Olympic CTF Sochi 2014 Binathlon 10 writeup

While running the setup.exe file, the wizard asks for a password. Its an Inno Setup package, I tried to unpack the package with innounp tool, I got the setup script file and an exectuable with its source code. The script contains the Hash of the password and the salt which are :

; PasswordHash=888e209e5d76a3135d04b8baccabd7936a0dd376
; PasswordSalt=0e559522ecf62077

Using hashcat i got the needed password which is 1234567 but it won't validate.

Running the executabe, it prints "You already saw the flag."

If we come back and run the install again and we read the eula (7A point) :

. 7A. YOU MAY SUBMIT THIS TO GET TEN POINTS: ILOVEREADINGEULAS.

So the flag is ILOVEREADINGEULAS