RevMe
Reverse a three-step transformation (reverse + rotate + XOR) applied to a 36-byte target symbol to recover the flag.
Reverse a three-step transformation (reverse + rotate + XOR) applied to a 36-byte target symbol to recover the flag.
The login form runs client-side JS. Deobfuscating or inspecting it reveals a hardcoded secret key used to AES-decrypt the flag — the key is plaintext at the top of the obfuscated script.