mobilemedium

Bad Weather

alfactf

Task: Smart home web app with IoT thermometer showing wrong weather data. Solution: Downloaded iOS IPA from manufacturer page, extracted hardcoded secret key from debug dylib using strings, then used the key to toggle the thermometer via REST API to get the flag.

$ ls tags/ techniques/
IPA extraction and binary analysisStrings analysis on Mach-O binariesAPI endpoint enumeration from mobile appHardcoded secret key extractionREST API exploitation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]