22年国赛单机取证
Evidence4
先搜索Evidence

找到一个

Evidence4
nsOh2.png
f5b9ce3e485314c23c40a89d994b2dc8
Evidence2
之后再一个个找
这个是压缩包格式的

导出来
伪加密

修复一下


Evidence2
ZQOo2.jpg
9e69763ec7dac69e2c5b07a5955a5868
Evidence3
png的文件

改个宽高


Evidence3
p3qQ4.jpg
a9a18aecec905a7742042461595b4b5c
Evidence6
mp3的格式

png的格式

再对照表就好

Evidence6
mkjRv.7z
e610fcd2a0cd53d158e8ee4bb088100a
Evidence5

这个也是错误格式
strings得到


IV3GSZDFNZRWKNI=

Evidence5
RVlYt.zip
d6638c17b2e700397ab2e02cbd079dae
Evidence9

Evidence9
jMH7w.xlsx
523c407180d54dde6eca700405599c8a
Evidence7
png格式的


Evidence7
OR8iq.xml
28ba933c31fd60f8c4461aed14a8c447
Evidence10


Evidence10
01d98.gif
d708444963b79da344fd71e5c72f7f02
Evidence1


Evidence1
eg2kX.jpg
85cdf73518b32a37f74c4bfa42d856a6
Evidence8


Evidence8
8cFQj.py
7fccfb1778b15fbc09deb6690afc776a
2023福建省单机取证
evidence 10
直接搜索找到了evidence 10

Evidence10
topy.docx
04b87697a5fd9e168ced165d21d177e3
evidence 7
png后缀


改高度得到

evidence 7
wb.zip
cdc07e85116b037c40351c49da6eb35a
evidence 1


evidence 1
sys.dll
d3c5335367e17b966a13e2663235a1ff
evidence 5

zip文件

补全文件头

解压得到jpg文件

evidence 5
tmp
da5d01d2f7e8c37ab1c1857be587ad74
evidence 2

evidence 2
tag
43168b2bdf149526b8bb8b89f1b06cc1
evidence 3

有隐藏图片,不过没用
strings hack.png | tail -60

echo IV3GSZDFNZRWKMYK | base32 --decode

evidence 3
hack.png
1308b0d65360eba6a47224733f13ca84
evidence 4

lsb隐写

evidence 4
sea.png
1c990420fc307c7bd2b65396c5e5e13f
evidence 8

evidence 8
display
8b2da168f3221d343c4e3f1aceed3e88
evidence 9

.7z文件
解压是bmp格式图片


evidence 9
z.x
14046db8621b2aca9ffced76d23cc6e9
evidence 6

evidence 6
cve.xlsx
c2b9d953d7e04c8e0d08fee3bd4513cd
1238

被折叠的 条评论
为什么被折叠?



