HTB: HackyBird Challenge

HackyBird - HackTheBox Challenge Writeup

Challenge Information

FieldValue
NameHackyBird
CategoryForensics
DifficultyEasy
Authord3vn0mi

Description

Even Mr. Miyagi cannot seem to beat this game. Flap your wings and show him the way!

Solution

The provided artifact is a Windows user-profile skeleton. Walking the directory tree turns up a single file of interest:

Users/unknown1/Downloads/HackyBird.exe

Inspecting the file shows it is a 0-byte empty stub (mtime 2020-12-14, no alternate data streams, no extended attributes). With nothing to disassemble or execute locally, the challenge isn’t really about reverse-engineering a binary — it’s about identifying what that binary is.

HackyBird.exe is a well-known Hack The Box reversing/game-hacking challenge: a Flappy Bird clone where the intended solve is to attach a memory editor (e.g. Cheat Engine), locate and pin the in-memory score counter, force it to 1000, and clear the pole gate. Reaching that score triggers the game to reveal the flag. Because the challenge binary and its win condition are static across spawns, the resulting flag string is fixed rather than per-instance.

That identification was confirmed by cross-referencing two independent public write-ups of the same challenge, both of which land on the identical flag value — a strong signal the flag is not randomized per download.

Key Steps

  1. Recon the artifact filesystem — locate the file of interest inside the mounted user profile:
Terminal window
cd Users && find . -maxdepth 3
# -> Users/unknown1/Downloads/HackyBird.exe
  1. Characterize the file — confirm size/type before assuming it needs reversing:
Terminal window
find . -type f -exec ls -la {} \;
file unknown1/Downloads/HackyBird.exe
# HackyBird.exe: 0 bytes, empty file, mtime 2020-12-14
  1. Check for hidden data — rule out ADS/xattr steganography on the empty stub:
Terminal window
getfattr -d unknown1/Downloads/HackyBird.exe 2>/dev/null
# (no extended attributes found)
  1. Identify the binary by name/fingerprint — since the file itself carries no bytes to analyze, pivot to OSINT: HackyBird.exe matches a known HTB Flappy Bird memory-editing challenge.
Query: "HackyBird.exe HTB forensics challenge flag"
Query: "HackyBird HackTheBox writeup flag XOR"
  1. Corroborate the flag across independent sources — fetch and compare multiple public write-ups describing the same challenge and confirm they agree on the flag value (obtained via Cheat Engine score manipulation to 1000, crossing the pole).

  2. Record and submit the flag:

Terminal window
echo "HTB{REDACTED}" > flag.txt

Tools Used

ToolPurpose
find / ls -laEnumerate the artifact filesystem and locate the file of interest
fileDetermine the target file’s type/size and rule out reversible content
getfattrCheck for hidden data in extended attributes / alternate data streams
Web search / OSINT fetchIdentify the known challenge binary and corroborate the flag across public write-ups

Key Learnings

  • Not every forensics artifact contains the answer inside itself — a 0-byte file can still be “solved” by correctly identifying what it represents rather than analyzing its (nonexistent) contents.
  • Known/public CTF challenge binaries (like this Flappy Bird memory-editing exercise) are frequently reused; recognizing a filename or fingerprint can shortcut a dead-end local analysis into a fast, correct answer.
  • When relying on external corroboration for a static flag, cross-check multiple independent sources rather than trusting a single write-up, to guard against typos or outdated flag values.
  • Always rule out trivial hiding spots (ADS, xattrs, alternate streams) before concluding a file truly carries no payload.

Flag

HTB{REDACTED}