Master the fundamental concepts of reverse engineering through this focused micro-challenge.
You have read the whole brief, and the concepts above stay free on every task. Writing and running the code needs a plan.
Three hints are available for this task, revealed one at a time inside the code workspace so you can struggle productively before seeing them.
Every task includes starter code, theory, and hidden tests so you can implement and verify locally in the browser.
How it worksFinding a hidden password inside a binary is one of the most common reverse engineering challenges. It applies to malware analysis, crackmes, vulnerability research, and understanding proprietary protections.
Strings analysis is always the first step:
cLoading…
If the password is stored in plaintext, this reveals it immediately. Developers sometimes hide passwords as XOR-encrypted byte arrays to evade simple strings analysis.
Tracing comparisons in disassembly: look for strcmp, strncmp, or byte-by-byte comparison loops. Every password check has a success branch and a failure branch:
cLoading…
You will document how to find password-checking logic through strings analysis and comparison tracing. Tracing backward from a "wrong password" message to the comparison instruction reveals what input would satisfy the check.
When static analysis fails, run the binary under GDB with a breakpoint on strcmp using break strcmp and commands to print both arguments. The comparison reveals the expected password at runtime even if it was XOR-encrypted in the binary. Some crackmes compute passwords algorithmically, requiring you to reverse the generation logic rather than extract a static string.
Write the kind of program a reverse engineer practises on: it checks a password hard-coded in the binary, compared character by character. Alongside, print the analysis walkthrough explaining how an attacker recovers that password: strings analysis, tracing the comparison loop, finding and patching the success branch, and why client-side checks can never be secret.
One line: the password guess (it may contain spaces). The secret is reverse engineer.
=== Step 1: Strings Analysis ===, === Step 2: Tracing Comparisons ===, === Step 3: Finding the Success Path === and === Why Client-Side Checks Are Reversible ===, separated by blank lines.Password length: 16 characters (the secret's length).correct password if the whole line (without its newline) equals the secret, else wrong password. A guess of the wrong length is rejected before any character is compared.Input:
cLoading…
Output:
cLoading…
fgets and strip the trailing newline, so passwords with spaces work.Hidden tests cover the correct password (with its space), another wrong guess (wrongguess), and a one-character guess (x).