> For the complete documentation index, see [llms.txt](https://docs.hex-rays.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.hex-rays.com/ida-9.5/add-ons/assist/how-tos/solve-crackme-with-assist.md).

# Solve a crackme with Assist

{% hint style="warning" %}
Assist is new in the IDA 9.5 beta, and its documentation is subject to change. Treat it as a work in progress rather than a finished reference.
{% endhint %}

This tutorial walks through a first, simple use case of Assist: jump into one of the predefined prompts and see how it can help you work on your binary.

Assist, a dockable agent inside IDA, ships with its own integrated guide that walks you through the most common usage scenarios, so the whole experience happens without ever leaving IDA.

## Prerequisites

* IDA 9.3, 9.4 or 9.5 (IDA Home, IDA Pro)
* Assist installed, see [Getting Started](/ida-9.5/add-ons/assist/getting-started.md).

{% hint style="info" %}
New to Assist? See the [Overview](/ida-9.5/add-ons/assist/overview.md) for a short recap, or [Getting Started](/ida-9.5/add-ons/assist/getting-started.md) for installation details.
{% endhint %}

## Workflows - try it with your own prompt

1. Open IDA and load the binary you want to analyze. To invoke Assist, press <kbd>Ctrl</kbd>+<kbd>Shift</kbd>+<kbd>K</kbd>, or navigate to **Edit → Plugins → Assist**.
2. Try it with your own prompt, for example:

   > Tell me what this crackme does

Assist decompiles the entry point and the functions it calls, searches strings, reads raw bytes where needed, and runs Python to work through the logic, then writes up a summary of what it found, asking for approval on anything beyond reading.

<details>

<summary>Assist exemplary reply</summary>

These five functions carry the whole password check. The rest of the binary is statically linked glibc that it doesn't depend on.

1. **`sub_401D36` (0x401D36), `main`**: controls the whole check.

   * It checks the argument count and password length.
   * It reorders the password's four dwords into the globals at `0x4B7290–0x4B729C`: `p2, p0, p3, p1`.
   * It XORs each one with the program's own file size.
   * It calls the checker and prints "Correct password" or "Wrong password".

   The dword reordering and the file-size XOR are both here, so this is where you learn how the password is transformed.
2. **`sub_401C8D` (0x401C8D), the checker**: runs CRC32 on each 4-byte global and compares the results with four hardcoded constants: `0xB0322B9C`, `0xC892A7C4`, `0x4107E1F6`, `0xF2425AAA`. These constants are what you invert to recover the password.
3. **`sub_402530` (0x402530), zlib `crc32`**: the table at `0x488040` uses the standard 0xEDB88320 polynomial. Identifying it matters because CRC32 over exactly 4 bytes is reversible. That turns the check from something you'd have to brute-force into a quick linear-algebra solve.
4. **`sub_4431D0` (0x4431D0), `stat`**: a wrapper for `__xstat(1, path, buf)`, called on `argv[0]`. The XOR key is `st_size`, read at offset 0x30 of `struct stat`.
   * With this binary's size (`0xB6A30`) the password is `kn0wl3dg34b1l1ty`.
   * Patching or resizing the file changes the key, so this function is the crackme's tamper check.
   * A path that doesn't resolve to the real file makes `stat` fail, which also produces "Wrong password".
5. **`j_ifunc_418020` (0x4010C8 → ifunc 0x418020), `strlen`**: the first gate. The password must be exactly 16 bytes because the check consumes four dwords. Any other length fails before the CRC check runs.

Two others are worth knowing but don't affect the answer. **`sub_40A030`** is `puts`, used only to print the result. **`start`** (0x401B70) is ordinary `_start` code that passes `main` to `__libc_start_main` (`sub_402990`); the diagnostic flagging an undefined read of `rax` there is harmless.

The fastest route through the binary is `main` for the data flow, `sub_401C8D` for the targets, then `sub_402530` and `sub_4431D0` for how to reverse the check.

</details>

## What's next?

* Want a guided starting point instead of a blank prompt? Try **Guide → Workflows**: for example, **Triage an unknown binary** starts with "Which five functions matter most here, and why?"
* Check **Guide → Reading answers** to see what Assist inspected while working.
* Spotting something wrong? Go to **Guide → When it is wrong** to see how to undo a change or delete a memory finding.
* Want to try a different theory without losing your current progress? Click the fork icon next to any earlier message to branch off: both branches stay, and you can switch between them. See **Guide → Conversations** for more.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.hex-rays.com/ida-9.5/add-ons/assist/how-tos/solve-crackme-with-assist.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
