$ cat writeup.md…
$ cat writeup.md…
hackthebox
Task: .NET MAUI (ex-Xamarin) Android APK whose 'claim reward' flow ties a native flag-decryption chain to the app's own AssemblyStore blob, with a decoy-flag trap and anti-frida gate. Solution: extract managed assemblies from the XABA v2 store, reverse the managed+native claim chain, then re-execute the arch-matched libflagnative.so offline under a stub libc, capturing the flag via LD_PRELOAD before flag_commit zeroes it.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar