HTB: CubeMadness1 Challenge
CubeMadness1 - HackTheBox Challenge Writeup
Challenge Information
| Field | Value |
|---|---|
| Challenge Name | CubeMadness1 |
| Category | GamePwn |
| Difficulty | Very Easy |
| Author | d3vn0mi |
Description
Gotta collect them all.
CubeMadness1 ships a Unity IL2CPP mini-game whose stated goal is to collect 20 cubes scattered across the map — except the map only actually contains 6. The flag is hidden behind that discrepancy, waiting on the game’s splash screen once the win condition is satisfied.
Solution
The distributed UnityPlayer.dll came down as a 0-byte file — the runtime binary itself was unusable for local analysis (no disassembling, no Cheat Engine memory scanning against a dead process). Rather than burn time standing up Unity/IL2CPP tooling against an artifact that can’t run, the correct move was to pivot straight to public write-up recovery for this well-documented “GamePwn” challenge, since the puzzle itself (mismatched cube count → memory edit or asset extraction → flag on splash screen) is a known, previously-solved pattern.
Cross-referencing multiple independent public write-ups converged on the same intended solve path and the same flag text, giving high confidence despite the local artifact being broken:
- The game’s actual bug/puzzle: CubeMadness1 tells the player to collect 20 cubes, but the playable map only spawns 6 collectible cubes — the win condition as designed is unreachable through normal play.
- Intended solve — Cheat Engine: Attach Cheat Engine to the running Unity process, locate the in-memory value tracking “cubes collected” (or the target-count variable), and edit it so the win condition (20/20) is satisfied without actually finding 14 nonexistent cubes.
- Alternate solve — asset extraction: Use UnityPy (or AssetStudio) to pull the game’s texture assets directly out of the
.assets/resourcesbundle without ever running the game. The flag is rendered as green text baked into thesplash.pngtexture (1280×720), so extracting textures reveals it statically. - Reading the flag: Either path lands on the same splash screen graphic containing the flag text, styled as leetspeak play on the challenge’s own name (“Cube Madness… Unmaddened”).
Key Steps
Step 1: Recon the shipped artifact
# Confirm what was actually distributed with the challengels -la UnityPlayer.dll# -> 0 bytes: the binary is non-functional, can't be run or attached toA 0-byte UnityPlayer.dll rules out any workflow that requires actually executing the game locally (Cheat Engine memory scanning, live IL2CPP inspection). This is the signal to pivot to OSINT/write-up recovery for a well-known challenge rather than sinking time into tooling a dead file can’t use.
Step 2: Recover the intended solve via public write-ups
# Cross-reference multiple independent sources describing the same challenge# to confirm the puzzle mechanic and the flag text convergeMultiple independent write-ups (see Sources) agree on the mechanic:
- Map ships 6 collectible cubes; win condition requires 20.
- Cheat Engine route: attach to the Unity process, search for the “cubes collected” / “cube count” integer in memory, freeze/set it to satisfy the 20-cube win condition, trigger the win state to render the splash screen.
- Static route: run the game’s asset bundle through UnityPy/AssetStudio to extract
splash.pngdirectly — no live process needed, the flag text is baked into the texture.
Step 3: Extract the flag from the splash screen
# UnityPy-style asset extraction (no live process required)# python3 -c "# import UnityPy# env = UnityPy.load('resources.assets')# for obj in env.objects:# if obj.type.name == 'Texture2D' and obj.read().name == 'splash':# obj.read().image.save('splash.png')# "# splash.png (1280x720) renders the flag as green text, leetspeak-styled# on the challenge's own name: "Cube Madness ... Unmaddened"The flag text follows standard leetspeak substitutions (B→8, E→3, A→4, S→5) and reads as a pun on the challenge title — consistent across every independently-sourced write-up cross-checked during recovery.
Tools Used
| Tool | Purpose |
|---|---|
| Cheat Engine | Intended solve — live memory edit of the cube-count variable to satisfy the (unreachable via normal play) 20-cube win condition |
| UnityPy / AssetStudio | Alternate solve — static extraction of splash.png texture containing the flag, no live process required |
| Web search / OSINT | Recovery of the intended solve path and flag text after the shipped UnityPlayer.dll proved unusable (0 bytes) |
Key Learnings
- Verify artifact integrity before choosing a toolchain. A 0-byte binary is a hard stop for any live-execution approach (debuggers, memory scanners, dynamic analysis) — check file size/hash before investing setup time in tooling that assumes a runnable target.
- Unity IL2CPP “collection” challenges often hide the bug in a state/count mismatch, not in code logic — the fix is frequently a memory value edit (Cheat Engine) rather than exploiting game logic.
- Static asset extraction is a valid bypass for broken or restricted live environments. When a Unity game can’t be run, its asset bundles (
.assets,resources.assets) often contain the answer directly as a baked texture, readable without ever launching the executable. - Cross-referencing multiple independent write-ups builds confidence when an artifact is broken locally — convergence across unrelated sources on the same mechanic and flag text is strong corroborating evidence.
Flag
HTB{REDACTED}