小白一枚,膜拜大佬,欢迎指正
总结
- 二叉树实现输入字符串的置换。
- C++函数名修饰。
- MD5加密
- IDA动态调试
求outstring得出outstring=‘private: char * __thiscall R0Pxx::My_Aut0_PWN(unsigned char *)’
贴上我的exp:
a=list('(_@4620!08!6_0*0442!@186%%0@3=66!!974*3234=&0^3&1@=&0908!6_0*&')
b=list('55565653255552225565565555243466334653663544426565555525555222')
c=list('1234567890-=!@#$%^&*()_+qwertyuiop[]QWERTYUIOP{}asdfghjkl;,ASDFGHJKL:"ZXCVBNM<>?zxcvbnm,./')
flag=''
for i in range(62):
for j in range(0,128):
if a[i]==c[j%23] and b[i]==c[j//23]:
flag+=chr(j)
break
print(flag)
这里贴上别的博主的exp学习参考
str1 = "(_@4620!08!6_0*0442!@186%%0@3=66!!974*3234=&0^3&1@=&0908!6_0*&"
str2 = "55565653255552225565565555243466334653663544426565555525555222"
str3 = '1234567890-=!@#$%^&*()_+qwertyuiop[]QWERTYUIOP{}asdfghjkl;,ASDFGHJKL:"ZXCVBNM<>?zxcvbnm,./'
name = ''
for i in range(62):
name += chr(str3.index(str1[i]) + str3.index(str2[i])*23 )
#str3.index(str[i])得出str1[i]在str3中的序号;(余数)
#str3.index(str2[i])得出str2[i]在str3中的序号;(商)
print (name)
根据函数名修饰规则得出修饰前的v2=?My_Aut0_PWN@R0Pxx@@AAEPADPAE@Z:
学习一下别的博主整理的函数名修饰。
分析出是二叉树实现置换,ida动态调试输入31个连续的ASCII码ABCDEFGHIJKLMNOPQRSTUVWXYZ[]^_得到置换规律然后逆置换破解
附exp:
#include <stdio.h>
#include <string.h>
int main()
{
char name[32] = "?My_Aut0_PWN@R0Pxx@@AAEPADPAE@Z";
int biao[] = { 0x50, 0x51, 0x48, 0x52, 0x53, 0x49, 0x44, 0x54, 0x55, 0x4a, 0x56, 0x57, 0x4b, 0x45, 0x42, 0x58, 0x59, 0x4c, 0x5a, 0x5b, 0x4d, 0x46, 0x5c, 0x5d, 0x4e, 0x5e, 0x5f, 0x4f, 0x47, 0x43, 65 };
char input[32] = { 0 };
int i;
for (i = 0; i < strlen(name); i++)
input[biao[i] - 65] = name[i];
puts(input);
return 0;
}
MD5加密得flag:
flag{63b148e750fed3a33419168ac58083f5}