← all writeups
revCOMPFEST 2026 · 500 pts · 12 min read

Deobfuscating a Packed ELF

2026-07-21 · by Fakhrity Hikmawan

Deobfuscating a Packed ELF

//First look

Binary terlihat kecil tapi penuh instruksi aneh — tanda klasik packer custom. Entry point hanya berisi loop decrypt yang menulis ke region RWX lalu jump ke sana.

//Dumping the unpacked code

Daripada reversing stub-nya secara statis, kita jalankan di gdb, break tepat setelah loop decrypt, lalu dump memory region-nya.

bash
(gdb) break *0x4012f4
(gdb) run
(gdb) dump binary memory unpacked.bin 0x403000 0x404800

//The key check

Hasil dump berisi fungsi check yang melakukan XOR input dengan key 0x5A lalu membandingkan dengan tabel byte. Tinggal balik operasinya:

python
table = [0x3c, 0x2b, 0x3e, 0x36, 0x29, 0x31, ...]
flag = "".join(chr(b ^ 0x5A) for b in table)
print(flag)  # COMPFEST{unp4ck3d_4nd_pwn3d}

flag{thanks_for_reading}

Questions or a cleaner solution? Reach out — I update writeups when I learn a better way.