
Flash CTF - Careless Talk
Careless Talk Writeup
Careless Talk is a 50 point warm up challenge. The handout is one small x86-64 ELF that asks for a watchword and prints a flag when it gets the right one. Nothing has to be reversed and nothing has to be run. The flag sits inside the binary in plaintext, split into two pieces at opposite ends of the file, and one strings call plus one grep puts them back together.
Running the file command on the file shows that it's a binary:
$ file careless-talk
careless-talk: ELF 64-bit LSB pie executable, x86-64, version 1 (SYSV), dynamically linked,
interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, not stripped
Running the strings command shows that it has a lot of strings:
$ strings careless-talk | wc -l
490
The top of that output already includes:
$ strings careless-talk | sed -n '27,30p'
FLAG_A=SkillBit{c4r3l355_t4lk_
--journal
watchword:
Watchword accepted. %s%s
Half a flag, and a naming convention worth more than the half. FLAG_A implies a FLAG_B, and the %s%s in the success message confirms the program prints two pieces back to back.
$ strings careless-talk | grep -n FLAG_
27:FLAG_A=SkillBit{c4r3l355_t4lk_
416:FLAG_B=c05t5_l1v35}
strings is the first move on an unknown binary, ahead of the disassembler and ahead of running it. A program that checks your input against a hardcoded credential has to carry that credential, and a program that prints a secret has to carry the secret.