#./keygen 4 "{a..z}" | xargs -I {} steghide extract -sf stega4.wav -p {}#fcrackzip -u -c aA1! -p aaaaa flag.zip#unzip -P 3L33t flag.zip && cat flag.txt
Showing posts with label cscamp. Show all posts
Showing posts with label cscamp. Show all posts
# CSCamp CTF Quals 2k13: Steganography - stega4.wav
Labels:
bruteforce,
crack,
cscamp,
ctf,
steganography
# CSCamp CTF Quals 2k13: Reversing - Challenge (dotnet)
# file challenge.exe
Run challenge.exe:. Username = Cookie
. Serial Number = Monsters
. Check
> Authentication failed!
Attach to the process using windbg:
>. Username = Cookie* Load SOS and symbols>.loadby sos mscorwks; .symfix; .reload>* Show all threads>~>* Show all managed threads>!threads>* Switch to thread 0 (new current thread)>~0s>* View the stack>!clrstack>* Show objects on the heap (MT = MethodTable)>!dumpheap -type StarwareCTF_DotNetChall>* Show what methods the object exposes>!dumpmt -md 00a0732c>* Method disassemble>!U 00a072ac>* Display one dword (4b)>dd 0BF1464h L1>* Method disassemble>!U 00de5960>* Set breakpoint at address>bp 00de5987>* Go>g
. Serial Number = Monsters
. Check
>> Authentication failed!* Display Unicode chars>du eax+c>* Clear all breakpoints>bc *>* Go>g
. Username = Cookie
. Serial Number = 0C81B9E71D6397203F2B7C73233FC5A4D9C6450D8037BB12BE9415B950AC3E521EA1B1C42B4ACD482C83FFBBA8212BE228A71FE544E463B59C344F1A41A55262
. Check
> Authentication successful. Waiting for flag
Reference
http://blog.botbie.com/2013/11/21/cscamp-ctf-quals-2013-reversing-150-write-up/
# CSCamp CTF Quals 2k13: Steganography - PNG
#file enc.png#cat png.py#./png.py#file dec.png
Labels:
cscamp,
ctf,
steganography
# CSCamp CTF Quals 2k13: Crypto - public is enough! (400 points)
#grep -v - public.pem | tr -d '\n' | base64 -d | openssl asn1parse -inform DER -i#grep -v - public.pem | tr -d '\n' | base64 -d | openssl asn1parse -inform DER -i -strparse 17#openssl rsa -pubin -inform PEM -text -noout < public.pem## Find p and q using this URL http://www.factordb.com/index.php#ipython:import gmpy:p = 33478071698956898786044169848212690817704794983713768568912431388982883793878002287614711652531743087737814467999489:q = 36746043666799590428244633799627952632279158164343087642676032283815739666511279233373417143396810270092798736308917:totien = (p-1) * (q-1):e = 65537:d = hex(gmpy.invert(e,totien)):d#cat rsatool.py#./rsatool.py -p 33478071698956898786044169848212690817704794983713768568912431388982883793878002287614711652531743087737814467999489 -q 36746043666799590428244633799627952632279158164343087642676032283815739666511279233373417143396810270092798736308917 -n 1230186684530117755130494958384962720772853569595334792197322452151726400507263657518745202199786469389956474942774063845925192557326303453731548268507917026122142913461670429214311602221240479274737794080665351419597459856902143413 -e 65537#ipython:from Crypto.PublicKey import RSA:keypair = RSA.generate(1024):keypair.n = 1230186684530117755130494958384962720772853569595334792197322452151726400507263657518745202199786469389956474942774063845925192557326303453731548268507917026122142913461670429214311602221240479274737794080665351419597459856902143413:keypair.e = 65537:keypair.d = 703813872109751212728960868893055483396831478279095442779477323396386489876250832944220079595968592852532432488202250497425262918616760886811596907743384527001944888359578241816763079495533278518938372814827410628647251148091159553:keypair.p = 33478071698956898786044169848212690817704794983713768568912431388982883793878002287614711652531743087737814467999489:keypair.q = 36746043666799590428244633799627952632279158164343087642676032283815739666511279233373417143396810270092798736308917:private = open('private.pem','w'):private.write(keypair.exportKey()):private.close():exit#openssl rsautl -decrypt -in message.enc -out /dev/tty -inkey private.pem#cat RSAcrack.py#cat message.enc | ./RSAcrack.py -d 740de48760442835baad5e1990453a9d16db7976d3f8bb98bf99c0c01cbe9b9c12b808c80683d1e346c16c79ac162874f28ca610c1b97e5e1ffae95725ce0c6b031c3e188b17187a793b322cc4004c568e76c9b258542ea2a2d6ecd462fff401 cad984557c97e039431a226ad727f0c6d43ef3d418469f1b375049b229843ee9f83b1f97738ac274f5f61f401f21f1913e4b64bb31b55a38d398c0dfed00b1392f0889711c44b359e7976c617fcc734f06e3e95c26476091b52f462e79413db5 | strings
# CSCamp CTF Quals 2k13: Steganography - Stego 3
Sam says "I love you, no really."
Mike says "Hot steamy grits!"
Mike says "Hot steamy grits!"
Mike says "No."
Sam says "Get off my colon"
Harold says "Who said OJ?"
Sam says "Who said OJ?"
JYA says "Jason paid me for it."
Harold says "Jason paid me for it."
Kenny says "Jason paid me for it."
Jason says "But I read slash-dot"
Phil says "Well smother me in curry sauce and lick me."
Adam says "Did he mean to die just then?"
Phil says "Mike - you ladyboy!"
Mike says "I said, you've got beautiful eyes."
Andy says "Mine's a pint"
Adam says "I'm so excited"
Adam says "I said, you've got beautiful eyes."
Adam says "So avoid that then!"
Harold says "Did he mean to die just then?"
JYA says "But I read slash-dot"
Phil says "Show me the fish!"
Sam says "Okay, now think of a funny line"
Mike says "Well smother me in curry sauce and lick me."
Adam says "Who said OJ?"
Mike says "Mike - you ladyboy!"
JYA says "Okay, now think of a funny line"
Adam says "Jason paid me for it."
Sam says "I never talk politics."
Mike says "Mmmm ... "
Harold says "Okay, now think of a funny line"
Mike says "Mine's a pint"
JYA says "Mike - you ladyboy!"
Kenny says "Who said OJ?"
Andy says "Alive"
Jason says "I'm so excited"
Kenny says "No."
Kenny says "No."
Andy says "I'd say Thursday"
JYA says "I'll be your private dancer, a dancer for money, I'll do what you want me to do."
Mr Hanky says "Mine's a pint"
JYA says "What does MPEG mean?"
Andy says "Has anyone noticed the plot is straying from ... well reason, really... "
JYA says "Mike - you ladyboy!"
Mike says "Mike - you ladyboy!"
Mike says "I said, you've got beautiful eyes."
Jason says "Has anyone noticed the plot is straying from ... well reason, really... "
Mr Hanky says "What does MPEG mean?"
Sam says "I'll be your private dancer, a dancer for money, I'll do what you want me to do."
Harold says "Who said OJ?"
Mike says "I'd say Thursday"
Sam says "So avoid that then!"
Harold says "What does MPEG mean?"
Mike says "Hot steamy grits!"
Kenny says "Did he mean to die just then?"
Kenny says "Well smother me in curry sauce and lick me."
Harold says "Did he mean to die just then?"
Adam says "But I read slash-dot"
Phil says "So avoid that then!"
Sam says "Mine's a pint"
Andy says "So avoid that then!"
end of scene
#wget --quiet http://web.archive.org/web/20100826055053/http://www.scramdisk.clara.net/play/playmaker.zip## Use playmaker to get the URL#wget --quiet http://www.mediafire.com/download/5fppbkaujddijuk/bruteme.rar#while read line; do result=`unrar x bruteme.rar -p$line 2> /dev/null | grep OK`; if [ "$result" != "" ]; then echo "Password = '$line'"; break; fi; done < dic.txt && cat Flag.txt
Labels:
cscamp,
ctf,
steganography
# CSCamp CTF Quals 2k13: Forensics - Forensics 1 (200 points)
#cat dataNov-8-2013.sql#names=$(while read line; do hex=`echo "$line" | xxd -p | tr -d '\n'`; if [ "`echo $hex | grep 0d`" != "" ]; then echo "`grep -A 1 "$line" dataNov-8-2013.sql | tail -n 1 | awk -F '"' '{print $2}'`"; fi; done < dataNov-8-2013.sql | tr '\n' ',')#echo -n ${names:0:-1} | md5sum
Subscribe to:
Posts (Atom)