Super Secure Catalog - Cyberchaze CTF Writeup
Walkthrough for the Super Secure Catalog Android reverse engineering challenge from Cyberchaze CTF.
Super Secure Catalog - Cyberchaze CTF Writeup
Challenge Info
| Field | Details |
|---|---|
| CTF | Cyberchaze CTF |
| Challenge | Super Secure Catalog |
| Category | Android / Reverse Engineering |
Solution
The app on opening, asks for a username and a password We can move on to inspecting in it Jadx
The entered username and password is being verified in another class names Cryto Now,we can inspect the Crypto class
A part of the flag was hardcoded, cyberchaze{th3_encRYpt3d_STR1ng_in_3nc6yPtE6_ There was also the use of Native Libraries, we can inspect it in:
The function was a string encoded in hexa, we can convert it to string value
- hexa : 666921457d
- ASCII : fi!E}
If we join them together we get the flag flag : cyberchaze{th3_encRYpt3d_STR1ng_in_3nc6yPtE6_fi!e}
This post is licensed under CC BY 4.0 by the author.




