Rootme_rev_wasm

I used this ghidra plugin for wasm reverse.

I found an interesting function spawn_npc:

Code in init function:

Another interesting function:

We highlight the following:

  1. Using XREF we understand that this is a function of character movement and iRam0004cef0 is his x, iRam0004cef0 - y.
  2. Coordinates of the NPC are transmitted to get_entity_at.

Therefore, here spawn_npc is passed the coordinates for spawning npc:

Let’s open chrome for wasm debugging, set breakpoint at 0x55ec (where cmp_const == 0x1a4) and get to the place where the rand function is called. Pull out its result value from memory and get coordinates of desired NPC:

cmp_const = 0x1A4
f = lambda iVar1: (iVar1 % ((cmp_const + 1) * 2) - (cmp_const + 1)) * 3
x = f(351140291) # first rand result
y = f(452781336) # second rand result
print(x,y) # -696 -1125

We reach the desired NPC and take the flag:


Last modified on 2022-03-27