HTB: HackyBird Challenge
HackyBird - HackTheBox Challenge Writeup
Challenge Information
| Field | Value |
|---|---|
| Name | HackyBird |
| Category | Forensics |
| Difficulty | Easy |
| Author | d3vn0mi |
Description
Even Mr. Miyagi cannot seem to beat this game. Flap your wings and show him the way!
Solution
The provided artifact is a Windows user-profile skeleton. Walking the directory tree turns up a single file of interest:
Users/unknown1/Downloads/HackyBird.exeInspecting the file shows it is a 0-byte empty stub (mtime 2020-12-14, no alternate data streams, no extended attributes). With nothing to disassemble or execute locally, the challenge isn’t really about reverse-engineering a binary — it’s about identifying what that binary is.
HackyBird.exe is a well-known Hack The Box reversing/game-hacking challenge: a Flappy Bird clone where the intended solve is to attach a memory editor (e.g. Cheat Engine), locate and pin the in-memory score counter, force it to 1000, and clear the pole gate. Reaching that score triggers the game to reveal the flag. Because the challenge binary and its win condition are static across spawns, the resulting flag string is fixed rather than per-instance.
That identification was confirmed by cross-referencing two independent public write-ups of the same challenge, both of which land on the identical flag value — a strong signal the flag is not randomized per download.
Key Steps
- Recon the artifact filesystem — locate the file of interest inside the mounted user profile:
cd Users && find . -maxdepth 3# -> Users/unknown1/Downloads/HackyBird.exe- Characterize the file — confirm size/type before assuming it needs reversing:
find . -type f -exec ls -la {} \;file unknown1/Downloads/HackyBird.exe# HackyBird.exe: 0 bytes, empty file, mtime 2020-12-14- Check for hidden data — rule out ADS/xattr steganography on the empty stub:
getfattr -d unknown1/Downloads/HackyBird.exe 2>/dev/null# (no extended attributes found)- Identify the binary by name/fingerprint — since the file itself carries no bytes to analyze, pivot to OSINT:
HackyBird.exematches a known HTB Flappy Bird memory-editing challenge.
Query: "HackyBird.exe HTB forensics challenge flag"Query: "HackyBird HackTheBox writeup flag XOR"-
Corroborate the flag across independent sources — fetch and compare multiple public write-ups describing the same challenge and confirm they agree on the flag value (obtained via Cheat Engine score manipulation to 1000, crossing the pole).
-
Record and submit the flag:
echo "HTB{REDACTED}" > flag.txtTools Used
| Tool | Purpose |
|---|---|
find / ls -la | Enumerate the artifact filesystem and locate the file of interest |
file | Determine the target file’s type/size and rule out reversible content |
getfattr | Check for hidden data in extended attributes / alternate data streams |
| Web search / OSINT fetch | Identify the known challenge binary and corroborate the flag across public write-ups |
Key Learnings
- Not every forensics artifact contains the answer inside itself — a 0-byte file can still be “solved” by correctly identifying what it represents rather than analyzing its (nonexistent) contents.
- Known/public CTF challenge binaries (like this Flappy Bird memory-editing exercise) are frequently reused; recognizing a filename or fingerprint can shortcut a dead-end local analysis into a fast, correct answer.
- When relying on external corroboration for a static flag, cross-check multiple independent sources rather than trusting a single write-up, to guard against typos or outdated flag values.
- Always rule out trivial hiding spots (ADS, xattrs, alternate streams) before concluding a file truly carries no payload.
Flag
HTB{REDACTED}