ã¯ããã«
ãã©ã¬ã³ã¸ãã¯ç¹ã«ãã£ã¹ã¯ã¤ã¡ã¼ã¸è§£æããã»ã»ã©è§£ããããªã£ã¦æ¢ããæ«ã«è¦ã¤ããsetodaNoteCTFã解ãããã¨æãã¾ãããwriteupã¨ããããã解ããéçãæ¸ãã¦ãã¾ãã®ã§ãæçè·é¢ãç¥ããã人ã«ã¨ã£ã¦ã¯æå³ããããªããã®ããããã¾ããããäºæ¿ãã ãããbegginerã®ãæ¯ãã¨æã£ã¦æããè¦å®ã£ã¦ããã ããã°å¹¸ãã§ãããã©ã¬ã³ã¸ãã¯ãã¡ã¤ã³ã«ãã£ã¦ããããã¨æã£ã¦ãã¾ããã¾ããç 究室ã®å人ãæµ·å¤ã®ctfãã¬ã¤ã¤ã¼ãgithubä¸ã§writeupãå ¬éãã¦ããã®ã§ããã¡ãããã£ã¦ã¿ããã¨ãæãã¾ãã®ã§ãgithubã«ãã£ã¬ã³ã¸ããããããã¾ããã
éé
- ã¯ããã«
- morse_one
- paint_flag
- Deletedfile
- Timeline
- browser_db
- MFT
- tkys_another_day
- MESSAGE
- CSIRT_asks_you_01
- unallocated_space
- CSIRT_asks_you_02
- Body
- Header
- puni_puni
- Mistake
morse_one
30 å人ãããç§å¯ã®ã¡ãã»ã¼ã¸ãéãããã¨ããããã¹ããã¡ã¤ã«ãéããã¦ãã¾ãããã©ããããã®ã¾ã¾ã§ã¯èªããªãããã§ããæ·»ä»ããããã¡ã¤ã«ã解æããç§å¯ã®ã¡ãã»ã¼ã¸ãè¦ã¤ãåºãã¦ãã ããã
ãã©ã°ã¯å¾ãããæååã flag{} ã§å²ãã§çãã¦ãã ããããã©ã°ã«è±åãå«ã¾ãã¦ããå ´åã¯ãã¹ã¦å¤§æåã§çãã¦ãã ãããä¾ãã°å¾ãããæååã Flag ã®å ´å㯠flag{FLAG} ã¨ãªãã¾ãã
ã¨ãããã¨ã§ãä½ãããã®zipãã¡ã¤ã«ã渡ãããã解åãã¦åºã¦ãããã¡ã¤ã«ã解æãã¦ããã
ââ# file morse_one.txt morse_one.txt: ASCII text, with no line terminators
ââ# strings morse_one.txt DDDBSDDSBDDDSDBDSBBBSDBBDSDBDDSDSBDDB
ã¨ããæãããªããªãã«æå³ä¸æãmorseãã¢ã¼ã«ã¹ã®ããã ãã¢ã¼ã«ã¹ä¿¡å·ã«é¢ä¿ãã¦ããã®ããªï¼(ã¢ã¼ã«ã¹ç¬¦å·)ãåèã«ããã4æã®çµã¿åããã§ã¡ãã»ã¼ã¸ãä¼ãããã®ãªã®ããªãã§ãã37é³ãéããã¦ããã®ã¯ã²ã£ããããã§ããã»ãã¼ãããã®ä¸ã¤ã表ãã¦ããã¨èãããããããããªãã®ã§ã¾ãä»åº¦ã
paint_flag
50 è¦èª¿æ»å¯¾è±¡è ã®ç«¯æ«ãããããã¡ã¤ã«ãæ¼åãããã¨ã«æåãã¾ãããã©ãããå¤é¨ã®ååè ã«æ©å¯ãã¼ã¿ãéããã¨ããããã§ããçµç¹å ã®ç£è¦ç¶²ãããããããããä¸è¦ããã¨æ©å¯ãã¼ã¿ãå«ã¾ãã¦ããªãã®ããã«å å·¥ãããã¦ããããã§ãããã¡ã¤ã«ã解æãã¦æ©å¯ãã¼ã¿ãåå¾ãã¦ãã ããã
æ·»ä»ããããã¡ã¤ã«ã解æãããã©ã°ãå
¥æãã¦ãã ããã
unzipããã¨wordãã¡ã¤ã«ã渡ãããã
ââ# file paint_flag.docx
paint_flag.docx: Microsoft Word 2007+
æ¡å¼µåã¨å®éã®å½¢å¼ã«éãã¯ãªããå®è¡ãã¦éãã®ã¯æãã®ã§ãã©ã解æãã¦ããã¾ãããããunzipãã¦ã¿ã¾ããããã
ââ# unzip paint_flag.docx Archive: paint_flag.docx inflating: docProps/app.xml inflating: docProps/core.xml inflating: word/document.xml inflating: word/fontTable.xml inflating: word/media/flag.png inflating: word/media/image1.png inflating: word/settings.xml inflating: word/styles.xml inflating: word/theme/theme1.xml inflating: word/webSettings.xml inflating: word/_rels/document.xml.rels inflating: [Content_Types].xml inflating: _rels/.rels
flag.pngã¨ãããã®ããããæªãããè¦ããçããããçµäºãéã®ãã¯ããããããåé¡ã§ããã
50 ããªãã¯ã¡ã¼ã«ãã¼ã¿ã®èª¿æ»ãä¾é ¼ããã¾ãããçµç¹å ã®è¦å¡ãè¦å®ã«åãã¦çµç¹å ã®ãã¼ã¿ãå人å©ç¨ã®ã¯ã©ã¦ããµã¼ãã¹ã«ããã¯ã¢ããã¨ãã¦ã³ãã¼ãã¦ãããã®ã®ããã§ããã¡ã¼ã«ãã¼ã¿ã«æ©å¯æ å ±ãå«ã¾ãã¦ããªããã調æ»ãã¦ãã ããã
æ·»ä»ããããã¡ã¤ã«ã解æãããã©ã°ãå¾ã¦ãã ããã
ã¨ãããã¨ã§ã¾ãã¯unzipã
ââ# unzip mail_0805f895cca0c713b0fa499b1671d4948bae4172.zip Archive: mail_0805f895cca0c713b0fa499b1671d4948bae4172.zip creating: ImapMail/ creating: ImapMail/mail.setodanote.net/ inflating: ImapMail/mail.setodanote.net.msf inflating: ImapMail/mail.setodanote.net/Archives.msf inflating: ImapMail/mail.setodanote.net/Drafts.msf inflating: ImapMail/mail.setodanote.net/filterlog.html inflating: ImapMail/mail.setodanote.net/INBOX inflating: ImapMail/mail.setodanote.net/INBOX.msf inflating: ImapMail/mail.setodanote.net/Junk.msf extracting: ImapMail/mail.setodanote.net/msgFilterRules.dat inflating: ImapMail/mail.setodanote.net/Sent-1 inflating: ImapMail/mail.setodanote.net/Sent-1.msf inflating: ImapMail/mail.setodanote.net/Sent.msf inflating: ImapMail/mail.setodanote.net/Templates.msf inflating: ImapMail/mail.setodanote.net/Trash.msf
ImapMailã¨ãããã®ã渡ãããã
ç¥è(ImapMail)
ImapMail
(IMAP 㨠POP ã¨ã¯ä½ã§ããã)ãåèã«ããããIMAP ã使ç¨ããã¨ãä»»æã®ããã¤ã¹ãããã©ãã«ãã¦ãã¡ã¼ã«ã«ã¢ã¯ã»ã¹ã§ãã¾ãããã¨ãããã¨ã®ããã ãã¾ãã.msfãã¡ã¤ã«ãç®ç«ã¤ãããã¯ä½ã ã
ç¥è(msfãã¡ã¤ã«)
msfãã¡ã¤ã«
(æ¡å¼µåã.msfãã®ãã¡ã¤ã«ã¨ã¯ï¼éãæ¹æ³ããç´¹ä»ï¼)ãè¦ãããMozilla Thunderbirdã®ã¤ã³ããã¯ã¹ãã¡ã¤ã«ãã ããã§ããã¤ã³ããã¯ã¹ã«ãã¼ããæ
å ±ããªããããªã®ã§ããã®ã»ãã®ãã¡ã¤ã«ãè¦ã¦ãããââ# cat Sent-1
ããããã¢ã«ãªã¨ã¹ãã©ã®ããåããè¼ã£ã¦ããã
Content-Type: application/x-zip-compressed; name="kimitsu.zip" Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="kimitsu.zip"
ãã®ä¸ã§kimitsu.zipã¨ãããã®ãæ·»ä»ãã¦ãã模æ§ã
ãã®è¨è¿°ã®ã®ã¡ã«ä»¥ä¸ã®ãããªæååããå§ã¾ãè¶
絶é·ãæååãããã
UEsDBBQAAAAIAEKk8lIYGu97DhgHAG8YBwALAAAAZ29vZGpvYi5wbmdUumN3JUy0Rrtj27Zt
ãããcyberchefã«æããã¨
base64ã¨ã³ã³ã¼ãããã¦ããããPKã¨ãããã¸ãã¯ãã°ãã°ã¼ãè¦ãããã¤ã¾ããzipã®å
容ãããã«æ¸ããã¦ããããã ããããæ½åºããªãã¨ãããªãã®ããªï¼å³ãããããããããªããSent-1ãç·¨éãã¦ãbase64ã¨ã³ã³ã¼ãããã¦ãé¨åã ãã®ãã¡ã¤ã«ãä½ããââ# strings Sent-1.txt | tr -d '\n' | base64 -d > kimitsu.zip
ã¨ããã¨
ââ# file kimitsu.zip kimitsu.zip: Zip archive data, at least v2.0 to extract, compression method=deflat
ãã£ãããzipãã¡ã¤ã«ãå®æããããã¨ã¯ãããunzipããã¨
ââ# unzip kimitsu.zip Archive: kimitsu.zip inflating: goodjob.png
æªããpngãã¡ã¤ã«ãæã«å ¥ãã®ã§ããããè¦ãã°flagã²ãããçµäºã
Deletedfile
80 ãã®ãã¡ã¤ã«ãåé¤ããå¹é£ãããªãã¯ããã誤ãã ã£ãã¨æãã¾ããã©ãããéè¦ãªãã¡ã¤ã«ãåé¤ããã¦ãã¾ã£ãããã§ããããªãã¯ãã£ã¹ã¯ã®ã¤ã¡ã¼ã¸ãã¡ã¤ã«ã®å ¥æã«æåãã¾ãããåé¤ããã¦ãã¾ã£ããã¡ã¤ã«ã復å ãã窮å°ãè±ãã¦ãã ããã
æ·»ä»ããããã¡ã¤ã«ã解æãããã©ã°ãå¾ã¦ãã ããã
念é¡ã®ãã£ã¹ã¯ã¤ã¡ã¼ã¸ãããã ããã解æ解æã
ââ# file deletedfile.raw deletedfile.raw: DOS/MBR boot sector MS-MBR Windows 7 english at offset 0x163 "Invalid partition table" at offset 0x17b "Error loading operating system" at offset 0x19a "Missing operating system"; partition 1 : ID=0xee, start-CHS (0x0,0,2), end-CHS (0x0,254,63), startsector 1, 4294967295 sectors
windows7ã®ãã¼ã¿ã®ããã ã
ââ# mmls deletedfile.raw GUID Partition Table (EFI) Offset Sector: 0 Units are in 512-byte sectors Slot Start End Length Description 000: Meta 0000000000 0000000000 0000000001 Safety Table 001: ------- 0000000000 0000000127 0000000128 Unallocated 002: Meta 0000000001 0000000001 0000000001 GPT Header 003: Meta 0000000002 0000000033 0000000032 Partition Table 004: 000 0000000128 0000016511 0000016384 Basic data partition 005: ------- 0000016512 0000020479 0000003968 Unallocated
ââ# fsstat deletedfile.raw -o 128 FILE SYSTEM INFORMATION -------------------------------------------- File System Type: FAT12
FAT12ãã¡ã¤ã«ã·ã¹ãã ã使ã£ã¦ããããã ã調ã¹ããããããå¦ã¹ããã ããsutopsyã«ã¶ã¡è¾¼ãã ãã復å ããã¦ããåé¤ãããã¡ã¤ã«ãè¦ã¤ãã£ãã®ã§ãçµäºã
Timeline
100 åã¯ã¿ã¤ã ã©ã¤ã³æ©è½ãç¥ã£ã¦ããããããã³ãã«è °ãããè紳士ããã¡ãã«åãã£ã¦è©±ãããã¦ãã¾ãããã¾ã使ããã¦ã¯ããªãããã ãããè紳士ã¯ãã話ãç¶ããªããæ£é¢ã«åãç´ãããæ¯ãã¤ãã¾ããã ããå®å ¨ã«æ¶ãã¦ãã¾ãåã«ã©ããªã¢ã¼ãã£ãã¡ã¯ãã§ãã£ãã確ããã¦ã¿ã¦ãããã¨ã¯æããããããããã£ã¦è紳士ã¯1æã®ãã£ã¹ã¯ãããªãã«æ渡ãã¨ãéãã«å»ã£ã¦ããã¾ãããã©ããããã£ã¹ã¯ã解æããå¿ è¦ãããããã§ãã
æ·»ä»ã®ãã¡ã¤ã«ã解æãããã©ã°ãå ¥æãã¦ãã ããã
ââ# unzip timeline_12296f199f1eb1c6d327a469af6b8e4fd8b83374.zip Archive: timeline_12296f199f1eb1c6d327a469af6b8e4fd8b83374.zip creating: C/ creating: C/Users/ creating: C/Users/stella/ creating: C/Users/stella/AppData/ creating: C/Users/stella/AppData/Local/ creating: C/Users/stella/AppData/Local/ConnectedDevicesPlatform/ creating: C/Users/stella/AppData/Local/ConnectedDevicesPlatform/L.stella/ inflating: C/Users/stella/AppData/Local/ConnectedDevicesPlatform/L.stella/ActivitiesCache.db inflating: C/Users/stella/AppData/Local/ConnectedDevicesPlatform/L.stella/ActivitiesCache.db-shm inflating: C/Users/stella/AppData/Local/ConnectedDevicesPlatform/L.stella/ActivitiesCache.db-wal
ã¨ãããã¨ã§ãCãã©ã¤ãã®ä¸ãããã£ããããªæããä¸çªä¸ã®é層ã«ããActivitiesCache.dbã«ã¤ãã¦ã®è¨äºããã£ãã
ç¥è(ã¿ã¤ã ã©ã¤ã³(ActivitiesCache.db))
ã¿ã¤ã ã©ã¤ã³(ActivitiesCache.db)
(Windowsã¿ã¤ã ã©ã¤ã³(ActivitiesCache.dbï¼ã®è§£ææ¹æ³)ãåèã«ãããActivitiesCache.dbã解æãããã¨ã§ãã端æ«ä¸ã§ã©ããªæä½ãè¡ããããããç¥ããã¨ãã§ããããã ãä½ãããã®ãã¼ã«ã§è§£æããæ¹ãè¯ããããªãã¨ãæ¸ããã¦ãããä¸å¿ãActivitiesCache.dbã¯SQLiteDBãªã®ã§ãããã解æãããã¼ã«ã§ãã§ããããªæ°ã¯ããããWindowsTimeline parserã使ã£ã¦ã¿ãã
èªã¿è¾¼ãã ãããè¦ã¦ããã¨}.txt
ã¨ãããã®ãã¡ã¢å¸³ã§ä½ããã¦ãããflagã®ã«ãããä¸ã«è¦ã¦ããã¨flagãåå²ãã¦ãã¡ã¤ã«åã«ãã¦ããããã ãCUIã§ã¾ã¨ãã¦ã¿ããWxTCmdã使ã£ã¦ãcsvã«ããã ããªã®ã§ããããªãWindowsTimeline parserã§è¦ãæ¹ãèªèº«ã¯å¥½ããããCUIãªãdbãã¡ã¤ã«ããã®ã¾ã¾strings
ããã°ããæ°ããããæéå¤åãæ°ã«ãããªãWxTCmdãããã®ãããããªããCUIã§ããæãã«æ½åºãããã¨ãããã§ããªã®ã§ææã¡ãã¦flagã²ããã
browser_db
100 調æ»å¯¾è±¡è ã®ãã½ã³ã³ãã Web ãã©ã¦ã¶ã®æ å ±ãåå¾ãã¾ããããã¡ã¤ã«ã解æãã¦èª¿æ»å¯¾è±¡è ãæªããè¡åããã¦ããªãã調æ»ããã®ãä»åã®ããªãã®ä»äºã§ãã
æ·»ä»ããããã¡ã¤ã«ã解æãããã©ã°ãå¾ã¦ãã ããã
stella_9s84jetw.default-release_places.sqliteã¨ãããã¡ã¤ã«ãä¸ããããã
ââ# file stella_9s84jetw.default-release_places.sqlite stella_9s84jetw.default-release_places.sqlite: SQLite 3.x database, user version 54, last written using SQLite version 3035004, page size 32768, writer version 2, read version 2, file counter 2, database pages 37, cookie 0x1f, schema 4, UTF-8, version-valid-for 2
SQLite 3.x databaseããããstrings stella_9s84jetw.default-release_places.sqlite | grep flag
ã§åºã¦ããflagãå
¥åãããæ£è§£ã ã£ããæ¬æ¥ã®è§£ãæ¹ã¯writeupãè¦ãã¨ãããã
MFT
100 å é¨åçºã«ããããè¦å¡ã極ç§æ å ±ããã¡ã¤ã«ãµã¼ããããã¦ã³ãã¼ããã¦ãããã¨ãå¤æãã¾ãããçµç¹ã¯è¦å¡ã®èº«æãæãã端æ«ãã証æ ã¨ãªããã¼ã¿ãæ½åºãã¾ãããä»åã®ããªãã®ä»äºã¯ã端æ«ããæ½åºãããã¼ã¿ã解æãããã¦ã³ãã¼ãããã極ç§æ å ±ã®ãã¡ã¤ã«åãç¹å®ãããã¨ã§ããçµç¹ããã¯æ¥µç§æ å ±ã®ãã¦ã³ãã¼ããããæ¥æã 2021-07-18 18:30é ã§ãããã¨ã¨ããã¡ã¤ã«ãµã¤ãºã 465030 ã§ãããã¨ã®ã¿ãä¼ãããã¦ãã¾ãã
æ·»ä»ãã¡ã¤ã«ã解æãã極ç§æ
å ±ã®ãã¡ã¤ã«åãç¹å®ãã¦ãã ãããä¾ãã°ãã¡ã¤ã«åã file.txt ã®å ´å㯠flag{file.txt} ã¨åçãã¦ãã ããã
ã¨ãããã¨ã§$MFTã渡ããããããã§MFTã«ã¤ãã¦ããããã(ãã¹ã¿ã¼ãã¡ã¤ã«ãã¼ãã«ã¨ã¯ãç¨èªé詳細ã)ãã
ãã¹ã¿ã¼ãã¡ã¤ã«ãã¼ãã«ï¼Master File TableãMFTï¼ã¯ãWindowsãæ¡ç¨ãã¦ããNTFSï¼NT File Systemï¼ã«ããã¦ãã·ã¹ãã å ã«åå¨ãããã¹ã¦ã®ãã¡ã¤ã«ã«é¢ããå ´æãç©çä¸ã®ä½ç½®ãã¡ã¿ãã¼ã¿ï¼ä½ææ¥ãæ´æ°æ¥ãã¢ã¯ã»ã¹æ¥ãªã©ï¼ãä¿åããã¬ã³ã¼ããã¡ã¤ã«ã§ãã
ãã¡ã¤ã«ãã¼ã¿ãå
¥ã£ã¦ããããã ãMFTExplorerã§è¦ã¦ãããããä»åã¯ãã¡ã¤ã«ãµã¤ãºãæ¥æãä¸ãããã¦ããã®ã§ã¿ã¤ã ã©ã¤ã³è§£æããæ¹ãããã¨èãããä»å°CTFã®è§£èª¬ããã¨ã«MFTECmd.exeã¨mactimeãç¨ãã¦è§£æããã(ä»å°CTF2018 ã»ãã¥ãªãã£æè¡ç«¶æä¼ï¼CTFï¼)ãã¾ãã¯timeline Exporerã§ãã£ã¨è¦ãããã¡ã¤ã«ãµã¤ãºã§æ¤ç´¢ããæ¹ãéãããªã®ã§ãã¡ã¤ã«ãµã¤ãºã§æ¤ç´¢ã
ããããã¨ããã£ã½ããã¡ã¤ã«ãè¦ã¤ãã£ããçµäºã
tkys_another_day
100 ç¡äºã§ãã¦ããã¦ããã ããããããªãã¯å¾è¼©ã®ç«¯æ«ã«æ®ããã¦ããããç»åãã¡ã¤ã«ãæ°ã«ãªã£ã¦ãã¾ããä½æãããæ¥ä»ã¯é³ä¿¡ä¸éã¨ãªãåæ¥ããã¡ã¤ã«ã¯ä½ããããªã®ããæççãªæ å ±ãã表示ããã¾ããããããããã¨å¾è¼©ã®æ¶æ¯ã«ã¤ãã¦ã®éè¦ãªæããããé ããã¦ããã®ã§ã¯ãªãããããªãã¯ãã¡ã¤ã«ã詳ãã解æãããã¨ã«ãã¾ããã
æ·»ä»ããããã¡ã¤ã«ã解æãããã©ã°ãå
¥æãã¦ãã ããã
pngãã¼ã¿ã渡ãããã
æåãè±è½ãã¦ããã復å
ãããã®ãç®æ¨ãªã®ããªï¼
ââ# file tkys_another_day.png tkys_another_day.png: PNG image data, 640 x 480, 8-bit/color RGBA, non-interlaced
ââ# binwalk tkys_another_day.png DECIMAL HEXADECIMAL DESCRIPTION -------------------------------------------------------------------------------- 0 0x0 PNG image, 640 x 480, 8-bit/color RGBA, non-interlaced 99 0x63 Zlib compressed data, best compression 5808 0x16B0 Zlib compressed data, best compression 10651 0x299B Zlib compressed data, best compression 10718 0x29DE Zlib compressed data, best compression 12661 0x3175 Zlib compressed data, best compression
strings
ã³ãã³ããã¦ãããã¾ã§ãã³ãã¯ãªãã£ããzlibããããªã«å
¥ã£ã¦ããã®ãã¨æãããpngã«zlibã¯ããã¾ã§ããããã¯ãªãã(aperisolve.com)ã«å
¥ãã¦ã¿ããAPNG Assembler 2.91ã¨ããã®ãæ°ã«ãªã£ããstringsãã¦ãè¦ãã¦ããã
ç¥è(APNG)
APNG
(GIFã¢ãã¡ããAPNGã®æ代ã«ï¼æ¬¡ä¸ä»£ç»åå½¢å¼APNGã使ãããªãã)ãåèã«ããããAPNGï¼ã¨ã¼ãã³ã°ï¼ã¨ã¯ã¢ãã¡ã¼ã·ã§ã³ããPNGç»åã®ãã¨ã§ãã¢ãã¡ã¼ã·ã§ã³GIFã«åã£ã¦ä»£ãã次ä¸ä»£ã®æ°ããç»åå½¢å¼ã§ãããã¨ãããã¨ã§åç»ã¿ãããªãã®ããããã ããzlibãè¤æ°ãã£ãã®ã ãããï¼ââ# exiftool tkys_another_day.png ExifTool Version Number : 12.65 File Name : tkys_another_day.png Directory : . File Size : 13 kB File Modification Date/Time : 2021:07:25 16:47:40+00:00 File Access Date/Time : 2024:03:31 06:40:05+00:00 File Inode Change Date/Time : 2024:03:31 06:35:43+00:00 File Permissions : -rw-r--r-- File Type : APNG File Type Extension : png MIME Type : image/apng Image Width : 640 Image Height : 480 Bit Depth : 8 Color Type : RGB with Alpha Compression : Deflate/Inflate Filter : Adaptive Interlace : Noninterlaced Animation Frames : 5 Animation Plays : inf Warning : [minor] Text/EXIF chunk(s) found after APNG IDAT (may be ignored by some readers) Software : APNG Assembler 2.91 Image Size : 640x480 Megapixels : 0.307
ã¢ãã¡ã¼ã·ã§ã³ãã¬ã¼ã ã5ããã®ã¯5æå ¥ã£ã¦ããã¨ãããã¨ããªï¼èª¿ã¹ã¦ã¿ãã¨disã¢ã»ã³ãã©ãããããã ããã¦ã¿ãã¨5æåºã¦ããã2,4ã«flagã®æçãããå ¥åãããçµäºãexiftool ã観ã¦ã¿ãã®ã¯ãããããããªãã
MESSAGE
120 ä»äºãçµãã¦å¸°å® ã®éã«ã¤ãããªãã人éãã®å°ãªãä½å® è¡ãéãéããèªå® ã®ãã³ã·ã§ã³ã«ãã©ãçãã¾ããã¡ããã©é¨å±ã®ãã¢ã®åã«ç«ã£ãæã«æã«æã£ã¦ããæºå¸¯ãé³´ãã¡ã¼ã«ãåä¿¡ãããã¨ãä¼ãã¾ãã
件åï¼ãããæå¾ã®è¦åã
ãã®ã¡ã¼ã«ã«ã¯ç»åãæ·»ä»ããã¦ãã¾ããã ã
æ·»ä»ããããã¡ã¤ã«ã解æãããã©ã°ãå¾ã¦ãã ããã
ââ# file lo3rs1tkd.jpg lo3rs1tkd.jpg: JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1280x959, components 3
JPGãã¡ã¤ã«ã渡ãããã
aperisolve.comã«ã¶ã¡è¾¼ããããã¾ããããã®ãè¦ã¤ãããªããç»å解æã¯è¦æããã
CSIRT_asks_you_01
150 çµç¹å ã®ã¤ã³ã·ãã³ã対å¿é¨ç½²ããæ¥ã解æãã¦ã»ããã¨ã®ä¾é ¼ãèãè¾¼ã¿ã¾ãããä¸æ£ä¾µå ¥ã確èªããã端æ«ã® Windows ã¤ãã³ããã°ã®èª¿æ»ã§ãç¶æ³ææ¡ã®ããã«ä¾µå®³ã«é¢ãã詳細ãªæ¥æã確èªãã¦ã»ããã¨ãããã¨ã®ããã§ãã
ä»åã®ããªãã®ä»äºã¯éããã¦ãããã¡ã¤ã«ã解æããä¸æ£ãªæ¹æ³ã«ãã£ã¦ãããã¯ã¼ã¯çµç±ã®ãã°ã¤ã³ãæåãããã¨ã示ãã¦ããæåã®è¨é²æ¥æï¼TimeCreated SystemTimeï¼ ã¨ Event ID ãç¹å®ãããã¨ã§ãã
ãã©ã°ã¯ UTC ã§ã®è¨é²æ¥æ ã yyyy/mm/dd_hh:mm:ss å½¢å¼ã«ããæå¾ã« Event ID ãã¢ã³ãã¼ã¹ã³ã¢ã§ã¤ãªããå½¢ã§çãã¦ãã ãããä¾ãã° è¨é²æ¥æ ã 2020/01/10 7:05:13.9234567Z ãEvent ID ã 1234 ã®å ´å㯠flag{2020/01/10_07:05:13_1234} ã¨ãªãã¾ããè¨é²æ¥æ㯠UTC+0 ã§åçãããã¨ã«æ³¨æãã¦ãã ããã
ã¨ãããã¨ã§ãSecurity.evtxã渡ããããhayabusaãç¨ãã¦è§£æãã¦ããã(Windowsã¤ãã³ããã°è§£æãã¼ã«ãHayabusaãã使ã£ã¦ã¿ã)ãè¦ãªããCSVãã¡ã¤ã«ã«ãããä¸æ£ãªãã°ã¤ã³ãæåãããã¨ã示ããã®ãæ¢ãã«è¡ããã¤ãã³ãIDããæ¢ãã®ãããããã4624ã®ãã°ã¤ã³æåã4625ã®ãã°ã¤ã³å¤±æããã¨ã«æ¢ãã¦ããã4625ã®ãã°ã¤ã³å¤±æã¯2åã»ã©å¤§éã«ãã°ã¨ãã¦æ®ã£ã¦ãããããã¯ä¸æ£ã¢ã¯ã»ã¹ãè¡ããã証æ ãªã®ã ãããï¼
大éã®4625ã®ä¸ã«4624ãè¨é²ãããã®ãä¸ãæã ããããããã«ãã£ã¦ç·å½ããæ»æã®ãããªãã®ãæåãããã¨ãåããããããflagã ã¨æããè¦ã¦ããtimeã¹ã¿ã³ãã¯UTC+9ã§ãããã¨ã«æ³¨æãããã¨ãçµäºã
unallocated_space
150 ããããä»å¤ã¯å¸°ãããã«ãªããªãååãããè¨ããªãããã¼ããã£ã¹ã¯ãUSBã¡ã¢ãªã大éã«è©°ã¾ã£ãç®±ãã©ãã£ã¨ãã¹ã¯ã«ç½®ãã¾ãããã¹ã¦ããçµç¹ã§ä½¿ç¨ããã¦ãããã®ã§æ¬æ¥ã¯ç ´å£å¦çãããã¯ãããä¸æ£ã«å©çãå¾ããã¨ãã人ç©ã仲ä»ãããã¨ã«ãããç ´å£å¦çãããã«ä¸å¤å¸å ´ã«åºåã£ã¦ãã¾ã£ããã®ã®ããã§ããä»æ¥ãè¨å¿µæ¥ã ã¨ããååãæ©ã帰ããããããªãã¯ãã£ã¹ã¯ã®è§£æ調æ»ãæä¼ããã¨ã«ãã¾ããã復å å¯è½ãªãã¼ã¿ããªãã確èªãã¦ãã ããã
æ·»ä»ããããã¡ã¤ã«ã解æãããã©ã°ãå ¥æãã¦ãã ããã
ââ# file unallocated_space unallocated_space: DOS/MBR boot sector MS-MBR Windows 7 english at offset 0x163 "Invalid partition table" at offset 0x17b "Error loading operating system" at offset 0x19a "Missing operating system", disk signature 0x23303fcc
渡ãããã®ã¯ä½ãã®ãã£ã¹ã¯ã¤ã¡ã¼ã¸ã®ããã ãmmlsã¯åå¿ãªããautopsyã«ä»£å ¥ãã¦ã¿ããé£ããããå°ãå¾åãã
CSIRT_asks_you_02
200 çµç¹å ã®ã¤ã³ã·ãã³ã対å¿é¨ç½²ããå¼ãç¶ãæ¥ã解æãã¦ã»ããã¨ã®ä¾é ¼ãåãã¦ãã¾ãã
ä¸ã¤ç®ã®è§£æä¾é ¼ï¼CSIRT_asks_you_01ï¼ã®çµæã¨å¥ã®è¨¼æ ãªã©ãããããã¢ã«ã¦ã³ãã®ãã¹ã¯ã¼ããèå¼±ã§ããå¯è½æ§ã示åããã¦ãã¾ããæ·»ä»ããããã¡ã¤ã«ã解æãããã®ãã¹ã¯ã¼ããç¹å®ãã¦ãã ããã
ãã©ã°ã¯ã¢ã«ã¦ã³ãåã¨ãã¹ã¯ã¼ãï¼å¹³æï¼ãã¢ã³ãã¼ã¹ã³ã¢ã§ã¤ãªãã§åçãã¦ãã ãããä¾ãã°ã¢ã«ã¦ã³ãåã user ããã¹ã¯ã¼ãã pass ã®å ´å㯠flag{user_pass} ã¨åçãã¾ãã
ã¨ãããã¨ã§ãsamã¨securityãsystemã®ãã¡ã¤ã«ã渡ãããã
ââ# file SAM.LOG1
SAM.LOG1: MS Windows registry file, NT/2000 or above
LOGã¨ããæ¡å¼µåã¯ã¬ã¸ã¹ããªæ
å ±ã®ããã ã
ãã¾ããã¿ããã«æ¢ãã¦ãæéããããã®ã§ã(ã¤ã³ã·ãã³ã対å¿ã¸ã®ãã©ã¬ã³ã¸ã㯠ææ³ã®çµ±åã«é¢ããã¬ã¤ã)ãåèã«ãã¹ã¯ã¼ããæ¢ãã¦ããã
ã¾ãSAMã«ã¤ãã¦
ãã¹ã¯ã¼ããã»ã¨ãã©ã® OS ã¯ãã¦ã¼ã¶ã®ãã¹ã¯ã¼ãã«å¯¾å¿ãããã¹ã¯ã¼ãããã·ã¥ããã£ã¹ã¯ä¸ã«ä¿æãã¦ãããWindows ã·ã¹ãã ã§ã¯ããµã¼ããã¼ãã£è£½ã®ã¦ã¼ãã£ãªãã£ã使ã£ã¦SAMï¼Security Account Managerï¼ãã¼ã¿ãã¼ã¹ãããã¹ã¯ã¼ãããã·ã¥ããã³ãã§ãããUNIX ã·ã¹ãã ã§ã¯ãé常ã/etc/passwd ãã¡ã¤ã«ã¾ãã¯/etc/shadow ãã¡ã¤ã«ã«ãã¹ã¯ã¼ãããã·ã¥ãæ ¼ç´ããã¦ããã4.3.2 é ã§èª¬æããããã«ããã¹ã¯ã¼ãã¯ã©ããã³ã°ããã°ã©ã ã使ã£ã¦ãã¹ã¯ã¼ãããã·ã¥ãããã¹ã¯ã¼ããæ½åºã§ããã
ã¨æ¸ãã¦ãã£ããããããããããã·ã¥ãããã¹ã¯ã¼ãã復å ããã®ããªï¼(Windows ã®ã¦ã¼ã¶ã¼åããã¹ã¯ã¼ãã復å : hashcat, impacket)ããã®ãããªå¾©å ã®ãµã¤ããããã
Body
30 ä½æä¸ã®ãµã¤ãã«æ©å¯æ å ±ãå«ã¾ãã¦ãã¾ã£ã¦ããããã§ãããµã¤ãã«ã¢ã¯ã»ã¹ãã¦æ©å¯æ å ±ãè¦ã¤ãåºãã¦ãã ããã
以ä¸ã®ãµã¤ãã«ã¢ã¯ã»ã¹ãã¦é ããããã©ã°ãè¦ã¤ãã¦ãã ããã
https://ctfweb.setodanote.net/web001/
ã¨ãããã¨ã§ããµã¤ãã«é£ã¶ããã®æãããããã¨bodyã®é¨åã«flagããããããã¨ããããã§ãéçºè
ãã¼ã«ã使ã£ã¦æ¢ããweb01ã®ä¸ã®flag{flag}ã¨ããã¨ããã«ãããçµäºã
Header
50 ä½æä¸ã®ãµã¤ãã管çãã¦ãããµã¼ãã«åé¡ããããæ©å¯æ å ±ãæ¼æ´©ãã¦ããããã§ãããµã¤ãã«ã¢ã¯ã»ã¹ãã¦æ©å¯æ å ±ãç¹å®ãã¦ãã ããã
以ä¸ã®ãµã¤ãã«ã¢ã¯ã»ã¹ãã¦é ããããã©ã°ãè¦ã¤ãã¦ãã ããã
https://ctfweb.setodanote.net/web002/
ããããããéçºè
ãã¼ã«ã§ãããã¼é¨åã確èªãããè¦ã¤ãããçµäºã
puni_puni
80 è¿æã®åä¾ãããã·ã«ã·ã«ãã¼ã©ãããããã¨1æã®ç´ãæ渡ããã¾ãããè¦ãã¨åä¾ã®åã¨ã¯æããªãæ£ç¢ºãªæ¸ä½ã§è±æ°åãã³ã£ããã¨æ¸ãè¾¼ã¾ãã¦ãã¾ããããã¯ãã£ãããããèããã¨ãã¾ããããç´ã«æèãåãããä¸ç¬ã®ãã¡ã«ãã®åä¾ã¯ããªããªã£ã¦ãã¾ããã
ç´ã«æ¸ãããæååã解æãããã©ã°ãå ¥æãã¦ãã ããããã©ã°ã¯å¾ãããæååã flag{} ã§å²ãã§çãã¦ãã ãããä¾ãã° flag ãå¾ãããå ´å㯠flag{flag} ã¨å ¥åãã¾ãã
xn--q6jaaaaaa08db0x8nc9t1b8fsviei84atb4i0lc
xn--q6jaaaaa03dpd4mb3jc5rpa0g9jpk07acadc.
xn--q6jylla3va3j6c8138a8eptvb303cxv4ft3o4ue63a
xn--v8ja6aj2a3cri3ag4a2r6cx2a1rkk1272c7j4ajd4bmf0kjhg6rb.
xn--q6j6gav1a0b2e1bh1ac2cl29ad7728kdjen6cz80dju6bqexchl9gel8b.
å
¨ãããããªãã調ã¹ã¦ã¿ãã
punycodeã¨ãããã®ãåºã¦ãããããã£ã½ããã
ç¥è(punycode)
punycode
(æ¥æ¬èªãã¡ã¤ã³/Punycodeã¨ã¯ï¼)ãåèã«ããããæ¥æ¬èªãã¡ã¤ã³ï¼å½éåãã¡ã¤ã³ï¼ãè±èªè¡¨è¨ã«å¤æããã³ã¼ãããPunycodeãã¨è¨ãã¾ãããããããã¤ã¾ããURLã«æ¥æ¬èªå ¥åãã§ããããã«ãªãæã«è±èªã¸ã®å¤æãè¡ãã³ã¼ãã®ããã ã(æ¥æ¬èªJPãã¡ã¤ã³åã®Punycodeå¤æã»éå¤æ)ã«xn--ã§å§ã¾ããã®ãå ¥ãã¦ã復å·ãã¦ããã°çµäºã
Mistake
100 ä½æä¸ã®ãµã¤ãã«ä¸åãããã¨å¤é¨ããææãåãã¦ãã¾ããã©ãããæ©å¯æ å ±ãæ¼ãã¦ãã¾ã£ã¦ããããã§ãããµã¤ãã«ã¢ã¯ã»ã¹ãã¦æ©å¯æ å ±ãç¹å®ãã¦ãã ããã
以ä¸ã®ãµã¤ãã«ã¢ã¯ã»ã¹ãã¦é ããããã©ã°ãè¦ã¤ãã¦ãã ããã