$ cat writeup.md…
$ cat writeup.md…
HackTheBox
Task: ARM embedded system reads 8-digit passcode via UART, uses it as LCG seed to generate addresses into W25Q128 SPI flash, reads scattered flag bytes. Solution: reverse engineer LCG parameters from binary, brute-force 10^8 seed space with known-plaintext 'HTB{' prefix check against flash dump.
$ cat /etc/rate-limit
Rate limit reached (20 reads/hour per IP). Showing preview only — full content returns at the next hour roll-over.
Our years undercover in the art dealing world have paid off, and we have compromised the inner circle. The coordinates of the stolen treasures are contained within a mysterious device that we now have clearance to access. We managed to dump its flash memory and extract the embedded software running on it, and tap its input channel with a trigger-based capturing device in order to monitor passcode input. Its secrets must be retrieved!
Three files provided:
embedded_software — ARM 32-bit ELF binary (Raspberry Pi), linked with wiringPi library, not strippedflash_memory_dump.bin — 16 MB W25Q128 SPI flash chip dumpinput_channel_trace.sal — Saleae Logic 8 capture of UART input channel (internal .sal format containing digital-0.bin and meta.json)Goal: recover the secret (flag) stored scattered across the flash memory.
The embedded_software file is an ARM 32-bit ELF binary for Raspberry Pi. It imports functions from libwiringPi.so (SPI and serial I/O) and libc.so.6. Source file names visible in debug info: main2.c, memory_access.c.
...
$ grep --similar