๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

๋ณด์•ˆ/CTF32

W@S 2023 CTF Write-up ๋ฌธ์ œํ’€์ด W@S 2023 CTF ๋ผ์—… ๋ฌธ์ œ ํ’€์ด 1๋ฒˆ ~ 6๋ฒˆ๊นŒ์ง€์˜ ๋ฌธ์ œ ํ’€์ด์ž…๋‹ˆ๋‹ค. (์„œ์ˆ ํ˜• ๋ฌธ์ œ๋„ ์žˆ๊ธฐ ๋•Œ๋ฌธ์— ์ •๋‹ต์ผ์ˆ˜๋„ ์•„๋‹์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค) QR ์ฝ”๋“œ ์‚ฌ์ง„์„ ๋ฆฌ๋”๊ธฐ๋ฅผ ํ†ตํ•ด ์ธ์‹ํ•˜๋ฉด ‘aHR0cHM6Ly9uYXZlci5tZS94TTJ1c3luSQ==’ ๋ฌธ์ž์—ด ์ถœ๋ ฅ ํ•ด๋‹น ๋ฌธ์ž์—ด์ด Base 64 ์ธ์ฝ”๋”ฉ๋œ ๊ฒƒ์ด๋ผ ์ƒ๊ฐ๋˜์–ด ๋””์ฝ”๋”ฉ (๋ณดํ†ต == ๋กœ ๋๋‚˜๋Š” ๊ฒฝ์šฐ Base 64 ์ธ์ฝ”๋”ฉ๋œ ๋ฌธ์ž์—ด์ด๊ธฐ ๋•Œ๋ฌธ) -> ํ•ด๋‹น ๋งํฌ๋กœ ๊ตฌ๊ธ€์— ๊ฒ€์ƒ‰ํ•œ ๊ฒฐ๊ณผ ‘ํ•œ๊ตญ์—ฌ์„ฑ๊ณผํ•™๊ธฐ์ˆ ์ธ์œก์„ฑ์žฌ๋‹จ’ ๋„ค์ด๋ฒ„ ์ง€๋„๊ฐ€ ๋‚˜์˜ด 1) 3.39.31.69 ์ง์ ‘ ์ ‘์† -> https://3.39.31.69/ ์ธํ„ฐ๋žฉ ์›น ์‚ฌ์ดํŠธ ์ฃผ์†Œ(https://interlab.or.kr/) Interlab ์ธํ„ฐ๋žฉ | Between Technology and Society ์ธํ„ฐ๋žฉ์€ .. 2023. 4. 9.
[HackCTF] Welcome_Forensics, Question? (forensics) https://ctf.j0n9hyun.xyz/challenges HackCTF Do you wanna be a God? If so, Challenge! ctf.j0n9hyun.xyz Welcome_Forensics ์ผ๋‹จ ์‚ฌ์ง„์ด ์„ธ๋กœ๋กœ ์™„์ „ํžˆ ์••์ถ•๋˜์—ˆ๋‹ค ์–ด๋–ป๊ฒŒ ํฌ๋ Œ์‹ ๋ฌธ์ œ์ธ์ง€๋Š” ๋ชจ๋ฅด๊ฒ ๋Š”๋ฐ ์ผ๋‹จ ํŒŒ์›Œํฌ์ธํŠธ๋กœ ๋ณต๋ถ™ํ•ด๋ณด๋‹ˆ ๋ฐ”๋กœ ์ด๋ ‡๊ฒŒ ํ”Œ๋ž˜๊ทธ ๊ฐ’์ด ์ œ๋Œ€๋กœ ๋‚˜์™”๊ณ  ๋‘๋ฒˆ์งธ๋กœ๋Š” ๋‹ค๋ฅธ์ด๋ฆ„์œผ๋กœ ์ €์žฅํ–ˆ์„ ๋•Œ๋„ ์ •๋ง ํ”Œ๋ž˜๊ทธ ๊ฐ’์ด ๊ทธ๋Œ€๋กœ ๋‚˜์™”๋‹ค HackCTF{w3lc0m3_70_f0r3n51c_w0rld!} Question? ์••์ถ•ํŒŒ์ผ์„ ํ•ด์ œํ•ด์„œ ๋”๋ธ”ํด๋ฆญํ•˜๋ฉด HxD๋กœ ํ™•์ธํ•˜๋ฉด ํŒŒ์ผ ์‹œ๊ทธ๋‹ˆ์ฒ˜์—๋Š” ์ด์ƒ์ด ์—†๋‹ค ๊ทธ๋Ÿผ Decoded text์—์„œ HackCTF๋ฅผ ๊ฒ€์ƒ‰ํ•ด๋ดค๋”๋‹ˆ ์ด๋ ‡๊ฒŒ ํ”Œ๋ž˜๊ทธ ๊ฐ’์ด ๋‚˜์˜จ๋‹ค HackCTF{P1e45e_find_.. 2021. 5. 29.
[HackCTF] Who Am I?, QRCODE (misc) https://ctf.j0n9hyun.xyz/login?next=%2Fchallenges HackCTF Do you wanna be a God? If so, Challenge! ctf.j0n9hyun.xyz Who am I? ๋ง ๊ทธ๋Œ€๋กœ x86 Instruction์—์„œ eip๋ฅผ ํ„ฐ๋œจ๋ ค์ฃผ๋Š” ์—ญํ• ์„ ์ฐพ๋Š” ๋ฌธ์ œ์ด๋‹ค eip๋ž€? ๋ช…๋ น ํฌ์ธํ„ฐ ๋ ˆ์ง€์Šคํ„ฐ์ด๋ฉฐ ๋‹ค์Œ์— ์‹คํ–‰ํ•ด์•ผ ํ•  ๋ช…๋ น์–ด๊ฐ€ ์กด์žฌํ•˜๋Š” ๋ฉ”๋ชจ๋ฆฌ ์ฃผ์†Œ๊ฐ€ ์ €์žฅ๋œ๋‹ค. ํ˜„์žฌ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ ์™„๋ฃŒํ•œ ํ›„์— eip ๋ ˆ์ง€์Šคํ„ฐ์— ์ €์žฅ๋˜์–ด ์žˆ๋Š” ์ฃผ์†Œ์— ์œ„์น˜ํ•œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜๊ฒŒ ๋œ๋‹ค. https://chriskhj6296.tistory.com/24 x86 CPU ๋ ˆ์ง€์Šคํ„ฐ ์กฐ์‚ฌ x86 CPU ๋ ˆ์ง€์Šคํ„ฐ ์กฐ์‚ฌ 1. ๋ ˆ์ง€์Šคํ„ฐ์˜ ์ข…๋ฅ˜์™€ ๊ทธ ์—ญํ•  ๋จผ์ € ์ข…๋ฅ˜๊ฐ€ ๊ทธ ๋ชฉ์ ์— ๋”ฐ๋ผ ๋ฒ”์šฉ ๋ ˆ์ง€์Šคํ„ฐ, ์„ธ.. 2021. 5. 29.
[N0Named] RE: xeh_desrev http://ctf.no-named.kr:1234/challenges#RE:%20xeh_desrev ์ด๋ฒˆ ๋ฌธ์ œ์—์„œ๋Š” 1) ์ผ๋‹จ png๋ฅผ ๋ณต๊ตฌํ•ด์•ผ ํ•˜๊ณ  2) xeh_deserev -> hex_reversed ํ—ฅ์Šค๊ฐ’์„ ๊ฑฐ๊พธ๋กœ ๋’ค์ง‘์œผ๋ผ๋Š” ์˜๋ฏธ์ธ ๊ฒƒ์„ ์œ ์ถ”ํ–ˆ๋‹ค ๋‹ค์‹œ ํ—ฅ์Šค์—๋””ํ„ฐ๋ฅผ ์‚ฌ์šฉํ–ˆ๋‹ค ๋”ฐ๋ผ์„œ ๊ฐ€์žฅ ๋’ท๋ถ€๋ถ„์„ ํ™•์ธํ–ˆ๋Š”๋ฐ ๋ฌธ์ œ์˜ ํžŒํŠธ์ฒ˜๋Ÿผ 89 50 4E 47 0D 0A 1A 0A ์ด๋ ‡๊ฒŒ ๋’ค๋ถ€ํ„ฐ png ํ—ค๋” ์‹œ๊ทธ๋‹ˆ์ฒ˜๊ฐ€ ์กด์žฌํ–ˆ๋‹ค ์ด ํŒŒ์ผ์„ ๊ฑฐ๊พธ๋กœ ๋’ค์ง‘๊ธฐ ์œ„ํ•ด ํ•˜๋‚˜ํ•˜๋‚˜ ๊ฐ’์„ ๋ฐ”๊ฟ”์ค„ ์ˆ˜๋„ ์žˆ์ง€๋งŒ ๊ทธ๋Ÿฌ๊ธฐ์—” ์‹œ๊ฐ„์ด ์—†์–ด์„œ ํŒŒ์ด์ฌ ์ฝ”๋“œ๋ฅผ ์ž‘์„ฑํ•ด์„œ ๋ฐ”๊ฟ”์ฃผ์—ˆ๋‹ค ๋”ฐ๋ผ์„œ ํŒŒ์ด์ฌ ํŒŒ์ผ ์ฝ๊ธฐ/์“ฐ๊ธฐ ๊ฐœ๋…๊ณผ ํŒŒ์ผ ๋ฐ”์ด๋„ˆ๋ฆฌ ๊ฑฐ๊พธ๋กœ ์ €์žฅํ•˜๊ธฐ ์‚ฌ์ดํŠธ๋ฅผ ํ†ตํ•ด ์ฝ”๋“œ๋ฅผ ์ž‘์„ฑํ–ˆ๋‹ค https://m.blog.naver.com/PostView.naver?b.. 2021. 5. 24.
[N0Named] magicIMAGE http://ctf.no-named.kr:1234/challenges#magicIMAGE ์ด๋ฒˆ ๋ฌธ์ œ๋Š” png๋ฅผ ๋ณต๊ตฌํ•˜๋Š” ๋ฌธ์ œ์ด๋‹ค ์ผ๋‹จ mandu.png๋ฅผ ๋‹ค์šด ๋ฐ›์•˜๋Š”๋ฐ, ์—ญ์‹œ ํŒŒ์ผ์ด ๊นจ์ ธ์žˆ์—ˆ๋‹ค ์ผ๋‹จ ์ด ์ƒํƒœ์—์„œ๋Š” ์•„๋ฌด๋Ÿฐ ์ •๋ณด๋ฅผ ์–ป์„ ์ˆ˜ ์—†์œผ๋ฏ€๋กœ ํ—ฅ์Šค์—๋””ํ„ฐ๋ฅผ ์‚ฌ์šฉํ•ด์„œ ๋จผ์ € ํ—ค๋” ์‹œ๊ทธ๋‹ˆ์ฒ˜๋ฅผ ํ™•์ธํ–ˆ๋‹ค https://know0how.tistory.com/6 [HxD] Hex Editor ํ”„๋กœ๊ทธ๋žจ ๋‹ค์šด๋กœ๋“œ ๋ฐ ์‚ฌ์šฉ๋ฒ• Hex Editor(์ดํ•˜ Hxd), ํ—ฅ์Šค ์—๋””ํ„ฐ ๋˜๋Š” ํ—ฅ์Šค ์ฝ”๋“œ ์—๋””ํ„ฐ๋ผ๋Š” ๋ช…์นญ์„ ์ผ์ปซ๊ณ  ์žˆ์œผ๋ฉฐ ์ด ํ”„๋กœ๊ทธ๋žจ์— ๋Œ€ํ•ด ์ƒ์„ธํžˆ ์•Œ๊ณ  ์‹œ์ž‘ํ•˜๊ธฐ ์ „์— ๊ธฐ๋ณธ์ ์œผ๋กœ ์•Œ์•„๋‘˜ ๊ฒŒ ์žˆ์Šต๋‹ˆ๋‹ค. ํ—ฅ์Šค(Hex)๋Š” ์ผ๋ฐ˜์ ์œผ๋กœ '์‹ญ์œก know0how.tistory.com 89 50 4E 47 ๊นŒ์ง€๋Š” PNG ํ—ค๋” ์‹œ๊ทธ๋‹ˆ์ฒ˜์™€ ๊ฐ™.. 2021. 5. 24.
[ctf-d] woodstock-1 ์ด๋ฒˆ ๋ฌธ์ œ๋Š” ํ™•์žฅ์ž๊ฐ€ pcpang์ธ ๊ฒƒ์„ ํ†ตํ•ด์„œ ์™€์ด์–ด์ƒคํฌ๋ฅผ ์ด์šฉํ•ด์•ผ๊ฒ ๋‹ค๋Š” ์ƒ๊ฐ์ด ๋“ค์—ˆ๋‹ค ๊ทธ๋ฆฌ๊ณ  ํ‚ค ํฌ๋งท์€ BITSCTF{(key)} ์ด๋‹ค * ์™€์ด์–ด์ƒคํฌ ๋‹ค์šด๋กœ๋“œ ํ™ˆํŽ˜์ด์ง€ www.wireshark.org/download.html Wireshark · Download Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products that fully integrate with Wireshark. I have a lot of traffic... ANSWER: SteelCentral™ AppResponse 11 • Full stack analysis – from packets to pages • Ric .. 2020. 12. 7.