SpookyPass — HackTheBox Challenge Writeup
Initial Inspection
We start by extracting the challenge package provided by Hack The Box (the default zip archive password is usually hackthebox).
::Identifying the Binary Format
Using file to check the executable properties:
Key Observation: The binary is not stripped. This means symbol names, function signatures
(such as main), and global variables remain intact in the symbol table, making static analysis
substantially easier.
Extracting Plaintext Credentials
::Using the strings utility
Since the binary contains unstripped symbols and hardcoded strings, running strings on the pass binary quickly reveals the contents of readable sections (.rodata, .data):
Output:
Vulnerability Concept: Storing plaintext credentials or authentication tokens directly in
binary read-only data sections (.rodata) allows attackers to extract them instantaneously using
simple string scanning utilities without executing the code.
Flag Capture
::Running the Executable
We make the binary executable and run it, providing the extracted password "s3cr3t_p455_f0r_gh05t5_4nd_gh0ul5":
Execution Log:

Red Team Consultant · Penetration Tester · Bug Bounty Hunter
Offensive security professional with 250+ vulnerabilities reported across 50+ organizations including Atlassian, Vimeo, and AT&T. Sharing research, tools, and field notes.