查壳
无壳
IDA
挨个看过去只有红框有具体内容,橙色箭头输出失败或成功。那关键就在这个if判断里。
![在这里插入图片描述](https://img-blog.csdnimg.cn/20210422211725425.png?x-oss-process=image/watermark,type_ZmFuZ3poZW5naGVpdGk,shadow_10,text_aHR0cHM6Ly9ibG9nLmNzZG4ubmV0L3FxXzQ1NzcxNDEz,size_16,color_FFFFFF,t_70#pic_center
仔细分析这里,发现红框的 off_6020A0和dword_6020C0都是已知的字符串,(其中后者需要处理下间隔,而且是以16进制数字示人)。这种套娃字符串的形式可当作用 6020C0字符串作为下标对6020A0进行排序。
EXP
arrA0=[36, 0, 0, 0, 0, 0, 0, 0, 5, 0,
0, 0, 54, 0, 0, 0, 101, 0, 0, 0,
7, 0, 0, 0, 39, 0, 0, 0, 38, 0,
0, 0, 45, 0, 0, 0, 1, 0, 0, 0,
3, 0, 0, 0, 0, 0, 0, 0, 13, 0,
0, 0, 86, 0, 0, 0, 1, 0, 0, 0,
3, 0, 0, 0, 101, 0, 0, 0, 3, 0,
0, 0, 45, 0, 0, 0, 22, 0, 0, 0,
2, 0, 0, 0, 21, 0, 0, 0, 3, 0,
0, 0, 101, 0, 0, 0, 0, 0, 0, 0,
41, 0, 0, 0, 68, 0, 0, 0, 68, 0,
0, 0, 1, 0, 0, 0, 68, 0, 0, 0,
43, 0, 0, 0]
arrC0='L3t_ME_T3ll_Y0u_S0m3th1ng_1mp0rtant_A_{FL4G}_W0nt_b3_3X4ctly_th4t_345y_t0_c4ptur3_H0wev3r_1T_w1ll_b3_C00l_1F_Y0u_g0t_1t'
#------way1------
# flag=''
# for i in range(0,len(arrA0)):
# if(i%4==0):
# arrA0[int(i/4)]=arrA0[i]
# for i in range(0,31):
# flag=arrC0[arrA0[i]]
# print(flag,end='')
#------way2------
count=0
for arr in arrA0:
if(count%4==0):
flag=arrC0[arr]
print(flag,end='')
count+=1
flag
ALEXCTF{W3_L0v3_C_W1th_CL45535}