Skip to content
All modules
CoreModule 21 of 27120 minutes

Reverse engineering

Get from an unknown executable to the one function that decides whether your input is right, and recognise which of four shapes the check takes.

Assumes16. File forensics and carving

By the end you can

  • Establish format, architecture and whether a binary is stripped, and say what each implies
  • Use strings and cross-references to find the check function without reading from main
  • Classify a flag check as direct comparison, transform-then-compare, hash-then-compare, or a constraint system
  • Invert a transform-then-compare check using the constants already in the binary
  • Choose between static reading and running it under a debugger, and say what each answers faster
  • Read managed bytecode - JVM, .NET, Python, WebAssembly - back to something close to source
  • Say when a decompiler helps and when its output is a reconstruction to be distrusted

1. Read

2. Use the tools

In the order they come up while solving. Read what each one does, or go straight to the workspace tab that runs it.

3. Try one now

Generated in your browser and checked in your browser. No account, nothing to download, and a fresh one whenever you want another.

4. Practise on the real thing

Real picoCTF challenges that use these techniques, easiest first. 101 match in total - see the full index.

Common mistakes

The wrong turns this topic reliably produces. Written as the mistake rather than the rule, because the rule is easy to agree with and easy to walk straight past.

  • Starting at main and reading forward. Strings and cross-references reach the check function in a minute; linear reading takes an hour and usually stops short.
  • Believing decompiler output. It is a reconstruction: types are guessed, and a wrong signature silently changes what the code appears to do.
  • Patching the check instead of solving it. It gets you past a prompt, but the flag is normally derived from the input rather than printed after it.
  • Reversing library code as if it were the author's. A statically linked binary carries whole libc functions with no symbols left on them, and an hour can go into a custom transform that turns out to be memcmp.
  • Reading a strings sweep that found nothing as proof the binary is hard. A keygen or a constraint system derives the flag from your input rather than storing it, so an empty sweep is evidence about the shape of the check.

Checkpoint

Given a stripped 64-bit binary that transforms input before comparing it, name the transform, invert it, and produce the flag without running the binary.

Teaching note

Students start at main and read forward, which is the slowest possible route. Make the first exercise strings-plus-cross-references only, with the disassembler closed - once they have found a check function that way they rarely go back to reading linearly.

Go deeper

The lessons above are written to get you through a challenge. These go after the subject instead. Each one opens our notes on that chapter - what it argues, what to take from it and where it stops - so this is somewhere to read now rather than a book to buy first. Nothing here is affiliate-linked or sold by us.

Every book the curriculum cites has a page in the library.