easy
这个东西发现没有入口,只能一个个看,发现qes这个函数有一堆数,函数很小,逆向也容易,完事以后用BJD包裹(这个没说)
#int qes()
a = [0x7FFA7E31,0x224FC,0x884A4239,0x22A84,0x84FF235,0x3FF87,0x88424233,0x23185,0x7E4243F1,0x231FC]
for i in range(5):
v6 = (a[i*2] & 0xffffffff) | ((a[i*2+1] & 0xffffffff)<<32)
v2 = [0]*51
v8 = 0
while v6:
v2[v8] = v6%2
v6 >>=1
v8 +=1
for j in range(50,-1,-1):
if v2[j] == 1:
print('*', end='')
else:
print(' ', end='')
if j%5 == 0:
print(' ', end='')
print('')
'''
* * * ***** * * ***** ***** * * ***** * * * *
* * * * * * * * * * * * * * ** *
***** ***** * *** * * ***** *** * * * * *
* * * * * * ** * * * * * * * **
* * * * ***** * * ***** * * * ***** * *
'''
#HACKIT4FUN
#BJD{HACKIT4FUN}
JustRE
这个也是漫天找函数,发现几乎直接给了flag
INT_PTR __stdcall DialogFunc(HWND hWnd, UINT a2, WPARAM a3, LPARAM a4)
{
CHAR String[100]; // [esp+0h] [ebp-64h] BYREF
if ( a2 != 272 )
{
if ( a2 != 273 )
return 0;
if ( (_WORD)a3 != 1 && (_WORD)a3 != 2 )
{
sprintf(String, Format, ++dword_4099F0);
if ( dword_4099F0 == 19999 )
{
sprintf(String, " BJD{%d%d2069a45792d233ac}", 19999, 0);
SetWindowTextA(hWnd, String);
return 0;
}
SetWindowTextA(hWnd, String);
return 0;
}
EndDialog(hWnd, (unsigned __int16)a3);
}
return 1;
}
//BJD{1999902069a45792d233ac}
BJD hamburger competition
这个网上搜了下说这种游戏主函数在Assembly-CSharp.dll,.net写的东西用dnSpy打开打到主函数
else if (name == "汉堡顶" && Init.spawnCount == 5)
{
Init.secret ^= 127;
string str = Init.secret.ToString();
if (ButtonSpawnFruit.Sha1(str) == "DD01903921EA24941C26A48F2CEC24E0BB0E8CC7")
{
this.result = "BJDCTF{" + ButtonSpawnFruit.Md5(str) + "}";
Debug.Log(this.result);
}
}
显然就是一个数字,它的sha1是那个然后求md5就行了,数字的很容易处理可以网上查也可以自己爆破。坑在md5函数,是在标准的md5后取了大写前20位
public static string Md5(string str)
{
byte[] bytes = Encoding.UTF8.GetBytes(str);
byte[] array = MD5.Create().ComputeHash(bytes);
StringBuilder stringBuilder = new StringBuilder();
foreach (byte b in array)
{
stringBuilder.Append(b.ToString("X2"));
}
return stringBuilder.ToString().Substring(0, 20); //大写前20位
}
最大的坑在后边,它说明的是BJDCTF包裹,实际从网上搜到是flag包裹
#flag{B8C37E33DEFDE51CF91E} ?为啥提示是BJDCTF这里要用flag
总体来说一套题4道有3道有问题。无语