$ cat writeup.md…
$ cat writeup.md…
sbpctf
Task: Windows PE32 crackme (task5.exe) that copies encrypted shellcode from .data, XOR-decrypts it at runtime, marks it RWX and calls it as a function to validate argv[1]. Solution: statically XOR the 34 .data dwords with 0xcafebabe, disassemble the recovered shellcode, read the stack-string password 'itiseasy' and the embedded key REDACTED.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar