Trend Micro CTF Asia Pacific & Japan 2015ãªã³ã©ã¤ã³äºé¸ã«åå ãã¦ãã
Trend Micro CTF Asia Pacific & Japan 2015|トレンドマイクロã«åå ãã¦ãã¾ããã
ãã¤ãã®Route9ã¨ãããã¼ã ã§åå ããçµæã¯154ä½(å¾ç¹ãããã¼ã ç·æ°359ãã¼ã )ã§ããã
çãä¸ã¡ããä¸ããªãã¨ãã³ã¡ã³ããã«ããæããã¾ãããã°ããã¼ã
ã¦ãã¨ã§ãåå è¨é²ãããã¦è§£ããåé¡ã®writeupãæ¸ãã¦ããã¾ãã
Analysis - offensive100
ã¢ã¯ã»ã¹ããã¨sign_in, sign_upããã£ã¦ãsign_inããã¨ã¢ã¯ã»ã¹ä¸è¦§ã¿ãããªã®ã表示ããããµã¤ãã
cookieã«userãå
¥ã£ã¦ãã®ã§ãªããæªãããªã¼ã¨æãã¤ã¤ãæéçµéã§å¤ãå¤ãã£ããããã®ã§ç¡é¢ä¿ããªã¼ã¨ãæãã¤ã¤ãã ãã ãã¦ã¾ããã
ããã¨ã¡ã³ãã¼ããããªä¸è¨ã
ãã£ããè¦ã人ã§è©¦ãã¦ã¿ããã¨ã«ã
$ curl http://ctfquest.trendmicro.co.jp:8888/95f20bb7856574e91db4402435a87427/signin -X POST -d "username=1&password=1&fuel_csrf_token=272c193c32f2e4cc7be0b7153027d5147bcc6c34c2aa9a3582729c3da89658" -i HTTP/1.1 302 Found Date: Sat, 26 Sep 2015 10:50:01 GMT Set-Cookie: user=96d9d1268c579e6a6f707c274b09d830f80a6dfa; path=/
cookieã«userã®å¤ãçªã£è¾¼ãã§ã¢ã¯ã»ã¹ããã¨éµãåãã¾ããã
Analysis - Defensive100
å顿ã®ãªã³ã¯å
ãDLããã¨vonnã¨ããå®è¡ãã¡ã¤ã«ãåºã¦ãã¾ãã
ãã¼ã ã¡ã³ãã¼ã®æ°ã
ã»ã»ã»ã¨ã®ãã¨ã使°ã«ãã®è¨äºæ¸ãã¦ã¦æ°ã¥ãããã©ãçã®flagèãã¦NEEEEE orz
Analysis - Others100
å£ããPDFã対象ã®åé¡ã
ã´ã¥ã¼ã¯ã«ãã£ã¦ã¯å£ãã¦ã¦ãç¡è¦ãã¦éãã¦ããã¡ããã¾ãã(ãã¡ããçãã¯ããããªããã©)
PDFã®ãã©ã¼ããããªãã¦èª¿ã¹ããã¨ããªãããã§ããã°æ¥½ããããªã¼ã¨æããrubyã®origamiã¨ãããã¼ãµã使ã£ã¦ã¿ãã¨ã
2.1.5 :001 > require "origami" 2.1.5 :002 > puts Origami::PDF.read("fix_my_pdf.pdf").pages [info ] ...Reading header... [info ] ...Parsing revision 1... [error] Breaking on: "stream\nx\x01\xED..." at offset 0x1581 [error] Last exception: [Origami::InvalidObjectError] Cannot determine object (no:13,gen:0) type [info ] ...Parsing xref table... [info ] ...Parsing trailer... [info ] ...Propagating types... 0x1581ã¯ããã®streamã®ç®æ 13 0 obj stream ... endstream
ãªããobject no13ã®ã¨ãããå£ãã¦ãã¨æãã¦ãããã®ã§ãããè¦ã¦ã¿ããããããããã
ãã¶ãã¶PDFã®ãã©ã¼ããããããã£ãã¨ãããè¾æ¸å¥?ãæå®ããå¿
è¦ãããã¨ã®ãã¨ã
13 0 Rãåç
§ãã¦ããã¨ãããæ¤ç´¢ããã¨ä»¥ä¸ã®ãããªé¨åããããããã®ã§ãããããã¯ç»åã§æ±ºã¾ãã ããã¨åæã«æãè¾¼ã¿(100ç¹åé¡ã ã...)
10 0 obj << /ProcSet [ /PDF /ImageB /ImageC /ImageI ] /ExtGState << /Gs1 15 0 R >> /XObject << /Im1 11 0 R /Im2 13 0 R >> >> endobj
ä½ãæ¸ãã°ãããããããªãã®ã§ãåãããã«ç»åãæå®ããã¦ããç®æããè¾æ¸å¥ãã³ãããã¦ã¿ã¾ããã
13 0 obj << /Length 14 0 R /Type /XObject /Subtype /Image /Width 305 /Height 50 /ColorSpace 16 0 R /Intent /Perceptual /SMask 17 0 R /BitsPerComponent 8 /Filter /FlateDecode >> stream ...
ããã§ãã©ã¼ããããã§ãã¯ã¯éããã©pdfãéãã¦ãå£ããç»åãè¦ããã ããä½ãè¶³ããªãã®ãããããæ¶ã
ã¨ãã¦ãã¨ã»ã»ã»
é©å½ã«ç»åå¹
ãå¤ãã¦ããçããè¦ãããã ã£ã¦â(ï¿£ãï¿£ï¼â
ã¡ããã¨è§£æ±ºãã¦ãªããã©ãè§£ããããè¯ãã§å
ã«é²ã¿ã¾ããã¨ãã
Programming100
å¥ã®åé¡ã§æ¶ã ã¨ãã¦ãéã«ã¡ã³ãã¼ãè§£ãã¦ããã¦ã¾ãããå¤è¬ã
åçã½ã¼ã¹ã³ã¼ã
Programming200
å¥ã®åé¡ã§æ¶ã
ã¨ry
ãã®è¾ºãåèã«ããããã§ã Ruby - Hashクラス(ローマ数字を数値に変換) | Kamimura's blog
åçã½ã¼ã¹ã³ã¼ã