๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

โœ’๏ธ Miscellaneous (Misc)/Dreamhack6

[Dreamhack] littlevsbig Write Up โš ๏ธ littlevsbig Write Up 1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋ฌธ์ œ ํŒŒ์ผ ์† chall.c ์˜คํ”ˆ ํ›„ ์ฝ”๋“œ ๋ถ„์„ --> FLAG ์ถœ๋ ฅ ์กฐ๊ฑด ๋ฐœ๊ฒฌ // Name: chall.c // Compile Option: gcc chall.c -o chall -fno-stack-protector #include #include #include #include #include #include #define FLAG_SIZE 0x45 void alarm_handler() { ใ…คใ…คputs("TIME OUT"); ใ…คใ…คexit(-1); } void initialize() { ใ…คใ…คsetvbuf(stdin, NULL, _IONBF, 0); ใ…คใ…คsetvbuf(stdout, NULL, _IONBF, 0); ใ…คใ…คsi.. 2023. 11. 28.
[Dreamhack] dreamhack-tools-cyberchef Write Up ๐ŸŒš dreamhack-tools-cyberchef Write Up 1. ๋ฌธ์ œ ์„ค๋ช… ํ™•์ธ ํ›„ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋‹ค์šด๋ฐ›์€ ํŒŒ์ผ ์† index.html ์œผ๋กœ ์ ‘์† --> ์•”ํ˜ธ๋ฌธ๊ณผ ์•”ํ˜ธํ™” ์ˆœ์„œ ๋ฐœ๊ฒฌ # ์•”ํ˜ธํ™” ์ˆœ์„œ : Rail Fence → Base64 → ROT13 # ๋ณตํ˜ธํ™” ์ˆœ์„œ : ROT13 → Base64 → Rail Fence 3. ๋ฌธ์ œ์— ๋ช…์‹œ๋œ Cyberchef ์œผ๋กœ ์ ‘์† ++ Dreamhack Cyberchef --> https://tools.dreamhack.games/cyberchef dreamhack-tools tools.dreamhack.games 4. ๋ณตํ˜ธํ™” ์ˆœ์„œ์— ๋”ฐ๋ผ ์•”ํ˜ธ๋ฌธ ์ฐจ๋ก€๋กœ ๋ณตํ˜ธํ™” --> FLAG ๋ฐœ๊ฒฌ # Input : EUg5MJAyYJ9fYJ5iMKqio29iVK1VL2Wl.. 2023. 11. 27.
[Dreamhack] Exercise: Welcome-Beginners ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿšบ Exercise: Welcome-Beginners ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ์„ค๋ช… ํ™•์ธ ํ›„ ์„œ๋ฒ„ ์ƒ์„ฑ 2. ์ƒ์„ฑํ•œ ์„œ๋ฒ„๋กœ ์ ‘์†ํ•˜๊ธฐ ์ „, ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ํ›„ ์˜คํ”ˆ 3. ์‚ฌ์šฉ์ž๋กœ๋ถ€ํ„ฐ ์ž…๋ ฅ๋ฐ›์€ ๊ฐ’์ด "Dreamhack" ์ธ ๊ฒฝ์šฐ FLAG๋ฅผ ์ถœ๋ ฅํ•˜๋Š” ๋ถ€๋ถ„ ๋ฐœ๊ฒฌ char cmp_str[10] = "Dreamhack"; char inp_str[10]; printf("Enter \"Dreamhack\" : "); scanf("%9s", inp_str); if(strcmp(cmp_str, inp_str) == 0){ ใ…คใ…คputs("Welcome Beginners!"); ใ…คใ…ค// print flag ใ…คใ…คputs(flag); } 4. Ubuntu ๊ฐ€์ƒํ™˜๊ฒฝ์—์„œ nc ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด ์„œ๋ฒ„ ์ ‘์† --> "Drea.. 2023. 11. 25.
[Dreamhack] baby-linux ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿคฑ baby-linux ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ์„ค๋ช… ํ™•์ธ ํ›„ ์„œ๋ฒ„ ์ƒ์„ฑ 2. ์ƒ์„ฑํ•œ ์„œ๋ฒ„๋กœ ์ ‘์† --> ls ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•˜์—ฌ ํ˜„์กดํ•˜๋Š” ํŒŒ์ผ ๋ชฉ๋ก ์ถœ๋ ฅ 3. cat ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด requirements.txt ํŒŒ์ผ ์˜คํ”ˆ --> ๋ณ„๋‹ค๋ฅธ ํžŒํŠธ๋ฅผ ๋ฐœ๊ฒฌํ•˜์ง€ ๋ชปํ•จ 4. cat ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด hint.txt ํŒŒ์ผ ์˜คํ”ˆ --> FLAG์˜ ๊ฒฝ๋กœ ๋ฐœ๊ฒฌ 5. ๋‹ค์‹œ cat ๋ช…๋ น์–ด๋ฅผ ์ด์šฉํ•ด hello ํŒŒ์ผ์— ์ ‘๊ทผ ์‹œ๋„ --> No! ๋ฌธ์ž์—ด๊ณผ ํ•จ๊ป˜ ์ ‘๊ทผ ๊ฑฐ๋ถ€ echo $(cat ./dream/hack/hello/flag.txt) 6. app.py ํŒŒ์ผ์„ ์—ด์–ด ์†Œ์Šค์ฝ”๋“œ ํ™•์ธ 7. app.py ์ฝ”๋“œ ํ™•์ธ --> Line 13์—์„œ 'flag' ์šฉ์–ด ํ•„ํ„ฐ๋ง ์š”์†Œ ๋ฐœ๊ฒฌ #!/usr/bin/env python3 import .. 2023. 11. 23.
[Dreamhack] broken-png ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿคณ broken-png ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ์— ๋Œ€ํ•œ ์„ค๋ช…์„ ์ฝ์€ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋‹ค์šด๋ฐ›์€ ์ด๋ฏธ์ง€ ํŒŒ์ผ ์—ด๊ธฐ --> FLAG ์ผ๋ถ€๊ฐ€ ์ž˜๋ ค์žˆ์Œ์„ ํ™•์ธ 3. HxD ์–ดํ”Œ์„ ํ†ตํ•ด ๋‹ค์šด๋ฐ›์€ ์ด๋ฏธ์ง€ ํŒŒ์ผ ์—ด๊ธฐ ++ HxD ํ”„๋กœ๊ทธ๋žจ์ด๋ž€? HxD๋Š” ์œˆ๋„์šฐ ์šด์˜ ์ฒด์ œ์—์„œ ๋™์ž‘ํ•˜๋Š” ํ”„๋ฆฌ์›จ์–ด ํ—ฅ์Šค ์—๋””ํ„ฐ๋กœ, ์ฃผ๋กœ ์ปดํ“จํ„ฐ ํŒŒ์ผ์˜ ์ด์ง„ ๋ฐ์ดํ„ฐ๋ฅผ ํŽธ์ง‘ ๋ฐ ๋ถ„์„ํ•˜๋Š” ๋„๊ตฌ๋กœ ์‚ฌ์šฉ๋œ๋‹ค. ์ด ์™ธ์—๋„ HxD๋Š” CRC(์ˆœํ™˜ ์ค‘๋ณต ๊ฒ€์‚ฌ) ์ง„ํ–‰ ๋ฐ ๋ฉ”๋ชจ๋ฆฌ ๊ฒ€์‚ฌ ๊ธฐ๋Šฅ๋„ ์ง€์›ํ•˜๋Š” ๊ฐ•๋ ฅํ•œ ๋„๊ตฌ๋กœ์„œ, ์ฃผ๋กœ ์‹œ์Šคํ…œ ๊ด€๋ฆฌ์ž๋‚˜ ํ”„๋กœ๊ทธ๋ž˜๋จธ, ๋ณด์•ˆ ์ „๋ฌธ๊ฐ€ ๋ฐ ์—”์ง€๋‹ˆ์–ด๊ฐ€ ์‚ฌ์šฉํ•œ๋‹ค. 4. ์ง„์ˆ˜ ์„ค์ •์„ '10'์œผ๋กœ ๋ณ€๊ฒฝํ•œ ๋’ค, ์ด๋ฏธ์ง€์˜ ์„ธ๋กœ ํฌ๊ธฐ๋ฅผ ๊ฐ€๋กœ์™€ ๋™์ผํ•˜๊ฒŒ ์กฐ์ • ํŒŒ๋ž‘ ๋ถ€๋ถ„ ๋นจ๊ฐ• ๋ถ€๋ถ„ 00 00 02 00 (10์ง„์ˆ˜) 00 00 0.. 2023. 8. 20.
[Dreamhack] 64se64 ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿ‘’ 64se64 ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ์— ๋Œ€ํ•œ ์„ค๋ช… ์ˆ™์ง€ (๋ฌธ์ œ ํŒŒ์ผ์€ ๋ณ„๋„ ๋‹ค์šด๋กœ๋“œ ํ•„์š” X) 2. ์„œ๋ฒ„ ์ƒ์„ฑ ํ›„ ์•ˆ๋‚ด๋œ ๋งํฌ๋กœ ์ ‘์† 3. F12 ๋‹จ์ถ•ํ‚ค๋ฅผ ํ†ตํ•ด ๊ฐœ๋ฐœ์ž ๋„๊ตฌ ์‹คํ–‰ --> Sources ํƒญ์—์„œ ์†Œ์Šค ์ฝ”๋“œ ํ™•์ธ Welcome! ๐Ÿ‘‹ 4. value ๋ณ€์ˆ˜ ์† base64๋กœ ์ธ์ฝ”๋”ฉ๋œ ๋ฌธ์ž์—ด ํ•ด๋…์„ ์œ„ํ•œ ์Šคํฌ๋ฆฝํŠธ ์ž‘์„ฑ import base64 encoded_data = "IyEvdXNyL2Jpbi9lbnYgcHl0aG9uMwphc2M9WzY4LCA3MiwgMTIzLCA5OCwgMTAxLCA0OCwgNTIsIDU0LCA5OCwgNTUsIDUzLCA1MCwgNTAsIDk3LCA5NywgNTAsIDEwMSwgNTAsIDU2LCAxMDIsIDUwLCA1NSwgNTQsIDEwMSwgNDgsID.. 2023. 8. 19.