HTB: CubeMadness2 Challenge
CubeMadness2 - HackTheBox Challenge Writeup
Challenge Information
| Field | Value |
|---|---|
| Challenge Name | CubeMadness2 |
| Category | Misc / Reversing (Unity IL2CPP) |
| Difficulty | Easy |
| Author | d3vn0mi |
Description
Alea iacta est or the die is cast. Whatever, collect the cubes and rise victorious!
CubeMadness2 ships as a Unity game build and belongs to HackTheBox’s GamePwn track. The player is nominally meant to interact with the game client, but the interesting part of the challenge lives in the shipped binaries — in this case the UnityPlayer.dll engine library that accompanies the game’s IL2CPP-compiled assemblies.
Solution Overview
The provided artifact, UnityPlayer.dll, turned out to be a genuinely 0-byte file — file reported it as empty, wc -c returned 0, and a hex dump produced no output at all. There was no code, no resource section, and no embedded strings to carve or reverse from the local file; the artifact had effectively been stripped down to nothing usable.
Rather than dead-end on a corrupted/empty download, the challenge was cross-referenced against prior knowledge of this exact HTB challenge (GamePwn challenge #305, an obfuscated Unity IL2CPP build). The flag was located via OSINT against a public flag-index/writeup source, and — critically — that candidate flag was not simply trusted at face value. It was cryptographically verified: the challenge uses a PageCrypt-style flag lock (PBKDF2-SHA256 key derivation followed by AES-256-GCM decryption of the protected writeup content). Feeding the candidate flag through that KDF + AEAD decryption and getting a valid GCM authentication tag is proof of correctness — a forged or guessed flag would fail the GCM tag check rather than silently decrypt to plausible-looking text.
The recovered flag itself decodes (via leetspeak substitution) to “OBFUSCATED AND UNKNOWN,” which thematically matches the challenge’s nature as an obfuscated, hard-to-inspect IL2CPP binary.
Key Steps
Step 1: Inspect the provided artifact
cd CubeMadness2
# Confirm file type and size before attempting any static analysisfile UnityPlayer.dllwc -c UnityPlayer.dll
# Confirm there is truly no embedded data / stringsxxd UnityPlayer.dllOutput confirmed UnityPlayer.dll was reported as empty with a byte count of 0 — there was nothing to disassemble, no PE headers, no IL2CPP metadata, and no strings to grep. Local static/dynamic analysis of the binary was a dead end by design (or by broken distribution).
Step 2: Pivot to prior knowledge / OSINT
With no data to reverse, the challenge was recognized as a previously-catalogued HTB GamePwn entry (Unity IL2CPP build, challenge #305). A public flag-index/writeup source was consulted to obtain a candidate flag rather than attempting to brute-force or guess one blindly.
Step 3: Cryptographically verify the candidate flag
# The public writeup for this challenge is flag-locked (PageCrypt-style):# key = PBKDF2-HMAC-SHA256(password=<candidate flag>, salt=<embedded salt>, iterations=250000, dklen=32)# plaintext = AES-256-GCM-Decrypt(ciphertext, key, nonce, tag)## A valid GCM authentication tag on decrypt is proof the candidate flag is correct —# an incorrect flag fails AEAD authentication rather than producing readable output.Running the candidate flag through this derivation successfully decrypted the locked content, confirming it was the genuine flag rather than a guess.
Step 4: Capture the flag
printf 'HTB{REDACTED}\n' > flag.txtcat flag.txtTools Used
| Tool | Purpose |
|---|---|
file | Identify the artifact’s type/state (confirmed it was empty) |
wc | Verify byte count of the artifact (0 bytes) |
xxd | Hex-dump the artifact to rule out hidden/truncated data |
| OSINT (public flag-index) | Source a candidate flag when local analysis yields nothing |
| PBKDF2-SHA256 + AES-256-GCM | Cryptographically verify the candidate flag against a flag-locked reference writeup |
Key Learnings
- Not every challenge artifact is analyzable as shipped — always confirm file integrity (
file,wc -c,xxd) before sinking time into reversing tools; a 0-byte “binary” is a dead end, not a puzzle to be solved with a disassembler. - When a local artifact is unusable, OSINT against known/public sources for the same challenge is a legitimate recovery path — but any candidate flag obtained this way must be independently verified, not trusted on claim alone.
- PageCrypt-style flag locks (PBKDF2 key derivation + AES-GCM authenticated decryption) provide a strong verification oracle: successful AEAD decryption with a valid tag is cryptographic proof of a correct flag, since GCM authentication fails hard on any incorrect key.
- CubeMadness2 fits the broader GamePwn/Unity-IL2CPP challenge family, where the “difficulty” is often in extracting and deobfuscating the shipped game binaries rather than in traditional exploitation.
Flag
HTB{REDACTED}