[SEC Playground: Half Year CTF 2024] - Loader
![[SEC Playground: Half Year CTF 2024] - Loader](/_next/image?url=https%3A%2F%2Fcdn.hashnode.com%2Fres%2Fhashnode%2Fimage%2Fupload%2Fv1722360106215%2F2053d771-5fdd-4959-967e-72ceb3a70293.png&w=3840&q=75)
Introduction to the Challenge
The challenge was a zip file containing a testdll.exe binary and loader.dll.

When executed, it ask for the key. And showed this message after incorrect key input.

Can you unpack this?.
Format: re{flag}
Password for unzip: secplayground
Anti-Debugging Techniques
Runtime software protection
Application close itself when open x64dbg
Open testdll.exe with x64dbg.


Click "Execute till return." The debugger will try to continue with the application flow.

After clicking for a while, I saw this error message, and testdll.exe closed itself.

It looks like the application was protected by WinLicense.

Flag Retrieval
Unpack DLL with unlicense
Use this tool to unpack the DLL file.
https://github.com/ergrelet/unlicense

Copy the loader.dll to the same directory as the downloaded unlicense.exe. Then, execute the command below.
.\unlicense.exe loader.dll

The unlicense tool will read and output an unprotected DLL. Replace loader.dll with unpacked_loader.dll.
x64dbg: Dynamic analysis
Now repeat the steps from earlier. This time, the application will not close itself.

Open Symbols tab. Click loader.dll on the left side, checkFlag Symbol will shown on the right side.


Right-click on checkFlag, then click Follow in Disassembler.

x64dbg will navigate back to the location of the checkFlag function.



![[SEC Playground: Half Year CTF 2024] - Upload your choice](/_next/image?url=https%3A%2F%2Fcdn.hashnode.com%2Fres%2Fhashnode%2Fimage%2Fupload%2Fv1722359993266%2F8f38a493-b63a-4803-b5b5-2e75fb8edbc3.png&w=3840&q=75)
![[SEC Playground: Half Year CTF 2024] - Crackme](/_next/image?url=https%3A%2F%2Fcdn.hashnode.com%2Fres%2Fhashnode%2Fimage%2Fupload%2Fv1722359974757%2F5259cff7-7887-4df8-a0c6-58ab05a0e3db.png&w=3840&q=75)
![[SEC Playground: Half Year CTF 2024] - Meaware 1-5](/_next/image?url=https%3A%2F%2Fcdn.hashnode.com%2Fres%2Fhashnode%2Fimage%2Fupload%2Fv1722257519132%2Fce572dc0-4b55-4e28-b01e-216f3a82af2a.png&w=3840&q=75)
![[SEC Playground: Half Year CTF 2024] - Hesitation](/_next/image?url=https%3A%2F%2Fcdn.hashnode.com%2Fres%2Fhashnode%2Fimage%2Fupload%2Fv1722252010340%2F8a69364f-eaab-4891-97fd-bfe601096f5e.jpeg&w=3840&q=75)