åå ã¾ã§ã¯ã以å ã«è¡ã£ã OWASP ZAP ã®èªåèå¼±æ§ã¹ãã£ã³ã®çµæã«ã¤ãã¦ããªã¹ã¯é«ãä¸ã«ã¤ãã¦ãåæã¨å¯¾çããã£ã¦ãã¾ããã
ä»åã¯ãCTFï¼Capture The Flagï¼ã«å
¥éãã¦ã¿ããã¨æãã¾ãã
CTF ã¨ã¯ãã»ãã¥ãªãã£ã«ãããå°éç¥èãæè¡ã使ã£ã¦ãé ããã¦ãã Flagï¼æãçããæååï¼ãè¦ã¤ãã競æã§ãã競æã¨è¨ã£ã¦ãããã¥ã¼ããªã¢ã«çãªå
¥éã¬ãã«ãããè³éãè¨å®ãããæ¬æ ¼çãªå¤§ä¼ã¾ã§ããããã§ãã
å½å
ã§éå¶ããã¦ãã CpawCTF ã¨ãããµã¤ããããã¾ããã¢ã«ã¦ã³ããä½ãã¨ãæ¥æ¬èªã§ãç¡æã§ãèªåã®ãã¼ã¹ã§ãCTF ã«ææ¦ã§ãã¾ããä»åã¯ãå®éã« CpawCTF ã«ãµã¤ã³ã¢ãããã¦ãå§ãã¦ã¿ããã¨æãã¾ãã
ããã§ã¯ããã£ã¦ããã¾ãã
ã¯ããã«
ãã»ãã¥ãªãã£ãã®è¨äºä¸è¦§ã§ããè¯ãã£ããåèã«ãã¦ãã ããã
ã»ãã¥ãªãã£ã®è¨äºä¸è¦§
CpawCTFã®å§ãæ¹
ã¾ãã以ä¸ã® CpawCTF ã®ãµã¤ãã«ã¢ã¯ã»ã¹ãã¾ãã
ctf.cpaw.site
CpawCTFã«ãµã¤ã³ã¢ãã
ããã¨ã以ä¸ã®ãããªç»é¢ã«ãªãã¾ããå³ä¸ã®ãSignUpããã¯ãªãã¯ããã¨ãScreenNameï¼è¡¨ç¤ºåï¼ãUserIDãPasswordãPassword (again) ã®å
¥åé
ç®ã表示ããã¾ãã
CpawCTFã®ãµã¤ã³ã¢ãã
ScreenName ã¯éè¤ãã¦ã大ä¸å¤«ããã ã¨æã£ãã®ã§ãããæ¢ã«ä½¿ããã¦ãã¨è¨ããã¦ãã¡ã§ãããScreenNameãUserID ã¯ã©ã¡ããã¦ãã¼ã¯ãªååãå
¥åããå¿
è¦ãããããã§ãã
CpawCTFã«ãµã¤ã³ã¢ããã§ãã
ç¡äºã«ãµã¤ã³ã¢ãããå®äºããã¨ã以ä¸ã®ãããªç»é¢ã«ãªãã¾ããã¾ãã¯ããã¥ã¼ããªã¢ã«çãªæãã§ãLevel 1 ãããã¾ããLevel 2 㨠Level 3ããã£ã¦ããããå®äºããã¨ã次ã®ã¹ããããããããã§ãã
ãµã¤ã³ã¢ããå¾ã®ç»é¢
CpawCTFã®Level 1
ãã㧠CpawCTF ã®åé¡ã®çããè¨è¼ãããã¨ã¯ããã¾ããããæåã® Test Problem ã¯ãã¹ãã¨ãããã¨ã§ãé°å²æ°ããä¼ãããã®ã¯å¤§ä¸å¤«ã®ããã§ãã
Level 1 ã®æåã®åé¡ã¯ã以ä¸ã®ããã«ãçããæ¸ããã¦ãã¦ãããããflagãã¨æ¸ããã¦ããããã¹ãããã¯ã¹ã«å
¥åãã¦ãSubmit ã§ãããããã¹ãããå
容ã¨ãªã£ã¦ãã¾ãã
Level 1ã®æåã®åé¡
çãã®å
¥åããã¯ã¹ã¨Submitãã¿ã³
æ£ããçããå
¥åãã¦ãSubmit ã§ããã¨ãé ä½ï¼Submitåºæ¥ãé ï¼ãä¸ã®æ¹ã«è¡¨ç¤ºããã¾ããQ1 ã«ã¤ãã¦ã¯ã20035çªç®ã®æ£ãã Submit ã ã£ãããã§ãã
Level 1ã®æåã®åé¡ã®çµæ
以ä¸ãçµæã ãã§ãããSubmit ã®é ä½ãæ¸ãã¦ããã¾ãã
åé¡ |
ã¿ã¤ãã« |
é ä½ |
Q1 |
[Misc] Test Problem |
20,035 |
Q6 |
[Crypto] Classical Cipher |
17,031 |
Q7 |
[Reversing] Can you execute ? |
11,390 |
Q8 |
[Misc] Can you open this file ? |
12,329 |
Q9 |
[Web] HTML Page |
13,922 |
Q10 |
[Forensics] River |
12,903 |
Q11 |
[Network]pcap |
11,964 |
Q12 |
[Crypto]HashHashHash! |
12,487 |
Q14 |
[PPC]並ã¹æ¿ãã! |
11,414 |
CpawCTFã®Level 2
Level 1 ã®åé¡ã«å
¨ã¦æ£è§£ãã㨠Level 2 ãåºç¾ãã¾ãã
CpawCTFã®Level 2
åæ§ã«ã以ä¸ãSubmit ã®é ä½ãæ¸ãã¦ããã¾ããQ18 ãã¯ãªã¢ããã¨ãã«ãLevel 3 ãåºç¾ãã¾ããã
åé¡ |
ã¿ã¤ãã« |
é ä½ |
Q13 |
[Stego]é ããããã©ã° |
7,657 |
Q15 |
[Web] Redirect |
8,018 |
Q16 |
[Network+Forensic]HTTP Traffic |
6,841 |
Q17 |
[Recon]Who am I ? |
7,518 |
Q18 |
[Forensic]leaf in forest |
6,933 |
Q19 |
[Misc]Image! |
5,773 |
Q20 |
[Crypto]Block Cipher |
5,624 |
Q21 |
[Reversing]reversing easy! |
4,995 |
Q22 |
[Web]Baby's SQLi - Stage 1- |
6,061 |
Q28 |
[Network] Can you loginï¼ |
4,763 |
CpawCTFã®Level 3
Level 2 ãåãçµãã§ãéä¸ã§ Level 3 ãåºç¾ãã¾ãããããLevel 3 ã®æåã®åé¡ãã¯ãªã¢ãã㨠Level 4 ãåºç¾ãã¾ããã
CpawCTFã®Level 3
åæ§ã«ã以ä¸ãSubmit ã®é ä½ãæ¸ãã¦ããã¾ãã
åé¡ |
ã¿ã¤ãã« |
é ä½ |
Q23 |
[Reversing]ã¾ããããããï¼ |
2,694 |
Q24 |
[Web]Baby's SQLi - Stage 2- |
4,409 |
Q26 |
[PPC]Remainder theorem |
3,461 |
Q29 |
[Crypto] Common World |
2,387 |
Level 4 ã¨ããã¿ã¤ãã«ã¯åºã¾ããããLevel 3 ãå
¨ã¦ã¯ãªã¢ãã¦ããåé¡ã¯åºã¾ããã§ãããç¾å¨ã¯ãLevel 3 ã¾ã§ã®ããã§ãã
ã©ã³ãã³ã°
ã©ã³ãã³ã°ã表示ãã¦ããã¨ããããã£ãã®ã§ãè²¼ã£ã¦ããã¾ãã1735ä½ã¨ãããã¨ã§ããã
CpawCTFã®ã©ã³ãã³ã°
CpawCTFããã£ã¦ã¿ãææ³
次ã¯ãCpawCTF2ï¼ãããããã§ãããã²ãã£ã¦ã¿ããã¨æãã¾ãã
ä»åãåãã¦ãCTF ã«ææ¦ããã®ã§ããããã® CpawCTF ã¯ãã¨ã¦ããªã¹ã¹ã¡ã§ãã¾ãã
ãããªãã«æéããããã¾ããããç§ã®å ´åã¯ãé常ã«å¾ããã®ãå¤ãã£ããã¨ããå°è±¡ã§ãã
ä¾ãã°ãWireshark ã¯ããããªãã«ãããã¾ã§ã使ã£ã¦ããã¤ããã§ãããããããªä½¿ãæ¹ããããã ãã¨æããã¨ããRSAã®ä»çµã¿ãã¡ããã¨ç解ã§ããããåãã¦ã®ãã¡ã¤ã«å½¢å¼ãããããã¨ãã¨ã¦ãè¯ãæ©ä¼ã«ãªãã¾ããã
å°ãæ®å¿µã ã£ãã®ã¯ãWeb ã«ãçããããããã¦ãé¢é£ãããã¨ãæ¤ç´¢ããã ãã§ã解ãæ¹ãåãããã¼ã¯ã¼ããç®ã«å
¥ã£ã¦ãã¾ããã¨ãããã¨ã§ããããã¨ãæå¾ã® RSA ã®åé¡ã¯ãã¡ãã£ã¨ã¢ã¤ã¢ã¤ããåé¡ã ã£ãã®ã§ãæ£ãã解説ãç¥ãããã¨ããã§ããã
以ä¸ãææ³ã§ããã
ãããã«
ä»åã¯ãCTF ã®å
¥éã¨ãã¦ãCpawCTF ã«ææ¦ãã¦ã¿ã¾ãããé常ã«æ¥½ããã£ãã§ãã
次åã¯ãã¨ãããããCpawCTF2 ãè¦ã¦ã¿ã¾ãã
ä»åã¯ãCpawCTF ã®ãã´ã使ããã¦ããã ãã¾ããããããã¨ããããã¾ãã
æå¾ã«ãªãã¾ããããã¨ã³ã¸ãã¢ã°ã«ã¼ãã®ã©ã³ãã³ã°ã«åå ä¸ã§ãã
æ°æ¥½ã«ãããã¨ãããããé¡ããããã¾ãð
ä»åã¯ä»¥ä¸ã§ãï¼
æå¾ã¾ã§ãèªã¿ããã ãããããã¨ããããã¾ããã