~ / writeups / spookypass

SpookyPass

Hack The Box · Very Easy · Reverse Engineering

Very Easy Reverse Engineering Challenge

Challenge Overview

Field Value
Name SpookyPass
Category Reverse Engineering
Difficulty Very Easy
Event Hack The Boo 2024
Deliverable pass — ELF 64-bit LSB PIE, x86-64, dynamically linked, not stripped
Objective Recover the hardcoded password to gain entry and print the flag

Attack surface summary: A single ELF binary that prompts for a password and, on a correct match, prints the flag. The password is stored in plaintext in the binary's read-only data (.rodata) section, so it falls to strings immediately.

Flag

Flag Value
SpookyPass [REDACTED]

Analysis

Extract the archive (default HTB challenge zip password is hackthebox) and identify the file:

unzip spooky_pass.zip      # password: hackthebox
file pass
# pass: ELF 64-bit LSB pie executable, x86-64, version 1 (SYSV),
#       dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2,
#       for GNU/Linux 4.4.0, not stripped

Because the binary is not stripped and stores the credential in plaintext, strings reveals it directly:

strings pass | grep -iE "password|spooky|s3cr3t|welcome|HTB"
# Before we let you in, you'll need to give us the password:
# s3cr3t_p455_f0r_gh05t5_4nd_gh0ul5
# Welcome inside!

The decompiled main() (Ghidra/IDA) confirms a plain strcmp against that string:

puts("Welcome to the \x1b[1;3mSPOOKIEST\x1b[0m party of the year.");
printf("Before we let you in, you'll need to give us the password: ");
fgets(local_98, 0x80, stdin);
pcVar2 = strchr(local_98, 10);
if (pcVar2 != (char *)0x0) { *pcVar2 = '\0'; }
iVar1 = strcmp(local_98, "s3cr3t_p455_f0r_gh05t5_4nd_gh0ul5");

Attack Chain

1. Extract & identify the binary

unzip spooky_pass.zip
file pass
# ELF 64-bit, x86-64, not stripped

2. Pull the plaintext password with strings

strings pass | grep -iE "password|s3cr3t|welcome"
# s3cr3t_p455_f0r_gh05t5_4nd_gh0ul5

3. Run the binary with the recovered password

chmod +x pass
./pass
# Welcome to the SPOOKIEST party of the year.
# Before we let you in, you'll need to give us the password: s3cr3t_p455_f0r_gh05t5_4nd_gh0ul5
# Welcome inside!
# [REDACTED]

(Alternative, no-execution path: the flag is also hardcoded in .rodata as individual char literals — extractable with the regex '([^']*)' from the decompiled code.)


Techniques Demonstrated

  1. File-format identification — file recognized the ELF binary and its characteristics.
  2. Static string analysis — strings recovered a plaintext credential from .rodata.
  3. Disassembly/decompilation — confirmed the strcmp authentication logic.

Tools Used

unzip, file, strings, (chmod + runtime execution), optional IDA/Ghidra for decompilation.

← all writeups