-
Notifications
You must be signed in to change notification settings - Fork 0
/
index.html
195 lines (178 loc) · 40.9 KB
/
index.html
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
<!DOCTYPE html><html lang="en" data-theme="light"><head><meta charset="UTF-8"><meta http-equiv="X-UA-Compatible" content="IE=edge"><meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0"><title>crazyman_army's blog - crazyman_army's blog</title><meta name="author" content="crazyman_army"><meta name="copyright" content="crazyman_army"><meta name="format-detection" content="telephone=no"><meta name="theme-color" content="#ffffff"><meta name="description" content="A Noob's Learning Record">
<meta property="og:type" content="website">
<meta property="og:title" content="crazyman_army's blog">
<meta property="og:url" content="https://crazymanarmy.github.io/index.html">
<meta property="og:site_name" content="crazyman_army's blog">
<meta property="og:description" content="A Noob's Learning Record">
<meta property="og:locale" content="en_US">
<meta property="og:image" content="https://s2.loli.net/2023/01/27/XA2Yr7TuwcNWhOp.jpg">
<meta property="article:author" content="crazyman_army">
<meta name="twitter:card" content="summary">
<meta name="twitter:image" content="https://s2.loli.net/2023/01/27/XA2Yr7TuwcNWhOp.jpg"><link rel="shortcut icon" href="https://s2.loli.net/2023/01/29/Duzv3pAYSsxaiVk.png"><link rel="canonical" href="https://crazymanarmy.github.io/index.html"><link rel="preconnect" href="//cdn.jsdelivr.net"/><link rel="preconnect" href="//busuanzi.ibruce.info"/><link rel="stylesheet" href="/css/index.css"><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/@fortawesome/fontawesome-free/css/all.min.css" media="print" onload="this.media='all'"><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/@fancyapps/ui/dist/fancybox.min.css" media="print" onload="this.media='all'"><script>const GLOBAL_CONFIG = {
root: '/',
algolia: undefined,
localSearch: {"path":"/search.xml","preload":false,"languages":{"hits_empty":"We didn't find any results for the search: ${query}"}},
translate: undefined,
noticeOutdate: undefined,
highlight: {"plugin":"highlighjs","highlightCopy":true,"highlightLang":true,"highlightHeightLimit":false},
copy: {
success: 'Copy successfully',
error: 'Copy error',
noSupport: 'The browser does not support'
},
relativeDate: {
homepage: false,
post: false
},
runtime: '',
date_suffix: {
just: 'Just',
min: 'minutes ago',
hour: 'hours ago',
day: 'days ago',
month: 'months ago'
},
copyright: undefined,
lightbox: 'fancybox',
Snackbar: undefined,
source: {
justifiedGallery: {
js: 'https://cdn.jsdelivr.net/npm/flickr-justified-gallery/dist/fjGallery.min.js',
css: 'https://cdn.jsdelivr.net/npm/flickr-justified-gallery/dist/fjGallery.min.css'
}
},
isPhotoFigcaption: false,
islazyload: false,
isAnchor: false,
percent: {
toc: true,
rightside: false,
}
}</script><script id="config-diff">var GLOBAL_CONFIG_SITE = {
title: 'crazyman_army\'s blog',
isPost: false,
isHome: true,
isHighlightShrink: false,
isToc: false,
postUpdate: '2023-04-05 20:52:42'
}</script><noscript><style type="text/css">
#nav {
opacity: 1
}
.justified-gallery img {
opacity: 1
}
#recent-posts time,
#post-meta time {
display: inline !important
}
</style></noscript><script>(win=>{
win.saveToLocal = {
set: function setWithExpiry(key, value, ttl) {
if (ttl === 0) return
const now = new Date()
const expiryDay = ttl * 86400000
const item = {
value: value,
expiry: now.getTime() + expiryDay,
}
localStorage.setItem(key, JSON.stringify(item))
},
get: function getWithExpiry(key) {
const itemStr = localStorage.getItem(key)
if (!itemStr) {
return undefined
}
const item = JSON.parse(itemStr)
const now = new Date()
if (now.getTime() > item.expiry) {
localStorage.removeItem(key)
return undefined
}
return item.value
}
}
win.getScript = url => new Promise((resolve, reject) => {
const script = document.createElement('script')
script.src = url
script.async = true
script.onerror = reject
script.onload = script.onreadystatechange = function() {
const loadState = this.readyState
if (loadState && loadState !== 'loaded' && loadState !== 'complete') return
script.onload = script.onreadystatechange = null
resolve()
}
document.head.appendChild(script)
})
win.getCSS = url => new Promise((resolve, reject) => {
const link = document.createElement('link')
link.rel = 'stylesheet'
link.href = url
link.onload = () => resolve()
link.onerror = () => reject()
document.head.appendChild(link)
})
win.activateDarkMode = function () {
document.documentElement.setAttribute('data-theme', 'dark')
if (document.querySelector('meta[name="theme-color"]') !== null) {
document.querySelector('meta[name="theme-color"]').setAttribute('content', '#0d0d0d')
}
}
win.activateLightMode = function () {
document.documentElement.setAttribute('data-theme', 'light')
if (document.querySelector('meta[name="theme-color"]') !== null) {
document.querySelector('meta[name="theme-color"]').setAttribute('content', '#ffffff')
}
}
const t = saveToLocal.get('theme')
if (t === 'dark') activateDarkMode()
else if (t === 'light') activateLightMode()
const asideStatus = saveToLocal.get('aside-status')
if (asideStatus !== undefined) {
if (asideStatus === 'hide') {
document.documentElement.classList.add('hide-aside')
} else {
document.documentElement.classList.remove('hide-aside')
}
}
const detectApple = () => {
if(/iPad|iPhone|iPod|Macintosh/.test(navigator.userAgent)){
document.documentElement.classList.add('apple')
}
}
detectApple()
})(window)</script><meta name="generator" content="Hexo 5.4.2"><link rel="alternate" href="/atom.xml" title="crazyman_army's blog" type="application/atom+xml">
</head><body><div id="web_bg"></div><div id="sidebar"><div id="menu-mask"></div><div id="sidebar-menus"><div class="avatar-img is-center"><img src="https://s2.loli.net/2023/01/27/XA2Yr7TuwcNWhOp.jpg" onerror="onerror=null;src='/img/friend_404.gif'" alt="avatar"/></div><div class="sidebar-site-data site-data is-center"><a href="/archives/"><div class="headline">Articles</div><div class="length-num">13</div></a><a href="/tags/"><div class="headline">Tags</div><div class="length-num">40</div></a><a href="/categories/"><div class="headline">Categories</div><div class="length-num">1</div></a></div><hr/><div class="menus_items"><div class="menus_item"><a class="site-page" href="/"><i class="fa-fw fas fa-home"></i><span> Home</span></a></div><div class="menus_item"><a class="site-page" href="/archives/"><i class="fa-fw fas fa-archive"></i><span> Archives</span></a></div><div class="menus_item"><a class="site-page" href="/tags/"><i class="fa-fw fas fa-tags"></i><span> Tags</span></a></div><div class="menus_item"><a class="site-page" href="/categories/"><i class="fa-fw fas fa-folder-open"></i><span> Categories</span></a></div><div class="menus_item"><a class="site-page" href="/link/"><i class="fa-fw fas fa-link"></i><span> Link</span></a></div><div class="menus_item"><a class="site-page" href="/about/"><i class="fa-fw fas fa-heart"></i><span> About</span></a></div></div></div></div><div class="page" id="body-wrap"><header class="full_page" id="page-header" style="background-image: url('https://s2.loli.net/2023/01/27/EqtWY23KHfAipbG.webp')"><nav id="nav"><span id="blog-info"><a href="/" title="crazyman_army's blog"><img class="site-icon" src="https://s2.loli.net/2023/01/29/Duzv3pAYSsxaiVk.png"/><span class="site-name">crazyman_army's blog</span></a></span><div id="menus"><div id="search-button"><a class="site-page social-icon search" href="javascript:void(0);"><i class="fas fa-search fa-fw"></i><span> Search</span></a></div><div class="menus_items"><div class="menus_item"><a class="site-page" href="/"><i class="fa-fw fas fa-home"></i><span> Home</span></a></div><div class="menus_item"><a class="site-page" href="/archives/"><i class="fa-fw fas fa-archive"></i><span> Archives</span></a></div><div class="menus_item"><a class="site-page" href="/tags/"><i class="fa-fw fas fa-tags"></i><span> Tags</span></a></div><div class="menus_item"><a class="site-page" href="/categories/"><i class="fa-fw fas fa-folder-open"></i><span> Categories</span></a></div><div class="menus_item"><a class="site-page" href="/link/"><i class="fa-fw fas fa-link"></i><span> Link</span></a></div><div class="menus_item"><a class="site-page" href="/about/"><i class="fa-fw fas fa-heart"></i><span> About</span></a></div></div><div id="toggle-menu"><a class="site-page" href="javascript:void(0);"><i class="fas fa-bars fa-fw"></i></a></div></div></nav><div id="site-info"><h1 id="site-title">crazyman_army's blog</h1><div id="site_social_icons"><a class="social-icon" href="https://twitter.com/CrazymanArmy" target="_blank" title="Twitter"><i class="fab fa-twitter"></i></a><a class="social-icon" href="mailto:[email protected]" target="_blank" title="Email"><i class="fas fa-envelope"></i></a><a class="social-icon" href="https://crazymanarmy.github.io/atom.xml" target="_blank" title="RSS"><i class="fa fa-rss"></i></a></div></div><div id="scroll-down"><i class="fas fa-angle-down scroll-down-effects"></i></div></header><main class="layout" id="content-inner"><div class="recent-posts" id="recent-posts"><div class="recent-post-item"><div class="post_cover left"><a href="/2023/04/05/XCTF-FINAL-7TH-Misc/" title="XCTF final 7th Misc - checkin Let's play mazegame && Let's play shellgame Writeup"><img class="post-bg" src="https://s2.loli.net/2023/04/05/h3qgQx71avNS6HX.jpg" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="XCTF final 7th Misc - checkin Let's play mazegame && Let's play shellgame Writeup"></a></div><div class="recent-post-info"><a class="article-title" href="/2023/04/05/XCTF-FINAL-7TH-Misc/" title="XCTF final 7th Misc - checkin Let's play mazegame && Let's play shellgame Writeup">XCTF final 7th Misc - checkin Let's play mazegame && Let's play shellgame Writeup</a><div class="article-meta-wrap"><span class="post-meta-date"><i class="far fa-calendar-alt"></i><span class="article-meta-label">Created</span><time datetime="2023-04-05T13:00:00.000Z" title="Created 2023-04-05 21:00:00">2023-04-05</time></span><span class="article-meta"><span class="article-meta-separator">|</span><i class="fas fa-inbox"></i><a class="article-meta__categories" href="/categories/Writeup/">Writeup</a></span></div><div class="content">checkin Let’s play mazegame:本来是作为签到题的 但是我的col写成了row 但是不让动态patch 所以公告上的patch给选手带来了很多不便在此表示抱歉
其主要思路就是dp选最大路径
exp:
12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364from pwn import *import stringfrom hashlib import sha256from tqdm import tqdmr = remote('127.0.0.1', 10002)N = 750def PoW(r, l): r.recvuntil(b'XXXX+') nonce = r.recvuntil(b')')[:-1].decode() r.recvuntil(b'== ') target ...</div></div></div><div class="recent-post-item"><div class="post_cover right"><a href="/2023/02/13/DiceCTF-2023-Misc-Writeup/" title="DiceCTF 2023 Misc Writeup"><img class="post-bg" src="https://s2.loli.net/2023/02/08/oVqsXMUceypINKx.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="DiceCTF 2023 Misc Writeup"></a></div><div class="recent-post-info"><a class="article-title" href="/2023/02/13/DiceCTF-2023-Misc-Writeup/" title="DiceCTF 2023 Misc Writeup">DiceCTF 2023 Misc Writeup</a><div class="article-meta-wrap"><span class="post-meta-date"><i class="far fa-calendar-alt"></i><span class="article-meta-label">Created</span><time datetime="2023-02-13T00:00:00.000Z" title="Created 2023-02-13 08:00:00">2023-02-13</time></span><span class="article-meta"><span class="article-meta-separator">|</span><i class="fas fa-inbox"></i><a class="article-meta__categories" href="/categories/Writeup/">Writeup</a></span></div><div class="content">DiceCTF 2023 Misc WriteupThis past week, during the Lantern Festival holiday, I checked out the DiceCTF 2023 with r3kapig. there were some good challenges. Overall the quality was very good and I learnt a lot from it. Here is a writeup of some of the Misc challenges, with * as a replay after the game
mlog:Challenge Description:
123456789101112Author:jim & asphyxiaThe future of log lines is here! Get your ML infused log lines and never worry about missing information in your logs.nc mc.ax 312 ...</div></div></div><div class="recent-post-item"><div class="post_cover left"><a href="/2023/02/03/%E7%AC%AC%E5%85%AD%E5%B1%8A%E8%A5%BF%E6%B9%96%E8%AE%BA%E5%89%91%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E5%A4%A7%E8%B5%9B-Misc-Isolated-Machine-Memory-Analysis-Writeup/" title="第六届西湖论剑网络安全大赛-Misc Isolated Machine Memory Analysis Writeup"><img class="post-bg" src="https://s2.loli.net/2023/02/03/ILHDQObjZ5xtFPa.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="第六届西湖论剑网络安全大赛-Misc Isolated Machine Memory Analysis Writeup"></a></div><div class="recent-post-info"><a class="article-title" href="/2023/02/03/%E7%AC%AC%E5%85%AD%E5%B1%8A%E8%A5%BF%E6%B9%96%E8%AE%BA%E5%89%91%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E5%A4%A7%E8%B5%9B-Misc-Isolated-Machine-Memory-Analysis-Writeup/" title="第六届西湖论剑网络安全大赛-Misc Isolated Machine Memory Analysis Writeup">第六届西湖论剑网络安全大赛-Misc Isolated Machine Memory Analysis Writeup</a><div class="article-meta-wrap"><span class="post-meta-date"><i class="far fa-calendar-alt"></i><span class="article-meta-label">Created</span><time datetime="2023-02-03T15:30:00.000Z" title="Created 2023-02-03 23:30:00">2023-02-03</time></span><span class="article-meta"><span class="article-meta-separator">|</span><i class="fas fa-inbox"></i><a class="article-meta__categories" href="/categories/Writeup/">Writeup</a></span></div><div class="content">第六届西湖论剑网络安全大赛-Misc Isolated Machine Memory Analysis Writeup本文赛后与zysgmzb共同完成
Isolated Machine Memory Analysis:123456789101112131415题目名称:Isolated Machine Memory Analysis题目内容:张三,现用名叫Charlie,在一家外企工作,负责flag加密技术的研究。为了避免flag泄露,这家企业制定了严格的安全策略,严禁flag离开研发服务器,登录服务器必须经过跳板机。张三使用的跳板机是一台虚拟机,虽然被全盘加密没法提取,但好消息是至少还没关机。 免责声明:本题涉及的人名、单位名、产品名、域名及IP地址等均为虚构,如有雷同纯属巧合。 注:本题模拟真实研发环境,解题有关的信息不会出现在人名、域名或IP地址等不合常理的地方。链接:https://pan.baidu.com/s/1WESej-pyjWKZni7drZGTig?pwd=cq46 提取码:cq46题目难度:中等Hint:hint1:在张三的电脑上发现一张截图,看起来应该是配置跳板 ...</div></div></div><div class="recent-post-item"><div class="post_cover right"><a href="/2023/02/03/%E7%AC%AC%E5%85%AD%E5%B1%8A%E8%A5%BF%E6%B9%96%E8%AE%BA%E5%89%91%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E5%A4%A7%E8%B5%9B-Misc-%E6%9C%BA%E4%BD%A0%E5%A4%AA%E7%BE%8E-Writeup/" title="第六届西湖论剑网络安全大赛-Misc 机你太美 Writeup"><img class="post-bg" src="https://s2.loli.net/2023/02/03/ILHDQObjZ5xtFPa.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="第六届西湖论剑网络安全大赛-Misc 机你太美 Writeup"></a></div><div class="recent-post-info"><a class="article-title" href="/2023/02/03/%E7%AC%AC%E5%85%AD%E5%B1%8A%E8%A5%BF%E6%B9%96%E8%AE%BA%E5%89%91%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E5%A4%A7%E8%B5%9B-Misc-%E6%9C%BA%E4%BD%A0%E5%A4%AA%E7%BE%8E-Writeup/" title="第六届西湖论剑网络安全大赛-Misc 机你太美 Writeup">第六届西湖论剑网络安全大赛-Misc 机你太美 Writeup</a><div class="article-meta-wrap"><span class="post-meta-date"><i class="far fa-calendar-alt"></i><span class="article-meta-label">Created</span><time datetime="2023-02-03T11:20:00.000Z" title="Created 2023-02-03 19:20:00">2023-02-03</time></span><span class="article-meta"><span class="article-meta-separator">|</span><i class="fas fa-inbox"></i><a class="article-meta__categories" href="/categories/Writeup/">Writeup</a></span></div><div class="content">第六届西湖论剑网络安全大赛2022-Misc 机你太美 Writeup机你太美1234567891011121314151617题目名称:机你太美题目内容:坤坤的手机里面,隐藏着什么秘密呢 链接:https://pan.baidu.com/s/1iWy1p9uDV4_15yCQ6jJMgw?pwd=7dfk 提取码:7dfk题目难度:困难Hint:hint1:adbshellhint2:看看找到的图片?hint3:在线exif附件更新https://dasctf-1251267611.file.myqcloud.com/gcsis2022/jntm-update.7z9ecf123c75b34f5ab1055796ae521d84 dasctf.npbk(这个附件是可以解决的,上面题目内容的附件有误)
导入npbk:下载发现是npbk文件
npbk文件可以通过夜神模拟器导入进行分析 https://whatext.com/npbk
下载夜神模拟器后可以修改一下npbk的打开方式这样直接点开后就可以在多开的部分看到导入,导入dasctf.npbk可以得到
需要先创建一个基于Andr ...</div></div></div><div class="recent-post-item"><div class="post_cover left"><a href="/2023/01/31/Hgame-2023-week3-Tunnel-&&-Tunnel-Revenge-Writeup(EN)/" title="Hgame 2023 week3 - Tunnel && Tunnel Revenge Writeup(EN)"><img class="post-bg" src="https://s2.loli.net/2023/01/27/LEtGKn9vX3DBSil.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="Hgame 2023 week3 - Tunnel && Tunnel Revenge Writeup(EN)"></a></div><div class="recent-post-info"><a class="article-title" href="/2023/01/31/Hgame-2023-week3-Tunnel-&&-Tunnel-Revenge-Writeup(EN)/" title="Hgame 2023 week3 - Tunnel && Tunnel Revenge Writeup(EN)">Hgame 2023 week3 - Tunnel && Tunnel Revenge Writeup(EN)</a><div class="article-meta-wrap"><span class="post-meta-date"><i class="far fa-calendar-alt"></i><span class="article-meta-label">Created</span><time datetime="2023-01-31T12:00:00.000Z" title="Created 2023-01-31 20:00:00">2023-01-31</time></span><span class="article-meta"><span class="article-meta-separator">|</span><i class="fas fa-inbox"></i><a class="article-meta__categories" href="/categories/Writeup/">Writeup</a></span></div><div class="content">Hgame 2023 week3 - Tunnel && Tunnel Revenge Writeup(EN):There is nothing to do on the third day of the Lunar New Year. I basically finished worshiping and started normal work and study. Hgame 2023 week3 just started. There is a misc question. A friend told me that it is very interesting, so I will take a look. Then I successfully got the first blood. The following is the idea of solving the problem
Tunnel:Unexpected pinch
Direct strings | grep hgame will come out
12345crazyman@ubuntu:~/D ...</div></div></div><div class="recent-post-item"><div class="post_cover right"><a href="/2023/01/31/Hgame-2023-week3-Tunnel-&&-Tunnel-Revenge-Writeup-CN/" title="Hgame 2023 week3 - Tunnel && Tunnel Revenge Writeup(CN)"><img class="post-bg" src="https://s2.loli.net/2023/01/27/LEtGKn9vX3DBSil.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="Hgame 2023 week3 - Tunnel && Tunnel Revenge Writeup(CN)"></a></div><div class="recent-post-info"><a class="article-title" href="/2023/01/31/Hgame-2023-week3-Tunnel-&&-Tunnel-Revenge-Writeup-CN/" title="Hgame 2023 week3 - Tunnel && Tunnel Revenge Writeup(CN)">Hgame 2023 week3 - Tunnel && Tunnel Revenge Writeup(CN)</a><div class="article-meta-wrap"><span class="post-meta-date"><i class="far fa-calendar-alt"></i><span class="article-meta-label">Created</span><time datetime="2023-01-31T12:00:00.000Z" title="Created 2023-01-31 20:00:00">2023-01-31</time></span><span class="article-meta"><span class="article-meta-separator">|</span><i class="fas fa-inbox"></i><a class="article-meta__categories" href="/categories/Writeup/">Writeup</a></span></div><div class="content">Hgame 2023 week3 - Tunnel && Tunnel Revenge Writeup(CN):大年初三没啥事,基本上都拜完了,开始正常的工作和学习了.正好Hgame 2023的week3开了.有一个misc题.朋友跟我说蛮有意思的,我就来看看.然后顺利拿到了一血.以下是解题思路
Tunnel:有非预期捏
直接strings | grep hgame就出了
12345crazyman@ubuntu:~/Desktop$ strings tunnel.pcapng | grep hgamehgame{ikev1_may_not_safe_aw987rtgh}hgame{ikev1_may_not_safe_aw987rtgh}hgame{ikev1_may_not_safe_aw987rtgh}hgame{ikev1_may_not_safe_aw987rtgh}
flag是–> hgame{ikev1_may_not_safe_aw987rtgh} ...</div></div></div><div class="recent-post-item"><div class="post_cover left"><a href="/2023/01/30/RealWorld-CTF-5th-Paddle-Writeup/" title="RealWorld CTF 5th - Paddle Writeup"><img class="post-bg" src="https://s2.loli.net/2023/01/30/OGIBvu3sSgNFRzQ.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="RealWorld CTF 5th - Paddle Writeup"></a></div><div class="recent-post-info"><a class="article-title" href="/2023/01/30/RealWorld-CTF-5th-Paddle-Writeup/" title="RealWorld CTF 5th - Paddle Writeup">RealWorld CTF 5th - Paddle Writeup</a><div class="article-meta-wrap"><span class="post-meta-date"><i class="far fa-calendar-alt"></i><span class="article-meta-label">Created</span><time datetime="2023-01-30T12:00:00.000Z" title="Created 2023-01-30 20:00:00">2023-01-30</time></span><span class="article-meta"><span class="article-meta-separator">|</span><i class="fas fa-inbox"></i><a class="article-meta__categories" href="/categories/Writeup/">Writeup</a></span></div><div class="content">RealWorld CTF 5th - Paddle Writeup:solved this challenge with thezzisu
By reading docker, it is mainly the following modules:
1234paddle-serving-server==0.9.0 \paddle-serving-client==0.9.0 \paddle-serving-app==0.9.0 \paddlepaddle==2.3.0
From WORKDIR /usr/local/lib/python3.6/site-packages/paddle_serving_server/env_check/simple_web_service,CMD ["python", "web_service.py"] in dockerfile, it is known that the loading of its main body is mainly paddle-serving-server
Search throug ...</div></div></div><div class="recent-post-item"><div class="post_cover right"><a href="/2023/01/23/Insomni%E2%80%99hack-teaser-2023-Autopsy/" title="Insomni’hack teaser 2023 - Autopsy"><img class="post-bg" src="https://s2.loli.net/2023/01/27/EihMjorFgk3KGJq.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="Insomni’hack teaser 2023 - Autopsy"></a></div><div class="recent-post-info"><a class="article-title" href="/2023/01/23/Insomni%E2%80%99hack-teaser-2023-Autopsy/" title="Insomni’hack teaser 2023 - Autopsy">Insomni’hack teaser 2023 - Autopsy</a><div class="article-meta-wrap"><span class="post-meta-date"><i class="far fa-calendar-alt"></i><span class="article-meta-label">Created</span><time datetime="2023-01-23T10:40:18.000Z" title="Created 2023-01-23 18:40:18">2023-01-23</time></span><span class="article-meta"><span class="article-meta-separator">|</span><i class="fas fa-inbox"></i><a class="article-meta__categories" href="/categories/Writeup/">Writeup</a></span></div><div class="content">Insomni’hack teaser 2023 - Autopsy:In the Lunar New Year, I played Insomni’hack teaser 2023, one of the topics labeled forensics, realistic, windows aroused my interest, I solved him. And I learned some knowledge from it. This is the record writeup
Autopsy:Wireshark loads through the export object and selects http, save all and then filters to get three files SYSTEM, SECURITY, ntds.dit
Then after searching, you can learn some relevant content about credential extraction
https://github.com/Secur ...</div></div></div><div class="recent-post-item"><div class="post_cover left"><a href="/2023/01/18/idek-2022-CTF-Pyjail-Pyjail-Revenge-Writeup/" title="idek 2022* CTF Pyjail && Pyjail Revenge Writeup"><img class="post-bg" src="https://s2.loli.net/2023/01/27/y7ElGdeCTWafXrh.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="idek 2022* CTF Pyjail && Pyjail Revenge Writeup"></a></div><div class="recent-post-info"><a class="article-title" href="/2023/01/18/idek-2022-CTF-Pyjail-Pyjail-Revenge-Writeup/" title="idek 2022* CTF Pyjail && Pyjail Revenge Writeup">idek 2022* CTF Pyjail && Pyjail Revenge Writeup</a><div class="article-meta-wrap"><span class="post-meta-date"><i class="far fa-calendar-alt"></i><span class="article-meta-label">Created</span><time datetime="2023-01-18T12:18:21.000Z" title="Created 2023-01-18 20:18:21">2023-01-18</time></span><span class="article-meta"><span class="article-meta-separator">|</span><i class="fas fa-inbox"></i><a class="article-meta__categories" href="/categories/Writeup/">Writeup</a></span></div><div class="content">idek 2022* CTF Pyjail && Pyjail Revenge WriteupPyjail:The code looks like this
123blocklist = ['.', '\\', '[', ']', '{', '}',':']DISABLE_FUNCTIONS = ["getattr", "eval", "exec", "breakpoint", "lambda", "help"]DISABLE_FUNCTIONS = {func: None for func in DISABLE_FUNCTIONS}
There is a blocklist ban off '.' , '\\', '[', ...</div></div></div><div class="recent-post-item"><div class="post_cover right"><a href="/2023/01/16/idek-CTF-2022-Forensics-HiddenGem-Mixtape-Writeup/" title="idek CTF 2022* Forensics - HiddenGem Mixtape Writeup"><img class="post-bg" src="https://s2.loli.net/2023/01/27/mMRbNxrHtVLlu7v.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="idek CTF 2022* Forensics - HiddenGem Mixtape Writeup"></a></div><div class="recent-post-info"><a class="article-title" href="/2023/01/16/idek-CTF-2022-Forensics-HiddenGem-Mixtape-Writeup/" title="idek CTF 2022* Forensics - HiddenGem Mixtape Writeup">idek CTF 2022* Forensics - HiddenGem Mixtape Writeup</a><div class="article-meta-wrap"><span class="post-meta-date"><i class="far fa-calendar-alt"></i><span class="article-meta-label">Created</span><time datetime="2023-01-16T12:26:35.000Z" title="Created 2023-01-16 20:26:35">2023-01-16</time></span><span class="article-meta"><span class="article-meta-separator">|</span><i class="fas fa-inbox"></i><a class="article-meta__categories" href="/categories/Writeup/">Writeup</a></span></div><div class="content">idek CTF 2022* Forensics - HiddenGem Mixtape WriteupThis week is the Preliminary Eve in China, and most of my time is resting and partying. At the same time, there are some good challenges in idek CTF, among which I prefer the HiddenGem Mixtape series of challenges. Since I am a forensics enthusiast, and I I am also a malware analyst. So I prefer this challenge that is close to the realworld. Although some people may feel that this challenge is strange,guessing. Including some designs that may c ...</div></div></div><nav id="pagination"><div class="pagination"><span class="page-number current">1</span><a class="page-number" href="/page/2/#content-inner">2</a><a class="extend next" rel="next" href="/page/2/#content-inner"><i class="fas fa-chevron-right fa-fw"></i></a></div></nav></div><div class="aside-content" id="aside-content"><div class="card-widget card-info"><div class="is-center"><div class="avatar-img"><img src="https://s2.loli.net/2023/01/27/XA2Yr7TuwcNWhOp.jpg" onerror="this.onerror=null;this.src='/img/friend_404.gif'" alt="avatar"/></div><div class="author-info__name">crazyman_army</div><div class="author-info__description">A Noob's Learning Record</div></div><div class="card-info-data site-data is-center"><a href="/archives/"><div class="headline">Articles</div><div class="length-num">13</div></a><a href="/tags/"><div class="headline">Tags</div><div class="length-num">40</div></a><a href="/categories/"><div class="headline">Categories</div><div class="length-num">1</div></a></div><a id="card-info-btn" target="_blank" rel="noopener" href="https://github.com/crazymanarmy"><i class="fab fa-github"></i><span>Follow Me</span></a><div class="card-info-social-icons is-center"><a class="social-icon" href="https://twitter.com/CrazymanArmy" target="_blank" title="Twitter"><i class="fab fa-twitter"></i></a><a class="social-icon" href="mailto:[email protected]" target="_blank" title="Email"><i class="fas fa-envelope"></i></a><a class="social-icon" href="https://crazymanarmy.github.io/atom.xml" target="_blank" title="RSS"><i class="fa fa-rss"></i></a></div></div><div class="card-widget card-announcement"><div class="item-headline"><i class="fas fa-bullhorn fa-shake"></i><span>Announcement</span></div><div class="announcement_content">欢迎来到我的blog,这里主要记录一些由我所自己研究的东西,包括打比赛的writeup,漏洞分析,样本分析,学习记录,感想和其他杂七杂八的东西.希望你可以在这里玩得开心 ^_^</div></div><div class="sticky_layout"><div class="card-widget card-recent-post"><div class="item-headline"><i class="fas fa-history"></i><span>Recent Post</span></div><div class="aside-list"><div class="aside-list-item"><a class="thumbnail" href="/2023/04/05/XCTF-FINAL-7TH-Misc/" title="XCTF final 7th Misc - checkin Let's play mazegame && Let's play shellgame Writeup"><img src="https://s2.loli.net/2023/04/05/h3qgQx71avNS6HX.jpg" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="XCTF final 7th Misc - checkin Let's play mazegame && Let's play shellgame Writeup"/></a><div class="content"><a class="title" href="/2023/04/05/XCTF-FINAL-7TH-Misc/" title="XCTF final 7th Misc - checkin Let's play mazegame && Let's play shellgame Writeup">XCTF final 7th Misc - checkin Let's play mazegame && Let's play shellgame Writeup</a><time datetime="2023-04-05T13:00:00.000Z" title="Created 2023-04-05 21:00:00">2023-04-05</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2023/02/13/DiceCTF-2023-Misc-Writeup/" title="DiceCTF 2023 Misc Writeup"><img src="https://s2.loli.net/2023/02/08/oVqsXMUceypINKx.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="DiceCTF 2023 Misc Writeup"/></a><div class="content"><a class="title" href="/2023/02/13/DiceCTF-2023-Misc-Writeup/" title="DiceCTF 2023 Misc Writeup">DiceCTF 2023 Misc Writeup</a><time datetime="2023-02-13T00:00:00.000Z" title="Created 2023-02-13 08:00:00">2023-02-13</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2023/02/03/%E7%AC%AC%E5%85%AD%E5%B1%8A%E8%A5%BF%E6%B9%96%E8%AE%BA%E5%89%91%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E5%A4%A7%E8%B5%9B-Misc-Isolated-Machine-Memory-Analysis-Writeup/" title="第六届西湖论剑网络安全大赛-Misc Isolated Machine Memory Analysis Writeup"><img src="https://s2.loli.net/2023/02/03/ILHDQObjZ5xtFPa.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="第六届西湖论剑网络安全大赛-Misc Isolated Machine Memory Analysis Writeup"/></a><div class="content"><a class="title" href="/2023/02/03/%E7%AC%AC%E5%85%AD%E5%B1%8A%E8%A5%BF%E6%B9%96%E8%AE%BA%E5%89%91%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E5%A4%A7%E8%B5%9B-Misc-Isolated-Machine-Memory-Analysis-Writeup/" title="第六届西湖论剑网络安全大赛-Misc Isolated Machine Memory Analysis Writeup">第六届西湖论剑网络安全大赛-Misc Isolated Machine Memory Analysis Writeup</a><time datetime="2023-02-03T15:30:00.000Z" title="Created 2023-02-03 23:30:00">2023-02-03</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2023/02/03/%E7%AC%AC%E5%85%AD%E5%B1%8A%E8%A5%BF%E6%B9%96%E8%AE%BA%E5%89%91%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E5%A4%A7%E8%B5%9B-Misc-%E6%9C%BA%E4%BD%A0%E5%A4%AA%E7%BE%8E-Writeup/" title="第六届西湖论剑网络安全大赛-Misc 机你太美 Writeup"><img src="https://s2.loli.net/2023/02/03/ILHDQObjZ5xtFPa.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="第六届西湖论剑网络安全大赛-Misc 机你太美 Writeup"/></a><div class="content"><a class="title" href="/2023/02/03/%E7%AC%AC%E5%85%AD%E5%B1%8A%E8%A5%BF%E6%B9%96%E8%AE%BA%E5%89%91%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E5%A4%A7%E8%B5%9B-Misc-%E6%9C%BA%E4%BD%A0%E5%A4%AA%E7%BE%8E-Writeup/" title="第六届西湖论剑网络安全大赛-Misc 机你太美 Writeup">第六届西湖论剑网络安全大赛-Misc 机你太美 Writeup</a><time datetime="2023-02-03T11:20:00.000Z" title="Created 2023-02-03 19:20:00">2023-02-03</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2023/01/31/Hgame-2023-week3-Tunnel-&&-Tunnel-Revenge-Writeup(EN)/" title="Hgame 2023 week3 - Tunnel && Tunnel Revenge Writeup(EN)"><img src="https://s2.loli.net/2023/01/27/LEtGKn9vX3DBSil.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="Hgame 2023 week3 - Tunnel && Tunnel Revenge Writeup(EN)"/></a><div class="content"><a class="title" href="/2023/01/31/Hgame-2023-week3-Tunnel-&&-Tunnel-Revenge-Writeup(EN)/" title="Hgame 2023 week3 - Tunnel && Tunnel Revenge Writeup(EN)">Hgame 2023 week3 - Tunnel && Tunnel Revenge Writeup(EN)</a><time datetime="2023-01-31T12:00:00.000Z" title="Created 2023-01-31 20:00:00">2023-01-31</time></div></div></div></div><div class="card-widget card-categories"><div class="item-headline">
<i class="fas fa-folder-open"></i>
<span>Categories</span>
</div>
<ul class="card-category-list" id="aside-cat-list">
<li class="card-category-list-item "><a class="card-category-list-link" href="/categories/Writeup/"><span class="card-category-list-name">Writeup</span><span class="card-category-list-count">13</span></a></li>
</ul></div><div class="card-widget card-tags"><div class="item-headline"><i class="fas fa-tags"></i><span>Tags</span></div><div class="card-tag-cloud"><a href="/tags/AI/" style="font-size: 1.1em; color: #999">AI</a> <a href="/tags/Android/" style="font-size: 1.2em; color: #999da3">Android</a> <a href="/tags/Android-Pin/" style="font-size: 1.1em; color: #999">Android Pin</a> <a href="/tags/BABA-IS-YOU/" style="font-size: 1.1em; color: #999">BABA IS YOU</a> <a href="/tags/BMC-Cache/" style="font-size: 1.2em; color: #999da3">BMC-Cache</a> <a href="/tags/CTF/" style="font-size: 1.5em; color: #99a9bf">CTF</a> <a href="/tags/CVE-2019-16328/" style="font-size: 1.1em; color: #999">CVE-2019-16328</a> <a href="/tags/Clone-And-Pwn/" style="font-size: 1.1em; color: #999">Clone-And-Pwn</a> <a href="/tags/Crypto/" style="font-size: 1.1em; color: #999">Crypto</a> <a href="/tags/ESP-Protocol/" style="font-size: 1.2em; color: #999da3">ESP Protocol</a> <a href="/tags/EVTX-Log-Anaylsis/" style="font-size: 1.1em; color: #999">EVTX Log Anaylsis</a> <a href="/tags/Forensics/" style="font-size: 1.3em; color: #99a1ac">Forensics</a> <a href="/tags/GIMP/" style="font-size: 1.1em; color: #999">GIMP</a> <a href="/tags/ISAKMP-Protocol/" style="font-size: 1.2em; color: #999da3">ISAKMP Protocol</a> <a href="/tags/Kerberos-Protocol/" style="font-size: 1.1em; color: #999">Kerberos Protocol</a> <a href="/tags/Misc/" style="font-size: 1.4em; color: #99a5b6">Misc</a> <a href="/tags/PHP/" style="font-size: 1.1em; color: #999">PHP</a> <a href="/tags/Pickle/" style="font-size: 1.1em; color: #999">Pickle</a> <a href="/tags/PowerShell/" style="font-size: 1.1em; color: #999">PowerShell</a> <a href="/tags/Pwn/" style="font-size: 1.1em; color: #999">Pwn</a> <a href="/tags/Pyjail/" style="font-size: 1.1em; color: #999">Pyjail</a> <a href="/tags/RGBA-Convert/" style="font-size: 1.1em; color: #999">RGBA Convert</a> <a href="/tags/SSH/" style="font-size: 1.1em; color: #999">SSH</a> <a href="/tags/Sysdig/" style="font-size: 1.2em; color: #999da3">Sysdig</a> <a href="/tags/VRAM/" style="font-size: 1.1em; color: #999">VRAM</a> <a href="/tags/VirtualBox/" style="font-size: 1.1em; color: #999">VirtualBox</a> <a href="/tags/Web/" style="font-size: 1.1em; color: #999">Web</a> <a href="/tags/Windows/" style="font-size: 1.2em; color: #999da3">Windows</a> <a href="/tags/YAFFS/" style="font-size: 1.1em; color: #999">YAFFS</a> <a href="/tags/adb-shell/" style="font-size: 1.1em; color: #999">adb shell</a> <a href="/tags/bashjail/" style="font-size: 1.1em; color: #999">bashjail</a> <a href="/tags/dp/" style="font-size: 1.1em; color: #999">dp</a> <a href="/tags/maze/" style="font-size: 1.1em; color: #999">maze</a> <a href="/tags/npbk/" style="font-size: 1.1em; color: #999">npbk</a> <a href="/tags/openssl/" style="font-size: 1.1em; color: #999">openssl</a> <a href="/tags/prompt-injection/" style="font-size: 1.1em; color: #999">prompt injection</a> <a href="/tags/pyjail/" style="font-size: 1.1em; color: #999">pyjail</a> <a href="/tags/python-format-exec/" style="font-size: 1.1em; color: #999">python format exec</a> <a href="/tags/rpyc/" style="font-size: 1.1em; color: #999">rpyc</a> <a href="/tags/shellcode/" style="font-size: 1.1em; color: #999">shellcode</a></div></div><div class="card-widget card-archives"><div class="item-headline"><i class="fas fa-archive"></i><span>Archives</span></div><ul class="card-archive-list"><li class="card-archive-list-item"><a class="card-archive-list-link" href="/archives/2023/04/"><span class="card-archive-list-date">April 2023</span><span class="card-archive-list-count">1</span></a></li><li class="card-archive-list-item"><a class="card-archive-list-link" href="/archives/2023/02/"><span class="card-archive-list-date">February 2023</span><span class="card-archive-list-count">3</span></a></li><li class="card-archive-list-item"><a class="card-archive-list-link" href="/archives/2023/01/"><span class="card-archive-list-date">January 2023</span><span class="card-archive-list-count">6</span></a></li><li class="card-archive-list-item"><a class="card-archive-list-link" href="/archives/2021/12/"><span class="card-archive-list-date">December 2021</span><span class="card-archive-list-count">1</span></a></li><li class="card-archive-list-item"><a class="card-archive-list-link" href="/archives/2021/10/"><span class="card-archive-list-date">October 2021</span><span class="card-archive-list-count">1</span></a></li><li class="card-archive-list-item"><a class="card-archive-list-link" href="/archives/2021/08/"><span class="card-archive-list-date">August 2021</span><span class="card-archive-list-count">1</span></a></li></ul></div><div class="card-widget card-webinfo"><div class="item-headline"><i class="fas fa-chart-line"></i><span>Info</span></div><div class="webinfo"><div class="webinfo-item"><div class="item-name">Article :</div><div class="item-count">13</div></div><div class="webinfo-item"><div class="item-name">UV :</div><div class="item-count" id="busuanzi_value_site_uv"><i class="fa-solid fa-spinner fa-spin"></i></div></div><div class="webinfo-item"><div class="item-name">PV :</div><div class="item-count" id="busuanzi_value_site_pv"><i class="fa-solid fa-spinner fa-spin"></i></div></div><div class="webinfo-item"><div class="item-name">Last Push :</div><div class="item-count" id="last-push-date" data-lastPushDate="2023-04-05T12:52:42.010Z"><i class="fa-solid fa-spinner fa-spin"></i></div></div></div></div></div></div></main><footer id="footer" style="background-image: url('https://s2.loli.net/2023/01/27/EqtWY23KHfAipbG.webp')"><div id="footer-wrap"><div class="copyright">©2023 By crazyman_army</div><div class="framework-info"><span>Framework </span><a target="_blank" rel="noopener" href="https://hexo.io">Hexo</a><span class="footer-separator">|</span><span>Theme </span><a target="_blank" rel="noopener" href="https://github.com/jerryc127/hexo-theme-butterfly">Butterfly</a></div><div class="footer_custom_text">Hope you like them</div></div></footer></div><div id="rightside"><div id="rightside-config-hide"><button id="darkmode" type="button" title="Switch Between Light And Dark Mode"><i class="fas fa-adjust"></i></button><button id="hide-aside-btn" type="button" title="Toggle between single-column and double-column"><i class="fas fa-arrows-alt-h"></i></button></div><div id="rightside-config-show"><button id="rightside_config" type="button" title="Setting"><i class="fas fa-cog fa-spin"></i></button><button id="go-up" type="button" title="Back To Top"><span class="scroll-percent"></span><i class="fas fa-arrow-up"></i></button></div></div><div id="local-search"><div class="search-dialog"><nav class="search-nav"><span class="search-dialog-title">Search</span><span id="loading-status"></span><button class="search-close-button"><i class="fas fa-times"></i></button></nav><div class="is-center" id="loading-database"><i class="fas fa-spinner fa-pulse"></i><span> Loading the Database</span></div><div class="search-wrap"><div id="local-search-input"><div class="local-search-box"><input class="local-search-box--input" placeholder="Search for Posts" type="text"/></div></div><hr/><div id="local-search-results"></div></div></div><div id="search-mask"></div></div><div><script src="/js/utils.js"></script><script src="/js/main.js"></script><script src="https://cdn.jsdelivr.net/npm/@fancyapps/ui/dist/fancybox.umd.min.js"></script><script src="/js/search/local-search.js"></script><div class="js-pjax"></div><script async data-pjax src="//busuanzi.ibruce.info/busuanzi/2.3/busuanzi.pure.mini.js"></script></div></body></html>