Flash CTF - Careless Talk

Careless Talk Writeup

Careless Talk is a 50 point warm up challenge. The handout is one small x86-64 ELF that asks for a watchword and prints a flag when it gets the right one. Nothing has to be reversed and nothing has to be run. The flag sits inside the binary in plaintext, split into two pieces at opposite ends of the file, and one strings call plus one grep puts them back together.

Running the file command on the file shows that it's a binary:

$ file careless-talk
careless-talk: ELF 64-bit LSB pie executable, x86-64, version 1 (SYSV), dynamically linked,
interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, not stripped

Running the strings command shows that it has a lot of strings:

$ strings careless-talk | wc -l
490

The top of that output already includes:

$ strings careless-talk | sed -n '27,30p'
FLAG_A=SkillBit{c4r3l355_t4lk_
--journal
watchword:
Watchword accepted. %s%s

Half a flag, and a naming convention worth more than the half. FLAG_A implies a FLAG_B, and the %s%s in the success message confirms the program prints two pieces back to back.

$ strings careless-talk | grep -n FLAG_
27:FLAG_A=SkillBit{c4r3l355_t4lk_
416:FLAG_B=c05t5_l1v35}

strings is the first move on an unknown binary, ahead of the disassembler and ahead of running it. A program that checks your input against a hardcoded credential has to carry that credential, and a program that prints a secret has to carry the secret.

‍

Trust our customers

Interested in joining our team? Let’s connect!