data:image/s3,"s3://crabby-images/97a4f/97a4f60b9803213a959602926bcdf95f90da83ca" alt=""
data:image/s3,"s3://crabby-images/05145/0514508480bdf9c900013c51cfe41664d1e50004" alt="Image: http://i1351.photobucket.com/albums/p799/ryanNullify/First_StrLen_zps752a6131.jpg"
data:image/s3,"s3://crabby-images/e799c/e799cf1b562c49a0c75c4040db6b9817747e9095" alt="Image: http://i1351.photobucket.com/albums/p799/ryanNullify/Second_StrLen_zps011b8a06.jpg"
data:image/s3,"s3://crabby-images/b6340/b6340014562acb310fb4c5fe6ed4fad33257c5a1" alt="Image: http://i1351.photobucket.com/albums/p799/ryanNullify/Valid_Call_zps2d6eb991.jpg"
The program then calls the keygen function and falls into the call to the wrong function if keygen returns zero and the call to the valid function if keygen returns one. It looks like the function that will need to be reversed is the keygen function.
data:image/s3,"s3://crabby-images/a6ae3/a6ae3eff699417636771997e5933dbd42adee56a" alt="Image: http://i1351.photobucket.com/albums/p799/ryanNullify/SeedValue_zpsa3a4a9e0.jpg"
After some inspection and remote debugging we were able to figure out some important information about the keygen function. The keygen function works as follows:
- Pull eight bytes from the user input and store the result in RAX
- Use the bottom four bytes of RAX as input to _srandom
- Call the _random function, and compare the return value to a number
- Increment r12 to grab the next four bytes of the user input
This entire algorithm is repeated a total of seven times. The first seven numbers that are compared after each reseeding of the random function were:
1. 0x7358837a
2. 0x34d8c3b53. 0x1f49456c
4. 0x1fea6614
5. 0x4e81abc76. 0x683d3f5d
7. 0x28c9a8feTherefore to find the key all we need to do is write a program that generates all possible four character printable ASCII values. Use those values as input to srandom, call random, and finally compare the result to each of the previous seven numbers to find a match. This will tell us what four characters were used as the seed at that particular point in the program. Once all seven seeds are found we should have the flag:). The solution program that we used is as follows:
data:image/s3,"s3://crabby-images/5df3e/5df3e467a71057f340f85f29bb227283ba376990" alt="Image: http://i1351.photobucket.com/albums/p799/ryanNullify/Program_zps7d99c91c.jpg"
Link to solution code: https://github.com/IAryan/CTFSolutions/blob/master/randySolution.c
data:image/s3,"s3://crabby-images/2d383/2d383ebca8761bc9d1c3549365f4c2ee8a2ff1da" alt="Image: http://i1351.photobucket.com/albums/p799/ryanNullify/After_zps2262087a.jpg"
The output of the bruteforce program reveals the flag: n0t s0 r4nd0m0 4ft3r a11!!!!
Solution write-up by Ryan
No comments:
Post a Comment