11:51 |