๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

๋ณด์•ˆ/CTF32

[ctf-d] ์ €๋Š” ์ด๋ฏธ์ง€์—์„œ ์–ด๋–ค ๊ฒƒ์„... ์ด๋ฒˆ ๋ฌธ์ œ๋Š” ์ด๋ฏธ์ง€์— ๋ญ”๊ฐ€ ๋‹ต์ด ์žˆ์„ ๊ฒƒ ๊ฐ™์€ ๋ฌธ์ œ์ด๋‹ค. logo.gif ํŒŒ์ผ์„ ๋‹ค์šด๋ฐ›์•˜๋‹ค ๊ทผ๋ฐ gif ํŒŒ์ผ์€ ๋ณดํ†ต ์›€์งค์šฉ(?)์ด๋ผ ์›€์ง์—ฌ์•ผ ํ•˜๋Š”๋ฐ ์•„๋ž˜ ํ™”๋ฉด์—์„œ ์•„๋ฌด ๊ฒƒ๋„ ๋ฐ”๋€Œ์ง€ ์•Š์•˜๋‹ค ๊ทธ๋ž˜์„œ ๋‹ค๋ฅธ ์—ฐ๊ฒฐ ํ”„๋กœ๊ทธ๋žจ(๊ทธ๋ฆผํŒ)์„ ์ด์šฉํ•ด ์—ด์—ˆ๋Š”๋ฐ ๋ฐ”๋กœ ๋‹ต์ด ๋‚˜์™€๋ฒ„๋ ธ๋‹ค... ์ผ๋‹จ ํ™•์‹คํžˆ ๋งž๋Š”์ง€๋Š” ๋ชจ๋ฅด๊ฒ ์–ด์„œ boy_this_goes_by_so_fast ๋ฅผ ์ž…๋ ฅํ•œ ํ›„ ์ œ์ถœํ–ˆ๋”๋‹ˆ ์ •๋‹ต์ด๋ผ๋Š” ํ‘œ์‹œ๊ฐ€ ๋‚˜์™”๋‹ค ์ด๋ ‡๊ฒŒ ํ‘ธ๋Š” ๋ฌธ์ œ๊ฐ€ ์•„๋‹Œ ๊ฒƒ ๊ฐ™์€๋ฐ... ์ผ๋‹จ ํ’€๊ธด ํ’€์—ˆ๋‹ค.. 2020. 12. 7.
[ctf-d] ์‚ฌ์ง„ ์†์—์„œ ๋นจ๊ฐ„์ƒ‰์ด... ์ด๋ฒˆ ๋ฌธ์ œ๋Š” png ํŒŒ์ผ์„ ์ด์šฉํ•ด์„œ ํ‘ธ๋Š” ๋ฌธ์ œ์ด๋‹ค ๋นจ๊ฐ„์ƒ‰์„ ์ค‘์š”ํ•˜๊ฒŒ ๋ด์•ผ ํ•  ๊ฒƒ ๊ฐ™๋‹ค incoherency.co.uk/image-steganography/#unhide Image Steganography Each channel (red, green, blue) of each pixel in an image is represented by an 8-bit value. To hide the secret image inside the cover image, we replace the n least significant bits of the cover pixel value with the same number of most significant bits from incoherency.co.uk stegsolve.. 2020. 12. 4.
[ctf-d] ์ €ํฌ๋Š” ์ด ๋ฌธ์„œ๋ฅผ ์ฐพ์•˜์Šต๋‹ˆ๋‹ค. ์ด๋ฒˆ ๋ฌธ์ œ๋Š” docx ํŒŒ์ผ ์•ˆ์— ํ”Œ๋ž˜๊ทธ๋ฅผ ์ฐพ์•„์•ผ ํ•˜๋Š” ๋ฌธ์ œ์ด๋‹ค. ์ผ๋‹จ file.docx๋ฅผ ๋‹ค์šด๋ฐ›๊ณ  ์—ด์–ด๋ณด๋‹ˆ file์˜ ์ผ๋ถ€ ์ฝ˜ํ…์ธ ๋ฅผ ์ฝ์„ ์ˆ˜ ์—†๋‹ค๋ผ๋Š” ๊ฒฝ๊ณ ์ฐฝ์ด ๋‚˜์™”๊ณ  ์˜ˆ(Y)๋ฅผ ๋ˆŒ๋ €๋”๋‹ˆ This is not the flag you're looking for. ์ด๋ผ๋Š” ๋ฌธ๊ตฌ๊ฐ€ ๋‚˜์™”๋‹ค ์œ„ ๋ฐฉ๋ฒ•์œผ๋กœ ๋‹ต์ด ๋‚˜์˜ค์ง€ ์•Š์ž ํ—ฅ์Šค ์—๋””ํ„ฐ๋ฅผ ์‚ฌ์šฉํ–ˆ๋‹ค ๊ทธ๋ฆฌ๊ณ  ์ญ‰ ์Šคํฌ๋กคํ•ด๋ณด๋‹ˆ ์Šคํฌ๋กค ํ•œ ๋ถ€๋ถ„์€ this_would_be_the_flag_you_are_looking_for ์ด๋ผ๋Š” ๋ฌธ์ž์—ด์ด๋‹ค. ๋”ฐ๋ผ์„œ ์ด ๋ฌธ์ž์—ด์„ ์ž…๋ ฅํ•˜๋‹ˆ ์ •๋‹ต์ด๋ผ๊ณ  ๋‚˜์™”๋‹ค! 2020. 12. 2.
[ctf-d] ์ €๋Š” ํ”Œ๋ž˜๊ทธ๋ฅผ ์ด ํŒŒ์ผ์—... ์ด ๋ฌธ์ œ์—์„œ ์–ป์„ ์ˆ˜ ์žˆ๋Š” ๊ฑด ํŒŒ์ผ์— ํ”Œ๋ž˜๊ทธ๊ฐ€ ์กด์žฌํ•˜๊ณ , ํ‚ค ํฌ๋งท์ด ABCTF{(key)}๋ผ๋Š” ๊ฒƒ์ด๋‹ค ์ด ๋ฌธ์ œ๋ฅผ ํ‘ธ๋Š” ๋ฐฉ๋ฒ•์„ 1) ์†์„ฑ, 2) ํ—ฅ์Šค ์—๋””ํ„ฐ, 3) ์Šคํ…Œ๊ฐ€๋…ธ๊ทธ๋ž˜ํ”ผ๋กœ ์œ ์ถ”ํ–ˆ๋Š”๋ฐ ์ผ๋‹จ ํ—ฅ์Šค ์—๋””ํ„ฐ๋ฅผ ๋จผ์ € ์ด์šฉํ–ˆ๋‹ค ์ฐพ๊ธฐ-์ฐพ๊ธฐ ๊ธฐ๋Šฅ์„ ์ด์šฉํ•ด์„œ ํ…์ŠคํŠธ ๋ฌธ์ž์—ด ๊ฒ€์ƒ‰ ๋Œ€์ƒ์— ABCTF ๋ผ๊ณ  ์“ด ๋‹ค์Œ์— ์ˆ˜๋ฝ ๋ฒ„ํŠผ์„ ๋ˆŒ๋ €๋‹ค ๊ทธ๋Ÿฌ๋‹ˆ๊นŒ ์ด ๋ถ€๋ถ„์ด ABCTF์„ ํฌํ•จํ•˜๊ณ  ์žˆ๋‹ค๊ณ  ๋ฐ”๋กœ ๋‚˜์™”๋‹ค ํ‚ค ํฌ๋งท๋Œ€๋กœ ๋‹ต์„ ์Šคํฌ๋กคํ•˜๋ฉด ABCTF{forensics_1_tooo_easy?} ์ด ๋‚˜์˜จ๋‹ค ์œ„์—์„œ ์ž‘์„ฑํ•œ ๋‹ต ๊ทธ๋Œ€๋กœ ์ž…๋ ฅํ•˜๋ฉด ์ •๋‹ต์ด๋ผ๊ณ  ๋‚˜์˜จ๋‹ค 2020. 12. 2.
Suninatas Web ๋ฌธ์ œ ํ’€์ด * Web1, Web2, Web3, Web7, Misc12, Misc17 *์œ„ ๋ฌธ์ œ์— ๋Œ€ํ•ด PPT ํ˜•์‹์œผ๋กœ ์ •๋ฆฌํ–ˆ์Šต๋‹ˆ๋‹ค. 2020. 11. 27.
[AFFCTF] Lost head / Astatine / TheCrew 1) Lost head(FORENSICS) ๋ฌธ์ œ : ๋Š์–ด์ง„ ์—ฐ๊ฒฐ์„ ๋‹ค์‹œ ์ฐพ๋Š” ๋ฌธ์ œ ํŒŒ์ผ ํ™•์žฅ์ž๊ฐ€ pcap ์ด๋ผ๋Š” ์ ์—์„œ wireshark ํ”„๋กœ๊ทธ๋žจ์„ ์‚ฌ์šฉํ–ˆ๋‹ค ํŒŒ์ผ - Export Objects - HTTP ๊ธฐ๋Šฅ์„ ์ด์šฉํ•ด HTTP object list์—์„œ challenges.php ํŒŒ์ผ ์ด๋ฆ„์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค (์‚ฌ์‹ค ์—ฌ๊ธฐ์„œ ์–ด๋–ป๊ฒŒ ๋ฐ”๋กœ ํŒŒ์ผ - Export Objects - HTTP ๊ธฐ๋Šฅ์„ ์ด์šฉํ•˜๋Š”์ง€ ์ž˜ ๋ชฐ๋ž๋Š”๋ฐ ์ด ๋ถ€๋ถ„์— ๋Œ€ํ•ด์„œ๋Š” ์ข€ ๋” ๊ณต๋ถ€ํ•ด๋ด์•ผ ํ•  ๊ฒƒ ๊ฐ™๋‹ค..) php๋ž€? ๋™์  ์›น ํŽ˜์ด์ง€๋ฅผ ๋งŒ๋“ค๊ธฐ ์œ„ํ•ด ์„ค๊ณ„๋œ ํ”„๋กœ๊ทธ๋ž˜๋ฐ ์–ธ์–ด์˜ ์ผ์ข… challenges.php ํŒŒ์ผ์˜ ํŒจํ‚ท์ด 46๋ฒˆ์ธ๋ฐ 46๋ฒˆ์งธ ํŒจํ‚ท์„ ํ™•์ธํ•ด๋ณด๋ฉด(์šฐํด๋ฆญ -> Follow -> TCP Stream) ์ด๋ ‡๊ฒŒ ํ”Œ๋ž˜๊ทธ๊ฐ’์ด ์กด์žฌํ•˜๊ณ  ์žˆ๋‹ค๋Š” ๊ฒƒ์„ .. 2020. 11. 25.