Skip to content

Instantly share code, notes, and snippets.

@Bono-iPad Bono-iPad/ Secret
Created May 1, 2016

What would you like to do?
Unbreakable Enterprise Product Activation (solved with angr)
import angr, simuvex, claripy
import logging
p = angr.Project("./unbreakable-enterprise-product-activation2")
initial_state = p.factory.blank_state(addr=0x4005bd)
flag = claripy.BVS('flag', 8*0x43),flag)
pg = p.factory.path_group(initial_state, immutable=False)
s = pg.found[0].state
for a in range(0,10):
s.add_constraints(s.memory.load(0x6042c0 + a, 1) < 0x80)
s.add_constraints(s.memory.load(0x6042c0 + a, 1) >= 0x20)
print "%r" %[0].state.memory.load(0x6042c0, 0x43))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.