{"id":1293,"date":"2021-05-31T13:51:11","date_gmt":"2021-05-31T13:51:11","guid":{"rendered":"https:\/\/cas.cybercop-training.ch\/?page_id=1293"},"modified":"2021-06-17T10:15:56","modified_gmt":"2021-06-17T10:15:56","slug":"owasp-crackme-simple","status":"publish","type":"page","link":"https:\/\/cas.cybercop-training.ch\/index.php\/owasp-crackme-simple\/","title":{"rendered":"Crackme Simple"},"content":{"rendered":"<h2>1. Introduction<\/h2>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/05\/emulator03.png\" alt=\"\" \/><\/p>\n<p>The password is somewhere hidden in this app. Extract it. The password is the flag.<\/p>\n<h2>2. Analysis<\/h2>\n<p>First I&#8217;ll open the package with <code>jad-x-gui<\/code><\/p>\n<p>The following AESUtil part looks interessting:<br \/>\n<img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/05\/jadx01-1.png\" alt=\"\" \/><\/p>\n<p>Note: We can see the <code>AES encryption key<\/code> and the <code>initialization vector<\/code><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">public class AESUtil { private static final String ENCRYPTION_IV = \"SHCUOkfd89ut7777\"; \r\nprivate static final String ENCRYPTION_KEY = \"Simpleji4todnkfL\";<\/pre>\n<p>From the encryption key a <code>sha256 cryptographic hash value will be genereated<\/code> (also called sha256.digest)<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">static Key makeKey() \r\n        { try \r\n             { return new SecretKeySpec(MessageDigest.getInstance(\"SHA-256\").digest(ENCRYPTION_KEY.getBytes(\"UTF-8\")), \"AES\");<\/pre>\n<p>The second part which looks interessting is located in <code>LoginViewModel<\/code>:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/05\/jadx02.png\" alt=\"\" \/><\/p>\n<p>We have a closer look at the following byte orders:<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">public class LoginViewModel extends ViewModel { \r\nprivate static byte[] exs = {-28, 73, 79, 78, 113, 73, 101, 98, 115, 6, 27, -35, 111, -55, -114, -11, -29, 0, -73, 91, 115, -24, -4, -94, -59, 43, -57, 112, 11, -54, -115, 2};<\/pre>\n<h2>3. Decryption process<\/h2>\n<p>Calculating the SHA256 value of the encryption key:<\/p>\n<p><a href=\"https:\/\/xorbin.com\/tools\/sha256-hash-calculator\">https:\/\/xorbin.com\/tools\/sha256-hash-calculator<\/a><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/05\/sha256.png\" alt=\"\" \/><\/p>\n<p>For the next step I&#8217;ll use Cyberchef<\/p>\n<p><a href=\"https:\/\/gchq.github.io\/CyberChef\">https:\/\/gchq.github.io\/CyberChef<\/a><\/p>\n<p>The Cyberchef Recipe looks like this:<\/p>\n<p>Input:<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">-28, 73, 79, 78, 113, 73, 101, 98, 115, 6, 27, -35, 111, -55, -114, -11, -29, 0, -73, 91, 115, -24, -4, -94, -59, 43, -57, 112, 11, -54, -115, 2<\/pre>\n<p>From Decimal<br \/>\nDelimiter: Comma<br \/>\nSupport signed values: yes<\/p>\n<p>AES Decrypt<br \/>\nKey: <code>d6eadb48382e79d35f25cbca4fb55ef69d842ee79ad843b4bae757fa99344d1a<\/code><br \/>\nInitialization Vector: <code>SHCUOkfd89ut7777<\/code><br \/>\nMode: <code>CBC<\/code><br \/>\nInput: <code>RAW<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/05\/cyberchef01.png\" alt=\"\" \/><\/p>\n<p>Output: <code>HL{R3v3rsing.FUN}<\/code><\/p>\n<p>Cyberchef Recipe:<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">From_Decimal('Comma',true) \r\nAES_Decrypt({'option':'Hex','string':'d6eadb48382e79d35f25cbca4fb55ef69d842ee79ad843b4bae757fa99344d1a'},\r\n{'option':'UTF8','string':'SHCUOkfd89ut7777'},'CBC','Raw','Raw',{'option':'Hex','string':''},{'option':'Hex','string':''})<\/pre>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. Introduction The password is somewhere hidden in this app. Extract it. The password is the flag. 2. Analysis First I&#8217;ll open the package with jad-x-gui The following AESUtil part looks interessting: Note: We can see the AES encryption key and the initialization vector public class AESUtil { private static final String ENCRYPTION_IV = &#8222;SHCUOkfd89ut7777&#8220;; [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-1293","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/1293","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/comments?post=1293"}],"version-history":[{"count":5,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/1293\/revisions"}],"predecessor-version":[{"id":1387,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/1293\/revisions\/1387"}],"wp:attachment":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/media?parent=1293"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}