corCTF_2024
forensics
the-conspiracy
题面
Author: jammy, Solved: 283, Pts: 109Our intelligence team created a chat app, and secretly distributed it to the lemonthinker gang. We’ve given you the application source and a capture taken by one of our agents - can you uncover their plans?
题解
按照source.py
中的encrypt
方法写出对应的decrypt
方法
1 |
|
遍历数据包解密。
1 |
|
1 |
|
hello blinkoid
hello night
how do we eliminate the msfroggers
idk i’ll ask slice1
how do we eliminate the msfroggers
we can send them to the skibidi toilet
or we can deprive them of their fanum tax
slice1 is being useless
what’s new
blinkoid? message back :(
oh errr… this sounds great! any more ideas
we could co-conspire with the afs
and get them to infiltrate the msfroggers
that way team lemonthink reins supreme
your a genius!
alright night
i have my own idea
let’s hear it
so yk about the afs
if we send our secret code over to them
they can use it to infiltrate the afs
what’s our code again?
i think it’s corctf{b@53d_af_f0r_th3_w1n}
hey night did you hear my idea
you had an idea? blinkoid just told me you were being useless
what the sigma
infiltration
题面
Author: jammy, Solved: 164, Pts: 116After successfully infiltrating the lemonthinker gang, we’ve obtained their current location - the UK. We’ve attained some security logs from a gang member’s PC, but need some help in answering information relating to these.nc be.ax 32222
题解
根据交互信息提示,找到对应的字段:
Hello agent. Thanks for your hard work in the field researching. We’ll now ask you 6 questions
on the information you’ve gathered.
I’d like to take this opportunity to remind you that our targets are located in the United Kingdom, so their timezone is BST (UTC +1).
We’d like to confirm what the username of the main user
on the target’s computer is. Can you provide this information? slice1
Now, we’d like the name of the computer
, after it was renamed. Ensure that it is entered in exactly how it is in the logs.
I wonder if they’ll make any lemonade with that lemon-squeezer…
Great work! In order to prevent their lemons from moulding, the lemonthinkers changed the maximum password age
. What is this value? Please enter it as an integer number in days.
It seems that our targets are incredibly smart, and turned off the antivirus
. At what time
did this happen? Give your answer as a UNIX timestamp.
The main lemonthinker, slice1, hasn’t learnt from the-conspiracy and has (again) downloaded some malware on the system. What is the name of the user created by this malware
?
Finally, we’d like to know the name of the privilege level of the user created by the malware
. What is this?
- 主机用户名:查看登录事件,尝试得
slice1
。 - 变更后主机名:事件中包含多台计算机名,尝试后得
lemon-squeezer
。 - 更改最大密码时限:筛选
事件4739
,找到时间为83
天。 - 关闭Windows defender:搜索defender,筛选
事件4699
,从已删除计划任务
事件得到具体时间。 - 创建新用户:筛选
事件4720
,得到病毒创建的用户为notabackdoor
。 - 创建新特权等级:
事件4732
,得到病毒创建的特权等级为Administrators
。
Misc
lights-out
题面
Author: plastic, Solved: 155, Pts: 117You know the game. Solve the board quickly before a new one is generated.
题解
源码中已经给出了线性代数解
的代码,直接调用即可。
1 |
|
touch grass 2
Author: strellic, BrownieInMotion, FizzBuzz101, Solved: 60, Pts: 151题解
一道鼓励你亲近大自然的题,前端伪造定位即可。