mobilemedium
Bad Weather
alfactf
Task: Smart home web app with IoT thermometer showing wrong weather data. Solution: Downloaded iOS IPA from manufacturer page, extracted hardcoded secret key from debug dylib using strings, then used the key to toggle the thermometer via REST API to get the flag.
$ ls tags/ techniques/
IPA extraction and binary analysisStrings analysis on Mach-O binariesAPI endpoint enumeration from mobile appHardcoded secret key extractionREST API exploitation
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]