攻防世界 REVERSE 新手区/logmein
看题,是和算法逆向相关的
查一下并没有加壳,是个64位的程序
用IDA64位打开,找到main函数,F5反汇编
分析算法
void __fastcall __noreturn main(__int64 a1, char **a2, char **a3)
{
size_t v3; // rsi
int i; // [rsp+3Ch] [rbp-54h]
char s[36]; // [rsp+40h] [rbp-50h]
int v6; // [rsp+64h] [rbp-2Ch]
__int64 v7; // [rsp+68h] [rbp-28h]
char v8[8]; // [rsp+70h] [rbp-20h]
int v9; // [rsp+8Ch] [rbp-4h]
v9 = 0;
strcpy(v8, ":\"AL_RT^L*.?+6/46");
v7 = 28537194573619560LL;
v6 = 7;
printf("Welcome to the RC3 secure password guesser.\n", a2, a3);
printf("To continue, you must enter the correct password.\n");
printf("Enter your guess: ");
__isoc99_scanf("%32s", s);
v3 = strlen(s);
if ( v3 < strlen(v8) )
sub_4007C0(v8);
for ( i = 0; i < strlen(s); ++i )
{
if ( i >= strlen(v8) )
((void (*)(void))sub_4007C0)();
if ( s[i] != (char)(*((_BYTE *)&v7 + i % v6) ^ v8[i]) ) //字符比较
((void (*)(void))sub_4007C0)();
}
sub_4007F0();
}
v7的v7[0]到v7[6 ]依次与v8[i]异或
if ( s[i] != (char)(*((_BYTE *)&v7 + i % v6) ^ v8[i]) ) //字符比较
((void (*)(void))sub_4007C0)(); //有一个字符对不上就输出答案错误
将v7转为字符
注意在汇编语言中字符串是以小端存储的,所以要反过来,脚本如下
#include <stdio.h>
#include <string.h>
#include <string.h>
int main() {
char v8[] = ":\"AL_RT^L*.?+6/46";
char v7[] = "harambe";
for(int i = 0; i < strlen(v8) ; i++)
{
v8[i] = v7[i % 7] ^ v8[i];
printf("%c",v8[i]);
}
return 0;
}
!
运行得到flag