Challenge Overview
| Field | Value |
|---|---|
| Name | SpookyPass |
| Category | Reverse Engineering |
| Difficulty | Very Easy |
| Event | Hack The Boo 2024 |
| Deliverable | pass — ELF 64-bit LSB PIE, x86-64, dynamically linked, not stripped |
| Objective | Recover the hardcoded password to gain entry and print the flag |
Attack surface summary: A single ELF binary that prompts for a password and, on a correct match, prints the flag. The password is stored in plaintext in the binary's read-only data (.rodata) section, so it falls to strings immediately.
Flag
| Flag | Value |
|---|---|
| SpookyPass | [REDACTED] |
Analysis
Extract the archive (default HTB challenge zip password is hackthebox) and identify the file:
unzip spooky_pass.zip # password: hackthebox
file pass
# pass: ELF 64-bit LSB pie executable, x86-64, version 1 (SYSV),
# dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2,
# for GNU/Linux 4.4.0, not stripped
Because the binary is not stripped and stores the credential in plaintext, strings reveals it directly:
strings pass | grep -iE "password|spooky|s3cr3t|welcome|HTB"
# Before we let you in, you'll need to give us the password:
# s3cr3t_p455_f0r_gh05t5_4nd_gh0ul5
# Welcome inside!
The decompiled main() (Ghidra/IDA) confirms a plain strcmp against that string:
puts("Welcome to the \x1b[1;3mSPOOKIEST\x1b[0m party of the year.");
printf("Before we let you in, you'll need to give us the password: ");
fgets(local_98, 0x80, stdin);
pcVar2 = strchr(local_98, 10);
if (pcVar2 != (char *)0x0) { *pcVar2 = '\0'; }
iVar1 = strcmp(local_98, "s3cr3t_p455_f0r_gh05t5_4nd_gh0ul5");
Attack Chain
1. Extract & identify the binary
unzip spooky_pass.zip
file pass
# ELF 64-bit, x86-64, not stripped
2. Pull the plaintext password with strings
strings pass | grep -iE "password|s3cr3t|welcome"
# s3cr3t_p455_f0r_gh05t5_4nd_gh0ul5
3. Run the binary with the recovered password
chmod +x pass
./pass
# Welcome to the SPOOKIEST party of the year.
# Before we let you in, you'll need to give us the password: s3cr3t_p455_f0r_gh05t5_4nd_gh0ul5
# Welcome inside!
# [REDACTED]
(Alternative, no-execution path: the flag is also hardcoded in .rodata as individual char literals — extractable with the regex '([^']*)' from the decompiled code.)
Techniques Demonstrated
- File-format identification —
filerecognized the ELF binary and its characteristics. - Static string analysis —
stringsrecovered a plaintext credential from.rodata. - Disassembly/decompilation — confirmed the
strcmpauthentication logic.
Tools Used
unzip, file, strings, (chmod + runtime execution), optional IDA/Ghidra for decompilation.