2014-01-01ãã1å¹´éã®è¨äºä¸è¦§
CSAW CTF 2014ã®äºé¸ã«superflipã¨ãããã¼ã åã§åå ãããçµæã2240ç¹145ä½ãå»å¹´ã¾ã§ã¯ç°¡åãªåé¡ãå¤ãã£ããã©ãä»å¹´ã¯é£ããåé¡ã¯æ®éã«é£ããã£ãã以ä¸ã解ããåé¡ã®è§£æ³ãåé¡ã¯ã¢ã«ã¦ã³ããç»é²ããã°ãããã§ã¾ã è¦ãããã Exploitation bo (â¦
SECCON 2014 横æµå¤§ä¼ã«åºãããã¤ããªäºé¸ã®å¾åçµã§äºé¸ãééããããç¿æ¥ã®ã¯ã¤ãºå¤§ä¼ã§åæ¦æé(´・Ïï½¥ï½) ãã¤ããªäºé¸ã¯ååçµã¨å¾åçµã«åãããããããã5åã®åé¡ã1åãã¤åºé¡ãããæåã«è§£ãã人ããæãã¦ããæ¹å¼ã1人ãåã«åºã¦ããã¸ã§ã¯ã¿â¦
IPAã«å ±åãããWL-Enqãã®èå¼±æ§ã«ã¤ãã¦ãIPAã«æ å ±éé示ä¾é ¼ã®åãä¸ããç³è«ãã¦èªããããã®ã§ãèå¼±æ§é¢é£æ å ±ãå ¬éãã¾ããç§ã¯ãããã®æ å ±ã®å 容ãçå®ã§ããã¨ç¢ºä¿¡ãã¦ãã¾ãããéçºè ãªã©ã®åèªãæ¯æããæå³ã§ãããã®æ å ±ãå ¬éããããã§â¦
HITCON CTF 2014ã«ãã¼ã fuzzi3ã§åå ãããç·å¢24人ãçµæã¯1ä½ã以ä¸ãç§ã解ããåé¡ã mid (ACM) 250ç¹ ã¸ã£ã³ã«ãACMã§ãã¾ãã«ãããã競æããã°ã©ã³ã°ã®åé¡ãæ´æ°nã¨nåã®æ´æ°A0, A1, â¦, An-1ãä¸ããããAã®ä¸å¤®å¤ãçãããnã¯1iã¯ç¬¦å·ä»ã64bitâ¦
表ã¯ãããæå·åããã°ã©ã ã¨æå·åãããã¡ã¤ã«ãä¸ãããã¦ããã¡ã¤ã«ã復å·ããåé¡ãæå·åã®ã³ãã³ã㯠$ ./crypt 1 pub.txt flag.pdf flag.bincryptã«ã¯ãããã¡ã¼ãªã¼ãã¼ããã¼ã®èå¼±æ§ãåå¨ããã®ã§ãæ»æãã¦ã¿ãã [kusano@www10383uf Decrypt â¦
çµè« #include <stdlib.h> #include <unistd.h> int main() { execl("/bin/sh", "/bin/sh", "-p", NULL); } ããã㯠#include <stdlib.h> #include <unistd.h> int main() { setreuid(geteuid(), -1); system("/bin/sh"); } åè setuid - Wikipedia 7-3. setuid ã¯æ éã« Technical Memorandum: set</unistd.h></stdlib.h></unistd.h></stdlib.h>â¦
æ²è¶ã®åã®ãã¹ãçããã¬ã¤ãããé¢ç½ãã£ãã5æéãããã§çµãããå®ãããªã¹ã¹ã¡ã ã²ã¼ã ãã¤ã³ã¹ãã¼ã«ããã«ãããã使ç¨è¨±è«¾å¥ç´æ¸ãèªãã ããæ°ã«ãªãæ¡é ããã£ãã 第5æ¡ï¼å¥ç´ã®çµäºï¼ å¼ç¤¾ã¯ãã客æ§ãæ¬å¥ç´ã®ããããã®æ¡é ã«éåããã¨ãã¯â¦
Googleã®ã¦ã§ããµã¼ãã¹ãã½ããã¦ã§ã¢ã«èå¼±æ§ãè¦ã¤ããã¨éãããããã詳細ãä¸çä¸ã®ï½½ï½°ï¾ï¾ï½°ï¾ï½¶ï½°ãæ¢ãã¦ããããç°¡åã«è¦ã¤ããèå¼±æ§ãªãã¦ããæ®ã£ã¦ããªãã ããã¨æã£ã¦ããããå¶ç¶è¦ã¤ãã¦ãã¾ããå ±é ¬ã¨ãã¦1000ãã«ããã£ãã Chrome Toolbox Chrâ¦
mixiã®èå¼±æ§å ±åå¶åº¦ï¼ãã§ã«çµäºãã¦ããï¼ã§å ±åããèå¼±æ§ã mixiã«å ±åããèå¼±æ§1 mixiã«å ±åããèå¼±æ§2 mixiã«å ±åããèå¼±æ§3ï¼ï¼å ±åããªãã£ãèå¼±æ§ï¼ Livlisã«ãã°ã¤ã³ãã¦ããã¦ã¼ã¶ã¼ã®Twitterã¢ã«ã¦ã³ãåã®æ¼æ´© 2013/12/19 å ±å 2014/05/15â¦
ã¼ã£ãã¼ã superflipã¯1403ç¹ã24ä½ã ã£ãã ç·´ç¿åé¡ ç·´ç¿åé¡ 100ç¹ FLAG{seccon2014} ãã®ãã±ããã解æãã ãããã¯ã¼ã¯ 100ç¹ FTPéä¿¡ãFTPã¯å¶å¾¡ã¨ãã¡ã¤ã«è»¢éã¯å¥ã®ãã¼ãã§è¡ãã55çªç®ã®ãã±ããã«ã RkxBR3tGN1AgMTUgTjA3IDUzQ1VSM30=ã¨ãããâ¦
ZIPã¯ä¸è¨ã®ãµã¤ãã«æ¸ãã¦ããããLZHãç¡ãã£ããZIPã®é¢é£ä»ããWindowsæ¨æºã«æ»ãï¼åæåããï¼ä»¥ä¸ã®å 容ãæ¡å¼µå.regã®ãã¡ã¤ã«ã«æ¸ãã¦ãã¬ã¸ã¹ããªã«è¿½å ããã°è¯ããWindows 7ã®ã¬ã¸ã¹ããªããã¨ã¯ã¹ãã¼ããããã©ãWindows 8ã§ãåãããVistaã§â¦
IPAã«å ±åãããæ±æ¹é¢¨ç¥é² ã Mountain of Faith.ãã¨ã04WebServerãã®èå¼±æ§ã«ã¤ãã¦ãIPAã«æ å ±éé示ä¾é ¼ã®åãä¸ããç³è«ãã¦èªããããã®ã§ãèå¼±æ§é¢é£æ å ±ãå ¬éãã¾ããç§ã¯ãããã®æ å ±ã®å 容ãçå®ã§ããã¨ç¢ºä¿¡ãã¦ãã¾ãããéçºè ãªã©ã®åèªãâ¦
mixiã®èå¼±æ§å ±åå¶åº¦ï¼çµäºï¼ã«å ±åããèå¼±æ§ã¨å ±åããªãã£ãèå¼±æ§ãåä¼ç¤¾ã®æ ªå¼ä¼ç¤¾Diverseãéå¶ããYYCã¨ããåºä¼ãç³»ãµã¤ãã«ã¤ãã¦ã æå¦è¨å®ã«ã¤ã㦠2014/03/12 å ±å 2014/04/11 ä¿®æ£å®äºãä»æ§ã§ããããå¶åº¦ã®å¯¾è±¡å¤ã¨ã®é£çµ¡ YYCã«ã¯ç¹å®ã®ç¸â¦
tkbctf3ã§åºé¡ãããåé¡ãåé¡ ^^5c^^66^^75^^74^^75^^72^^65^^6c^^65^^74^^7e ^^5c^^63^^61^^74^^63^^6f^^64^^65^^60K7 KK5cKK65KK6eKK64KK6cKK69KK6eKK65KK63KK68KK61KK72- KK5cKK73KK74KK72KK69KK6eKK67KK60 KK7eKK60I13KK7eKK60G10KK5cKK6cKK65KK74 IKKâ¦
tkbctf33ä½ã ã£ãã Misc 100 Real World TeX ãããªæãã®è¬ã®texãã¡ã¤ã«ã16é²æ°ãæåã«ç´ãã^^ãKKãåé¤ããZVHNããããã\ã¹ãã¼ã¹{}ã«ç½®æã¨ããã¨texã£ã½ããªããã©ãIãGãã©ãå¦çãã¦è¯ãã®ãåãããªãã£ãã ^^5c^^66^^75^^74^^75^^72^^65^^â¦
mixiã®èå¼±æ§å ±åå¶åº¦ï¼ãã§ã«çµäºãã¦ããï¼ã§å ±åãã¦ãä¿®æ£ãããèå¼±æ§ã youbrideã®æææ©è½ãç¡æã§ä½¿ããåé¡ 2014/03/12 å ±å 2014/03/18 ä¿®æ£å®äº 2014/03/24 75,000åã®Amazonã®ãããå±ãã youbrideã¯mixiã®åä¼ç¤¾ã®æ ªå¼ä¼ç¤¾Diverseãéå¶ããå©â¦
backdoorCTFã«ãã¼ã superflipã¨ãã¦åå ããã2630ç¹21ä½ããµã¯ãµã¯è§£ãã¦é¢ç½ãã£ãããã©ã°ã¯è¦ã¤ãããã©ã°ã®MD5ããã·ã¥ãæ稿ãããã®ãå¤ãã£ãã®ã§ãä¸å¿çãã«ãMD5ããã·ã¥ãä»ãã¦ãããæå®ãããåé¡ä»¥å¤ã«ãCSSã¨ãã«é ããã©ã°ããã£ããããâ¦
mixiã®èå¼±æ§å ±åå¶åº¦ã§å ±åãã¦ãä¿®æ£ãããèå¼±æ§ãå ±é ¬ããããããã©ãããåãã£ãã追è¨ããã nohanaã®ãã¹ã¯ã¼ããªãã¤ã³ãã¼ã®XSS 2013/10/02 å ±å 2014/02/14 ä¿®æ£å®äº 2014/03/25 å ±é ¬æ¯æã対象å¤ã¨ã®é£çµ¡(´・Ïï½¥ï½) http://nohana.parseapp.com/pâ¦
RuCTF 2014 Qualsã«ããã¼ã superflipã¨ãã¦1æ¥ã ãåå ãã¦ããã310ç¹182ä½(´・Ïï½¥ï½) RuCTFãåé¡æ°ã50åããã£ã¦ãã©ã®åé¡ãé¢ç½ããã§ãããã以ä¸ã解ããªãã£ãã®ããããã©ãææ¦ããåé¡ã crypto 100. MD5 æªç¥ã®æååpasswordã«ãããã¦ãé©å½ãªâ¦
iPhone 5sã«ã¹ãã©ãããä»ããã¾ã¾ç´æ£ããã¯ã«è¼ããããããã«ããã ã¹ãã©ããã¯NETSUKEã使ã£ããAmazonã§ãAmazonçºéã§è²·ããããã©ã¤ãã¼ã交æå¼ã®å 端ã ãã«ãªã£ã¦ããã®ãè¥å¹²æ®å¿µã ãã©ããã£ãããã¦ãã¦è¯ãæãã ãã®ã¾ã¾ã ã¨ç´æ£ããã¯ã«â¦
ãã®ããã°ã©ã ã«ã¯èå¼±æ§ãããã #include <stdio.h> #include <string.h> char target[] = "test"; int main() { char buf[1024]; fgets(buf, sizeof buf, stdin); printf(buf); printf("%p: %s\n", target, target); return 0; } $ g++ -m32 -o bug bug.cpp $ ./bug abcdefg</string.h></stdio.h>â¦
2013ã年度ãã®å ¨å½å¤§ä¼ãç§ãæå±ãã¦ããæãã¼ã ã¯ãååããä¸ã®é ä½ã ã£ã(´・Ïï½¥ï½) å¡ã®ååãä»ãã6åã®ãµã¼ãã¼ããã£ã¦ããµã¼ãã¼ã®ä¸ãããã¼ã¯ã¼ããæ¢ãåºãã¨ç¹æ°ã²ãããæå®ããããã¡ã¤ã«ã«ãã¼ã ãã¨ã®æååãæ¸ãè¾¼ã¾ãã¦ããã¨ç¹æ°ã²ãâ¦
SECCON 2013 ãªã³ã©ã¤ã³äºé¸å¤§ä¼ã«ããã¼ã superflipã¨ãã¦åå ããã3600ç¹ï¼ãã¶ãï¼10ä½ã解ããåé¡ã¯æ¬¡ã®éãã 以ä¸ã解ããåé¡ã¨å¾ãã解ããåé¡ã®Write-upã ãã©ã¬ã³ã¸ãã¯ã¹ 100ç¹ ããã¯ã©ãï¼ åé¡ãã¡ã¤ã«ã¯é»åã¡ã¼ã«ãæ¬æ㯠ç: ââââââ âââ¦
IPAã¯èå¼±æ§é¢é£æ å ±ãåãä»ãã¦ãï¼JPCERT/CCã«éç¥ãã¦JPCERT/CCãï¼è£½åéçºè ã«é£çµ¡ããã¨ããä»äºããã¦ããï¼åã«ããã¨å°ä»»ã®äººãããããã§ã¯ãªããããï¼ãã©ãããåé¡ãèå¼±æ§ã¨ãã¦åçããããã¯IPAãå ¬éãã¦ããèå¼±æ§ã®ä¸è¦§ãè¦ãã°ãããâ¦
hack you 2014ã«åå ããã12/20åã3000ç¹ã15ä½ã以ä¸ã解ããåé¡ã®è§£æ³ã Crypto 100 Easy one åç´ãªæå·åã®ããã°ã©ã ã¨ãå¹³ææå·åã®ãã¢ã¨ãæå·åãä¸ããããã®ã§ãéµãéç®ãã¦ã P = open("msg001", "rb").read() C = open("msg001.enc", "rb"â¦