{"id":26,"date":"2022-07-17T21:57:46","date_gmt":"2022-07-17T21:57:46","guid":{"rendered":"http:\/\/moveax.me\/?p=26"},"modified":"2022-07-17T22:15:24","modified_gmt":"2022-07-17T22:15:24","slug":"crackme0x04-dissected-with-radare2","status":"publish","type":"post","link":"https:\/\/giga-rapid.com\/esites\/moveaxme\/crackme0x04-dissected-with-radare2\/","title":{"rendered":"Crackme0x04 Dissected with Radare2"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">All the exercises solved so far, had one thing in common: there was only one solution for the problem. Crackme0x04 does not inherit that characteristic because it has multiple solutions and has some tricks to calculate those solutions when compared to the&nbsp;<a href=\"crackme0x03\/\">previous crackme<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Getting the&nbsp;Crackme0x04&nbsp;password through analysis<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">afll shows two functions, the&nbsp;<em>main<\/em>&nbsp;and the&nbsp;<em>check<\/em>. Let\u2019s print them.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/01\/main-1.png\" alt=\"main of Crackme0x04\" class=\"wp-image-252\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Well, we can see the same as in the previous exercises, the prints of all those strings and the request for input.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I put a breakpoint right after the scanf instruction, ran the program to insert 957 as input, but when I went to check the value stored in the variable local_78h, I was surprised. Instead of seeing 0x3bd in the variable I saw this.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/01\/afvd-2.png\" alt=\"afvd\" class=\"wp-image-254\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">That\u2019s ASCII. This means that our input is being treated as a string. Not a problem!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s see what\u2019s in the check function.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/01\/check.png\" alt=\"check\" class=\"wp-image-253\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Check function is not a dummy function anymore\u2026 But let me guide you through the code!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First, the length of our \u201cstring\u201d is calculated and the value is saved in eax. Don\u2019t forget that our input is represented by arg_8h variable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">local_ch saves the position our string, so it\u2019s an index.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The next instruction suggests that we\u2019re about to enter in a loop, that will only end when we reach the end of our string. But this doesn\u2019t seem the best path to follow, because if this happens, we\u2019ll jump to the string \u201cPassword incorrect\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The next two instructions, makes our position in the input string move forward. The following instructions until&nbsp;<a href=\"https:\/\/linux.die.net\/man\/3\/sscanf\">sscanf<\/a>, extract a digit (a char, actually) from the input string in the index local_ch. The sscanf seems to be converting the ASCII to hexadecimal.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Solution<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As you can see, the number converted will be added to local_8h, so this variable will be a counter. And guess what? If that counter happens to hold 0xf (or 15 in decimal)\u2026 JACKPOT!!! If not, we keep converting the chars in the string that we inserted until the sum results in 0xf or the string ends.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Can you see the big picture now?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This crackme just collects our input and sum the digits in it, from left to right. If it sums to 15 at any point, you\u2019ll get a \u201cPassword OK\u201d message. That\u2019s all.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Getting the&nbsp;Crackme0x04&nbsp;password through program modification<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">At this point, program analysis is far more difficult than crack the program. Personally, I\u2019m much more interested in dissect this exercises and understand how they work than crack them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re like me and want to understand what is happening on the program stack and, at the same time keep tabs in all variables and registers you will \u201cwaste\u201d much more time when compared to program patch. Consequently, you\u2019ll get a deeper knowledge not only in this particular program but also in assembly. That\u2019s where I\u2019m aiming.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Moving to program patch, if you\u2019re lazy, you can just replace a jump instruction at the right place, making the program accept any input.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I tried save the value 0xf in local_8h between the sscanf and compare instructions but sadly I couldn\u2019t. I think it has something to do with the instructions size but I\u2019m still looking into it. Let me show you.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/01\/error.png\" alt=\"Cracking Crackme0x04\" class=\"wp-image-258\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">I\u2019ve been trying to get around this for the last couple days, but I guess I need to dedicate some time to this issue. If you know the reason for this to happen, leave me a comment or email me. I\u2019ll be very grateful!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So I moved on, and contrary to what I wanted, I used a lazy method: inserted a compare instruction and a jump to the \u201cPassword OK\u201d string. Here\u2019s the code.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/01\/after.png\" alt=\"\" class=\"wp-image-259\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Simple. Let\u2019s test it.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/01\/done.png\" alt=\"result\" class=\"wp-image-260\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">ALL GOOD!!!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">How did you crack this one? Let me know!!!<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Walkthrough video<\/strong><\/h4>\n","protected":false},"excerpt":{"rendered":"<p>All the exercises solved so far, had one thing in common: there was only one solution for the problem. Crackme0x04 does not inherit that characteristic&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/giga-rapid.com\/esites\/moveaxme\/crackme0x04-dissected-with-radare2\/\">Continue reading<span class=\"screen-reader-text\">Crackme0x04 Dissected with Radare2<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,1],"tags":[],"class_list":["post-26","post","type-post","status-publish","format-standard","hentry","category-radare2","category-uncategorized","entry"],"_links":{"self":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/26","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/comments?post=26"}],"version-history":[{"count":1,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/26\/revisions"}],"predecessor-version":[{"id":27,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/26\/revisions\/27"}],"wp:attachment":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/media?parent=26"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/categories?post=26"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/tags?post=26"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}