圖片較多,手機加載較慢
python寫的及其拉胯,所以請見諒(是真的拉胯)
解題用的方法都是笨方法,大家知道怎么做了之后可以找簡單的方法
已解題:簽到抽獎、神仙姐姐、飄啊飄、感受下氣氛、我跟你拼了、套神應援團.png、貪吃蛇的秘密、簡單二維碼、misc41、亞當和夏娃
加上自己的兩道題:你以為是easyRSA嗎,其實是我套娃之神噠 、我想要獲得旗幟
后面補充的題(在很后面)阿拉丁、迷、LunaticRE

1.簽到抽獎

得到flag
中文也可能是英文及其他小眾語言字符
2.神仙姐姐

當然我不會寫腳本,我是不會這樣做的,,

首先打開burp,點擊一下“拜”

發現會向sx.php發送一個GET請求,訪問

可以看到,回傳了fake flag,num即我們拜的次數
群里說只需要拜1-1000次隨機會有一次出現flag,所以我用burp發包

使用數值,1-1000

因為回應都是fake,所以使用↓箭頭,一直翻,直到那個real flag一閃而過

3.飄啊飄
有手X就行
雖然當時沒看題目描述,當時是接近9點,在上課,所以想用手機看看,結果打開之后(寫WP復現,所以時間為下午6點)
顯示重定向錯誤,換了5個瀏覽器,都是重定向錯誤,其中via顯示重定向的地址

所以我用qq瀏覽器換成電腦的UA訪問

4.感受下氣氛
flag是ctfshow{[0-9]{9}}
所以隨便填就好了,只要滿足正則
ctfshow{012345678}
5.我跟你拼了
把ttt下載下來,亂操作一通,最后習慣性改了高度(不會吧不會吧不會真的有人去拼吧

ctfshow{hello_67373}
6.套神應援團.png
先天八卦操的改版,先看看附件,,,,
說多了都是淚,,,直接講思路
因為開頭非常像brainfuck,并且的確一眼就能看出是先天八卦操的改版,所以找到對應關系即可,可以有多種解法,我是讀的某個特定的RGB
from PIL import Image
img = Image.open("套神應援團.png")
w, h = img.size
for y in range(0,h,250):
for x in range(0,w,230):
s = img.getpixel((30+x,30+y))
print(s)
然后去brainfuck解碼的網站生成一個ctfshow{}
然后找到對應關系
(247, 230, 237)="+"
(154, 12, 8)="["
(250, 217, 244)="-"
(245, 246, 250)=">"
(244, 246, 250)="<"
(157, 8, 14)="]"
(220, 200, 199)="."
然后寫解密腳本
from PIL import Image
flag = ''
img = Image.open("套神應援團.png")
w, h = img.size
for y in range(0, h, 250):
for x in range(0, w, 230):
test = img.getpixel((x + 30, y + 30))
if(test==(247, 230, 237)):
flag += "+"
if(test==(154, 12, 8)):
flag += "["
if(test==(250, 217, 244)):
flag += "-"
if(test==(245, 246, 250)):
flag += ">"
if(test==(244, 246, 250)):
flag += "<"
if(test==(157, 8, 14)):
flag += "]"
if(test==(220, 200, 199)):
flag += "."
print(flag)


解碼即可https://www.splitbrain.org/services/ook
7.貪吃蛇的秘密
python編譯的exe檔案,直接反編譯,參考如下
軟體地址https://github.com/countercept/python-exe-unpacker/
第一步:python pyinstxtravtor.py xxxxx.exe
第二步:得到一個檔案夾
其中有一個struct 跟 xxxxx(都沒有后綴名)
十六進制查看struct,xxxxx,
會發現xxxxx比struct少了一行
這時將struct的那一行復制給xxxxx,然后xxxxx保存后添加后綴
xxxxx.pyc
第三步:使用uncompyle6(我是kali)
uncompyle6 xxxxx.pyc > xxxxx.py
根據提示POS,查看POS
allpos = [
(100, 540), (200, 200), (500, 160), (360, 400), (280, 300), (500, 300), (360, 160), (420, 360), (160, 320), (420, 300), (320, 200), (540, 440), (360, 120), (100, 220), (380, 100), (440, 140), (40, 440), (100, 300), (480, 140), (420, 480), (460, 520), (280, 380), (600, 260), (440, 320), (480, 400), (40, 540), (440, 300), (440, 80), (400, 40), (300, 580), (540, 400), (180, 320), (80, 340), (40, 520), (340, 140), (160, 540), (260, 300), (480, 380), (280, 60), (40, 480), (340, 40), (260, 220), (440, 500), (380, 40), (80, 360), (340, 280), (480, 80), (200, 340), (240, 300), (600, 120), (120, 40), (520, 80), (480, 520), (100, 100), (320, 560), (100, 80), (260, 580), (40, 400), (540, 560), (440, 380), (220, 600), (40, 420), (260, 420), (560, 160), (140, 600), (80, 240), (580, 460), (40, 60), (360, 560), (80, 40), (600, 200), (140, 440), (520, 440), (440, 480), (280, 160), (100, 420), (520, 220), (80, 160), (600, 140), (120, 220), (500, 320), (400, 560), (440, 100), (140, 480), (240, 220), (220, 200), (120, 520), (340, 200), (180, 240), (40, 240), (500, 540), (60, 480), (40, 580), (100, 120), (440, 440), (460, 300), (480, 560), (540, 300), (320, 300), (240, 380), (480, 300), (140, 280), (180, 300), (540, 480), (600, 160), (460, 220), (240, 180), (120, 400), (200, 220), (380, 240), (380, 560), (540, 160), (320, 380), (160, 200), (80, 380), (200, 520), (440, 580), (360, 260), (40, 160), (480, 160), (440, 520), (580, 420), (280, 260), (540, 120), (80, 260), (400, 300), (600, 220), (160, 120), (240, 100), (240, 40), (580, 560), (200, 560), (100, 340), (40, 360), (120, 120), (80, 100), (260, 520), (200, 180), (480, 260), (420, 80), (600, 100), (160, 600), (560, 300), (220, 100), (500, 220), (360, 420), (580, 580), (540, 100), (600, 40), (260, 320), (200, 160), (440, 120), (480, 120), (260, 280), (220, 560), (520, 300), (560, 100), (140, 400), (40, 380), (300, 420), (420, 600), (40, 100), (420, 540), (440, 240), (280, 520), (40, 560), (260, 480), (520, 260), (200, 60), (480, 420), (80, 440), (360, 440), (340, 80), (580, 200), (520, 40), (320, 260), (160, 240), (600, 300), (40, 280), (360, 600), (360, 320), (200, 360), (80, 200), (600, 460), (280, 200), (560, 80), (340, 580), (200, 540), (220, 340), (200, 140), (120, 360), (140, 160), (300, 460), (220, 280), (520, 460), (40, 340), (220, 300), (100, 480), (340, 260), (400, 460), (540, 500), (320, 240), (340, 360), (340, 600), (520, 600), (100, 400), (80, 600), (280, 460), (160, 280), (320, 340), (280, 220), (320, 440), (120, 340), (320, 280), (300, 180), (440, 360), (160, 400), (300, 400), (160, 100), (260, 540), (240, 360), (320, 420), (360, 520), (300, 380), (500, 200), (100, 560), (520, 100), (120, 320), (120, 240), (100, 40), (340, 340), (440, 260), (160, 480), (80, 120), (380, 440), (560, 120), (360, 360), (120, 200), (360, 500), (140, 40), (340, 520), (200, 80), (300, 500), (400, 420), (120, 560), (580, 380), (520, 500), (520, 560), (560, 380), (200, 300), (220, 60), (260, 200), (520, 380), (60, 340), (100, 280), (580, 260), (180, 380), (380, 60), (540, 600), (540, 40), (340, 480), (460, 380), (600, 80), (260, 600), (500, 580), (440, 180), (200, 460), (540, 80), (300, 60), (340, 100), (460, 240), (540, 380), (400, 340), (340, 240), (360, 40), (220, 420), (580, 220), (40, 600), (560, 200), (120, 600), (100, 520), (400, 200), (580, 160), (100, 600), (500, 520), (460, 420), (80, 520), (380, 500), (80, 480), (60, 220), (500, 380), (200, 260), (500, 280), (100, 360), (600, 380), (300, 540), (240, 520), (40, 140), (420, 280), (320, 160), (40, 120), (440, 160), (160, 60), (540, 340), (360, 180), (520, 420), (260, 240), (520, 120), (100, 160), (120, 540), (560, 40), (520, 520), (540, 220), (380, 580), (140, 260), (580, 360), (420, 100), (340, 440), (440, 460), (600, 420), (240, 160), (260, 440), (80, 540), (60, 160), (520, 480), (500, 600), (500, 240), (400, 120), (400, 160), (440, 40), (160, 440), (160, 500), (320, 60), (240, 260), (320, 600), (80, 560), (340, 460), (360, 540), (160, 160), (500, 440), (360, 80), (380, 220), (540, 280), (380, 320), (520, 160), (160, 80), (340, 220), (240, 240), (160, 40), (480, 220), (60, 600), (160, 140), (220, 480), (320, 480), (120, 100), (80, 300), (40, 80), (320, 400), (200, 40), (480, 340), (340, 500), (480, 480), (420, 500), (420, 380), (480, 200), (120, 480), (160, 560), (480, 320), (320, 120), (240, 140), (280, 180), (280, 320), (400, 240), (120, 440), (460, 440), (560, 360), (400, 360), (320, 220), (300, 300), (160, 580), (40, 300), (420, 340), (280, 120), (40, 500), (400, 140), (460, 560), (320, 580), (220, 120), (160, 520), (480, 440), (420, 60), (300, 320), (120, 160), (340, 60), (80, 80), (120, 80), (40, 40), (540, 260), (120, 260), (100, 200), (460, 200), (320, 500), (380, 420), (200, 380), (300, 600), (320, 80), (580, 40), (160, 360), (260, 460), (540, 580), (260, 120), (560, 520), (500, 40), (540, 420), (600, 60), (220, 460), (480, 100), (180, 360), (460, 600), (400, 600), (300, 140), (500, 560), (480, 40), (220, 80), (60, 40), (440, 400), (480, 60), (440, 420), (560, 400)]
因為給了坐標點,所以很容易想到QR,就去嘗試了一下,但是因為我不會讀行…所以只好寫了個很憨的腳本
from PIL import Image
s=[100,200,500,360,280,500,360,420,160,420,320,540,360,100,380,440,40,100,480,420,460,280,600,440,480,40,440,440,400,300,540,180,80,40,340,160,260,480,280,40,340,260,440,380,80,340,480,200,240,600,120,520,480,100,320,100,260,40,540,440,220,40,260,560,140,80,580,40,360,80,600,140,520,440,280,100,520,80,600,120,500,400,440,140,240,220,120,340,180,40,500,60,40,100,440,460,480,540,320,240,480,140,180,540,600,460,240,120,200,380,380,540,320,160,80,200,440,360,40,480,440,580,280,540,80,400,600,160,240,240,580,200,100,40,120,80,260,200,480,420,600,160,560,220,500,360,580,540,600,260,200,440,480,260,220,520,560,140,40,300,420,40,420,440,280,40,260,520,200,480,80,360,340,580,520,320,160,600,40,360,360,200,80,600,280,560,340,200,220,200,120,140,300,220,520,40,220,100,340,400,540,320,340,340,520,100,80,280,160,320,280,320,120,320,300,440,160,300,160,260,240,320,360,300,500,100,520,120,120,100,340,440,160,80,380,560,360,120,360,140,340,200,300,400,120,580,520,520,560,200,220,260,520,60,100,580,180,380,540,540,340,460,600,260,500,440,200,540,300,340,460,540,400,340,360,220,580,40,560,120,100,400,580,100,500,460,80,380,80,60,500,200,500,100,600,300,240,40,420,320,40,440,160,540,360,520,260,520,100,120,560,520,540,380,140,580,420,340,440,600,240,260,80,60,520,500,500,400,400,440,160,160,320,240,320,80,340,360,160,500,360,380,540,380,520,160,340,240,160,480,60,160,220,320,120,80,40,320,200,480,340,480,420,420,480,120,160,480,320,240,280,280,400,120,460,560,400,320,300,160,40,420,280,40,400,460,320,220,160,480,420,300,120,340,80,120,40,540,120,100,460,320,380,200,300,320,580,160,260,540,260,560,500,540,600,220,480,180,460,400,300,500,480,220,60,440,480,440,560]
t=[540,200,160,400,300,300,160,360,320,300,200,440,120,220,100,140,440,300,140,480,520,380,260,320,400,540,300,80,40,580,400,320,340,520,140,540,300,380,60,480,40,220,500,40,360,280,80,340,300,120,40,80,520,100,560,80,580,400,560,380,600,420,420,160,600,240,460,60,560,40,200,440,440,480,160,420,220,160,140,220,320,560,100,480,220,200,520,200,240,240,540,480,580,120,440,300,560,300,300,380,300,280,300,480,160,220,180,400,220,240,560,160,380,200,380,520,580,260,160,160,520,420,260,120,260,300,220,120,100,40,560,560,340,360,120,100,520,180,260,80,100,600,300,100,220,420,580,100,40,320,160,120,120,280,560,300,100,400,380,420,600,100,540,240,520,560,480,260,60,420,440,440,80,200,40,260,240,300,280,600,320,360,200,460,200,80,580,540,340,140,360,160,460,280,460,340,300,480,260,460,500,240,360,600,600,400,600,460,280,340,220,440,340,280,180,360,400,400,100,540,360,420,520,380,200,560,100,320,240,40,340,260,480,120,440,120,360,200,500,40,520,80,500,420,560,380,500,560,380,300,60,200,380,340,280,260,380,60,600,40,480,380,80,600,580,180,460,80,60,100,240,380,340,240,40,420,220,600,200,600,520,200,160,600,520,420,520,500,480,220,380,260,280,360,380,540,520,140,280,160,120,160,60,340,180,420,240,120,160,540,40,520,220,580,260,360,100,440,460,420,160,440,540,160,480,600,240,120,160,40,440,500,60,260,600,560,460,540,160,440,80,220,280,320,160,80,220,240,40,220,600,140,480,480,100,300,80,400,40,340,500,480,500,380,200,480,560,320,120,140,180,320,240,440,440,360,360,220,300,580,300,340,120,500,140,560,580,120,520,440,60,320,160,60,80,80,40,260,260,200,200,500,420,380,600,80,40,360,460,580,120,520,40,420,60,460,100,360,600,600,140,560,40,80,40,400,60,420,400]
img0 = Image.new('RGB', (1000, 1000), '#ffffff')
for i in range(len(s)):
for j in range(20):
for n in range(20):
img0.putpixel ((s[i]+j,t[i]+n), (0,0,0))
img0.save("result.png")
其中,20是試出來的,第一次用的10,第二次用的20就出來了

掃描即出flag
8.簡單二維碼
先說real flag:

用這個來控制左右偏移,之前哪場比賽(忘了)就用到了

然后說fake flag
fake flag1:打開WP,全選改字體顏色

fake flag2:
剛剛那段話后面有隱藏文字,選項—格式標記—勾選隱藏文字

fake flag3:
提示用stegsolve梭一下,用stegsolve打開發現LSB隱寫和二維碼,掃描二維碼又是一個fake flag

fake flag4:LSB

fake flag5:
在B通道

fake flag6:(啊這里沒有flag)
因為WP里面有兩張不顯示的圖片,所以將WP改成zip后綴解壓,進入word—media
發現第二張png圖缺少檔案頭所以不顯示,將其補上(89504E47)


fake flag7:
第三張png圖winhex查看

fake flag8:
word里面還有個flag.xml


9.你以為是easyRSA嗎,其實是我套娃之神噠
題目描述 里 有
說明零寬,直接復制之后去解就可以了
https://offdev.net/demos/zwsp-steg-js

然后解壓
e=62其實是提示base62,因為這明顯不滿足RSA
把c拿去16進制轉字串之后,得到4PNR3rDPYKOUENdjw4ovN8CILBFNmq
再拿去base62(cyberchef),得到解壓密碼password is ctfshowHHH
flag.zip是偽加密,把09改成00即可

some password is the flag,I means such as “password is abcde”,the flag is ctfshow{.*} 其中 ctfshow{正則} 最后得到 flag:ctfshow{some password}
10.我想要獲得旗幟
真的能通關,,幾分鐘就好了,反編譯用gm8decompiler(github),在反編譯中,滑鼠移動到那個問號上就知道了,
第一關(11)

第二關左上角(2)

第三關(114514)

第四關(1919810)

其中,這里給了flag格式,其他地方也分別有提示

第五關(233)

結合in order,按照順序連起來即可
11.misc41
注意F001,直接搜這個!

一眼就看出來了,flag大家自己去寫
12.亞當和夏娃
出題人說是非預期,我就直接說非預期了(預期也不會,,)
去binwalk 亞當和夏娃-Adam and s Eve n.png(或者tweakpng.exe)
我就用tweakpng吧,第一行這個(binwalk第一個文本)

提取出來保存,然后用notepad+±----插件-----converter----HEX–>ASCII
轉了之后保存,然后winhex查看

把jpg檔案頭前面的都刪掉,然后改成jpg打開

得到flag
13.阿拉丁

不知道是怎么出的,群主說只需要問他flagxxxxxx?即可,如果有數字則會回傳數字位,例如


用此方法組合起來即可
14.迷
也是群主說的,訪問/flag

根據題目描述,訪問/菜


15.LunaticRE
氣死了氣死了,明明找到了BUG()但是沒對flag部分做手腳
無殼,IDA64打開
期間,反復看了sub_140001730(),還找到了fake flag

還有提示,base58解碼即可


最后一個個函式的找,找到了他,可惡,當時沒有太去注意,

將其轉成字串形式,就能明顯發現是flag,全部組合起來即可

轉載請註明出處,本文鏈接:https://www.uj5u.com/qita/271933.html
標籤:其他
下一篇:Python 操作HDFS
