Misc
ez_QR

一共有50个二维码,每个二维码对应一个字符,豆包写个python脚本
1 | import os |

flag:QLNU{ZHe_sh1_y1_ge_Er_w31_m4_666_oovo_qaqqlnuyyds_ha_ha_ha!!!#1}
baby_MISC

斯国一怎么就是四个1了,怎么读都不像呀,感觉是四多1
.\Decode.exe -X -P 1111 特别的人.mp3
-X是提取隐藏文件
-P是密码
111为文件隐藏时的密码
特别的人.mp3是要提取的文件

我想要把16进制的上面这堆放在010那个区域的左边,但不管怎么能都是在右边

怎么办???????
生日的祝福

里面有段这个
1 | dGFibGUxPSAnzrEnCnRhYmxlMj0gJ0FCQ0RFRkdISUpLTE1OT1BRUlNUVVZXWFlaYWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU2Nzg5Ky8nCgpkZWYgZW5jcnlwdCh0ZXh0LCBzaGlmdCk6CiAgICBlbmNyeXB0ZWRfdGV4dCA9ICIiCiAgICBmb3IgY2hhciBpbiB0ZXh0OgogICAgICAgIGlmIGNoYXIuaXNhbHBoYSgpOgogICAgICAgICAgICBzaGlmdGVkID0gb3JkKGNoYXIpICsgc2hpZnQKICAgICAgICAgICAgaWYgY2hhci5pc2xvd2VyKCk6CiAgICAgICAgICAgICAgICBpZiBzaGlmdGVkID4gb3JkKCd6Jyk6CiAgICAgICAgICAgICAgICAgICAgc2hpZnRlZCAtPSAyNgogICAgICAgICAgICAgICAgZWxpZiBzaGlmdGVkIDwgb3JkKCdhJyk6CiAgICAgICAgICAgICAgICAgICAgc2hpZnRlZCArPSAyNgogICAgICAgICAgICBlbGlmIGNoYXIuaXN1cHBlcigpOgogICAgICAgICAgICAgICAgaWYgc2hpZnRlZCA+IG9yZCgnWicpOgogICAgICAgICAgICAgICAgICAgIHNoaWZ0ZWQgLT0gMjYKICAgICAgICAgICAgICAgIGVsaWYgc2hpZnRlZCA8IG9yZCgnQScpOgogICAgICAgICAgICAgICAgICAgIHNoaWZ0ZWQgKz0gMjYKICAgICAgICAgICAgZW5jcnlwdGVkX3RleHQgKz0gY2hyKHNoaWZ0ZWQpCiAgICAgICAgZWxzZToKICAgICAgICAgICAgZW5jcnlwdGVkX3RleHQgKz0gY2hhcgogICAgcmV0dXJuIGVuY3J5cHRlZF90ZXh0CgplbmNyeXB0ZWRfdGFibGUxID0gZW5jcnlwdCh0YWJsZTEszrIpCgojIGVuY3J5cHRlZF90YWJsZTE9ICdRUlNUVVZXcXJzdHV2d3h5emFiY2RlZmdoaWprbG1ub3BYWVpBQkNERUZHSElKMDEyMzQ1Njc4OSsvS0xNTk9QJwoKZmxhZyA9ICIiCgpmb3IgXyBpbiByYW5nZSg/KToKICAgIHRleHQxID0gYmFzZTY0LmI2NGVuY29kZShmbGFnLmVuY29kZSgpLCBhbHRjaGFycz10YWJsZTEuZW5jb2RlKCkpLmRlY29kZSgpCgpmb3IgXyBpbiByYW5nZSjOsik6CiAgICBlbl9mbGFnID0gYmFzZTY0LmI2NGVuY29kZSh0ZXh0MS5lbmNvZGUoKSwgYWx0Y2hhcnM9dGFibGUyLmVuY29kZSgpKS5kZWNvZGUoKQpwcmludChlbl9mbGFnKQ== |
Base64解码得到
1 | table1= 'α' |
将生日祝福以压缩包形式打开,需要密码,使用ARCHPR破解一下

打开后是
1 | Vm0wd2QyUXlVWGxWV0d4V1YwZDRXRmxVU205V01WbDNXa2M1VjJKR2JETlhhMXBQVmxVeFYyTkljRmhoTWsweFZtcEdZV015U2tWVWJHaG9UVlZ3VlZadGNFSmxSbGw1VTJ0V1ZXSkhhRzlVVmxaM1ZsWmFkR05GWkZwV01VcEpWbTEwVjFWdFNsWlhiR2hYWWxob2VsUlVSbUZrUjA1R1pFWlNUbFpVVmtwV2JURXdWakZXZEZOc1dsaGlSa3BZV1ZkMGQyUnNjRmRYYlVaclVsUkdWbFpYZUhkV01ERkZVbFJHVjJFeVVYZFpla3BIWXpGT2RWVnRhRk5sYlhoWFZtMXdUMVF3TUhoalJscFlZbFZhY2xWc1VrZFdiRnBZWlVaT1ZXSlZXVEpWYkZKSFZqSkZlVlZZWkZwbGEzQklXWHBHVDJSV1ZuTlhiV3hUVFcxb1dGWnRNVEJXTWxGNVZXNU9hbEp0VWxsWmJHaFRWMFpTVjFwRVFrOWlSM2hYVmpKNFQxWlhTa2RqUmxwWFlsaG9lbFpxUm1GT2JFWlpZVVprVTFKWVFrbFdiWEJIVkRKU1YxZHVUbFJpVjJoeldXeG9iMWRHV25STlZFSlhUVlV4TkZaWGRHdFdNa3B5VGxac1dtSkhhRlJXTUZwVFZqRmtkRkp0ZUZkaVJsa3hWa1phVTFVeFduSk5XRXBxVWxkNGFGVXdhRU5TUmxweFVtMUdVMkpWVmpaWlZWcGhZVWRGZUdOSE9WZGhhMHBvVmtSS1QyUkdTbkphUm1ocFZqTm9kbFpHVm05Uk1XUnpWMjVLV0dKSFVtOVVWbHBYVGxaYVdHVkhkR2hpUlhBd1dWVm9UMVp0Um5KT1ZsSlhUVlp3V0ZreFdrdGpiVkpIVld4a2FWSnRPVE5XTW5oWFlXczFXRkpyWkZoaWF6VnhWVEJrTkZkR1VsZFhhM1JUVW14d2VGVXlkR3RoYlVwV1ZtcGFXbFpXY0doWlZXUkdaVWRPU0U5V1pHaGhNSEJ2Vm10U1MxUXlVa2RUYmtwb1VqSm9WRmxZY0ZkbGJHUllaVWM1YVUxWFVraFdNalZUVkd4T1NHRkdRbFppVkVVd1ZtcEdVMVp0UmtoUFZtaFRUVVpaTVZac1pEUmpNV1IwVTJ0a1dHSlhhR0ZVVmxwM1pXeHJlVTFWWkZOaVJrcDZWbGN4YzFVd01IaFNhbHBYWVd0dmQxWlVSa1psUm1SellVWlNhVkp1UW5oV1YzaHJZakZzVjFWc1dsaGlWVnBQVkZaYWQyVkdWWGxrUjBacFVteHdlbFl5ZUhkWFIwVjRZMFJPVjJGcldreFdha3BQVWpKS1IyRkhhRTVXYmtKMlZtMTBVMU14VVhsVVdHeFZZVEZ3YjFWcVRrTldSbXhaWTBaa2EwMVdjREJaTUZZd1lWVXhXRlZyYUZkTmFsWlVWa2Q0WVZKc1RuTmhSbFpYWWtaWk1GWkhkR0ZaVm1SSVZXdG9hMUp0VW5CV2JHaERUbXhhVlZOVVJsVk5WbkF3VlcwMVMxUXhXbk5UYlVaVlZteHdNMVpyV21GalZrNXlXa1pPYVZKcmNEWldiR040WXpGVmQwMUlhRk5oYkhCWVdXeFNSazFHV2xWU2JIQnNVbTFTV2xkclZURlhSa3BaVVc1b1YxWjZRalJaYWtaYVpVWldjMkZGT1ZkbGJYaDZWMWQwWVdReVZrZFdXR3hyVWtWS1dGVnRkSGRsYkZWNVpVaGtXR0pHY0ZoWk1HaExWakpHY2xkcmVGZGhhM0JRVldwS1MxSXhjRWRhUlRWT1VsaENTMVpxUm1GVk1VbDVVbGhvWVZKWFVsWlpiWFIzWWpGV2NWTnRPVmRTYlhoYVdUQmFhMkpIU2toVmJHeGhWbGROTVZsV1ZYaGpNVTUxWTBaa1RtRnNXbFZXYTJRMFlURk9SMVp1VGxoaVJscFlWRlJHUzA1c1draGxSMFpYVFd4S1NWWlhkRzloTVVsNVlVaENWbUpIYUVSVWJYaHJWbFpHZEZKdGNFNVdNVWwzVmxSS01HRXhaRWhUYkdob1VqQmFWbFp0ZUhkTk1YQllaVWhLYkZZeFdrbGFSV1F3VmpKS2NsTnJhRmRTTTJob1ZrUktSMWRHU2xsYVIzQlRWak5vV1ZkV1pEQmtiVkY0WWtoR1UySkZjSE5WYlRGVFpXeHNWbGRzVG1oV2EzQXhWVmMxYjFZeFdYcGhTRXBYVmtWYWNsVnFSbGRqTVhCSFlVZG9UazFWY0ZaV2JHTjRUa2RSZVZaclpGZFhSM2h5VldwT1UySXhiSE5XYm1SWFRWZDRlVlpYTVVkWFJrbDNWbXBTV2sxSGFHaFdha3BIWTIxT1JtVkdXazVXYmtKSlYxaHdSMVl5VFhsU2EyaHBVbXMxY0ZVd1ZrdE5iRnB4VW0xR1ZrMVZNVFJXVm1oelZsWmtTR0ZJUmxaaVIxRXdWbTE0YzJOc1pIVmFSM0JUWWtoQ05GWnJZM2RPVmxsNFYyNU9hbEpGU21oV2JHUk9UVlphV0dNemFHcGlWWEJHVmxkNGExUnNXWGxoUkVwWFlXdEtjbFY2Umt0amF6VlhXa1phYVZKc2NGbFdSbEpMWWpGT1YxZHJhR3RTTUZwaFZtMHhVMU5XV2xoa1J6bG9UVlZzTlZsVmFFTldiVXBJWVVWU1YwMVdjSEpXYkZwSFpFWktkR05GTlZkTlZXd3pWbXhTUzA1SFRYaFhiR1JoVWxkb2IxVnFRbUZXYkZwMFpVaGtUazFXY0hsV01qRkhZV3hhY21ORVFtRlNWMUYzVm1wS1MyTnNUbkppUm1oWFlrWndlVmRZY0VkV2JWRjNUVlprV0dKWGVITlpWRVozVjFaa1dHVkdUbE5oZWtaSVZqSjRWMVV5UlhwUmJrNVdZbFJHVkZwWGVITldiR1J6Vkcxb1UxWkZXWGRYVmxaaFlqRmtSMWR1VGxSaE0yaFlWbXRXWVZsV2NGWlhiR1JxVFd0YVNWa3dXazlXTURGV1kwWmtWMkpIVGpSVWEyUlNaVlphY2xwR1pGaFNNMmg1VmxkMFYxTXhaRWRWYkdSWVltMVNjMVp0TVRCTk1XeFdXWHBXVjAxRVJrWlZiVFZ2Vm0xS1dWVnVXbGRoYTNCSVdUSjRhMlJIUmtoU2JFNXBVMFZLU2xZeWRHRmhNVTE0VTFoc1UyRXlhRzlWYkZKWFYwWnNkR1JGZEU1aVJuQXdXVEJXYTFkc1dYZFdhbEpYWWtkb2RsWXdXbXRUUjBaSFlrWndhVmRIYUc5V2JYQkhZekpOZVZKcmFGQldiVkpVV1d4b2IwNVdXblJOUkVab1RWWnNORll5TlZOV2JVcElaVWRvVm1KSFVrOVVWbHBoVjBkTmVtRkhjR2xXV0VKSFZteGtOR0V4VW5OWFdHeG9Va1Z3V0ZSV1duZGhSbFkyVW10d2JGSnNTakZXYlhoTFlWWktjMk5HYkZoV00xSjJWVlJHYTFZeFpISmhSM2hUVFVad2FGWnRNSGhWTVVsNFZXNU9XR0pWV2xkVmJYaDNUVVpzVmxkc1RsZFdiSEJZV1RCa1IxWldXbk5qU0VwWFlXdGFhRmw2Um10amF6bFhXa2RzVTAweVRqUldiWGhUVXpBMVNGUllhRmhpUjFKb1ZXeGtiMkl4Vm5STlZ6bFhZa1p3TUZwVmFHdFVhekZZWlVaa1YwMXFWbkpXVkVwTFUxWkdjbUZHWkZOTk1taFZWbTF3UzFNeVRuTlVia3BxVW0xb2NGVnRlSGRpTVdSWFZXdDBVMDFXYkRSV1Z6VkxWMGRLUjFOdE9WVldSVnBNVmpGYWExWXhWbkphUjNST1lURndTVmRYZEc5U01WVjVVMnRhYWxORk5WZFpiRkpIVmtaWmVXVkhkR3BpUm5CV1ZXMTRhMVJzV25WUmFscFlWa1ZLYUZacVJtdFNNV1JaWTBaYWFXRXpRbGxXYlhSWFdWZE9jMVp1UmxSaE0xSlZWbTF6TVUxR1ZuUmxSVGxwVWpCd1dsbFZVbE5XTURGWVZWaGtXRlp0VWxOYVZscGhZMnh3UjFwR2FGTk5NbWcxVm14a2QxUXhWWGxUV0docFUwVTFXRmx0TVZOV1JsSlhWMnQwYkdKSGVGZFpWV1F3VjBaSmQyTkZhRnBOUm5CMlZqSnplRk5IUmtabFJtUm9ZVE5DU1ZkVVNqUmhNazUwVm10a1lWSlVWbGhaYlhSTFUyeFplR0ZJWkZOTlZtdzFWa1pvYzFVeVJYbGhTRUpXWWxoTmVGa3dXbFprTVZweVpFVTFhVkp1UVhkV1JscFRVVEZhY2sxV1drNVdSa3BZVm0weGIyVnNXblJOVlZwc1ZteGFlbFl5ZUhkaFZtUkhVMWh3V0Zac1dtaFdha3BUVW1zeFYxcEdWbWxYUlVwVlYxZDBiMUV3TlVkWGJrcGFUVEpTVUZadGVITk9SbGw1VGxaT1YySlZjRWxaVlZwdlZqSkdjazVWT1ZWV2JIQm9WakJrVG1WdFJrZFViR1JvVFZoQk1GWnRlR3RPUjBWNFZXNVNVMkpyTlZsWmExWmhWMFpTVjFkdVpHaFNiRmt5VlcxME1HRnJNVmRUYWtaWFZqTm9VRmxXV2twbFJrNTFXa1prYVZkR1NsbFdiVEI0VlcxV1IxcElWbE5pUlRWd1ZteGFkMkZHV25STlNHaFdUVlUxV0ZZeU5WTmhNVW8yWWtjNVZWWnNXak5VVlZwelZteGtjMVJzWkZkaVNFSmFWMVpXVjFVeFduSk5WbVJxVWpKb1lWUldXbmRWUm10NFYyeGthazFyTlVoWGEyUnpWakpGZVdRemNGZGlXR2hVVlhwQmVGTkdUbGxpUms1b1RXeEtWbGRYTVhwTlZscFhZa2hPVjJKVldtOVZiWGgzWlVaYVNHVkZPV2hTYTNCNldXdFNUMVl3TVhGV2JrcFhWa1Z3VEZVeFdrZGpiVVpIV2taT1RrMXRhRlpXYlRGM1V6Rk5lVlJ1VGxWaWEzQnhWVzB4YjJOR1ZuUmxTR1JwVFZkU1dGWlhkREJWTURGWFlrUlNXR0V5YUZoV2EyUkxWMGRXU1ZSc2NGZFNWbTk2Vm1wR1lWbFdTWGhhU0ZKVFlsaFNUMVpxUmt0VFZsbDVaRWRHYUUxWFVrbFZNblJoWVd4T1JrNVdaRnBpUmtwSVZtdGFXbVZYVmtsVWJHUnBVakZKZDFaRVJtdGlNVmwzVFZWc1VtRXlhRmxXYTFaTFlVWnNjVkp0ZEZOTlYxSXhWa2Q0VTJGRk1IbGhSbXhYWWxoU1dGZFdaRmRqTVdSMVVteFNhRTB4U2xWV1JscGhaREpXYzFkcmFFNVdlbXhXV1Zod1IxWXhhM2RYYlRsWFRXdHdTVlpIY0ZOV1YwVjVWV3M1WVZKRlJYaFdha1ozVTBkS1IxUnNUbWxoTUhCWlZtcEdhMDVHVlhsVVdHeFVWMGRvVjFsclpGTlhWbXgwVFZaT2FrMVdjREJhVldoUFZERmFkR1JFVGxkaVZFVjNWbXBCZUZKV1NuSlhiRnBwVmtaYU1sWnRNSGhUTVdSWFZtNVdXR0pIVW05WlZFWjNZakZhV0UxVVVsUk5helZZVmxjMVUxVXlTa2hWYmtKWFlsaFNNMVV5ZUdGak1YQkpXa1pTVGxaWGR6QldWRVp2WXpGVmVWSlliR2hUUlVwWFdXeG9UbVZHYTNkWGJrNVhWbXRhTVZZeWN6RldNa3BKVVZoa1dHSkdXbkZVYkdSR1pEQXhWMWRzYUdsaVdHaFhWbTB4TkdReVVuTlhiazVZWWxoU1ZWVnFRbUZUUm14V1YyNWthRlp0VWtsWlZXTTFWakpLV1ZGcmFGcGxhM0JQV2xaYVMyTnRSa2RSYkdScFZtdHdWbFl4WkRCV01sRjRXa2hPV0dFeVVsbFpiR2hEVlVaYWNWRnNaRTVOVmtwWVZqSXhNR0ZIU2taalJXUldUV3BHU0Zac1dtRldNazVJVW0xR1UxSldjRzlYYTFaV1pVWmFjMk5GV2xCV01uaFVWakJXU2sxV1dYaFhiR1JhVmpCV05GWlhOVk5WTWtweVRsWnNXbUV4V21oV01GcFRWakZrZFZwSGFGTmlSbXQ1VmxjeE1HUXlTa2RUYms1VVlXdGFXRlpxVG05VlJteFhWMnR3YkZKck5URlhhMXByWVVkRmQyTkhPVmRYU0VKTVZUSXhWMUl5VGtaaVJsWnBVakpvZDFadGVHRmtNV1JIVjJ0a1dHSlZXbkZVVlZKWFUwWmtjbUZGZEdoU2EzQjVWR3hhYTFadFNsbGhSRTVWVmxad2FGWXdWVEZXYkZKeldrVTFhRTB3U2t0V01WcFhWakZWZUZkc2FGUmlSM2h2VldwS2IxbFdVbGRYYm1SV1VteHdlbFl5ZERCaGF6RldUbGhzVldKR2NISldSM040WkVkR1NGSnNaR2xXUlZsNlZsaHdTMVZ0VmtoVGEyUmhVbTFTV1ZWcVNtOVhiR1JYVld0a2EwMVdjRmhaYTJoTFdWWktObUpHYkZaaVZFVXdWakZhY21WdFRrWmFSMmhPWVROQ1NsZHNWbUZoTVZsM1RWaEdVMkV5YUdGV2FrNXZZVVpyZVUxVk9WUldNRFZJV1ZWa2IxUnNaRVpUV0d4WFlsUkdNMVY2Ums1bFZsSjFWR3hXYVdFelFuZFdWekI0VlRGa1IySklUbGhoTVhCeVZGWmFjMDVHV1hsTlZXUllVakJ3V0ZZeWRHOVdNVW8yVm10NFYwMUhVa3hWYlhNeFZqSkdSMWR0YkZOaWEwcFpWbXRrTkZKck9WZFJiRXBSVmtSQk9RPT0= |
frombase64的魔法棒一直点

1 | w8+8nMw3t8F2kGv3vNB9s9shjNcLhpTNt6TfmM7euLc9gnHMuqBmd8XDpDsSl5gSwqFGmMr/r8oSj7z8uEP5vz== |


flag:QLNU{Y0u_@r4_gO0d_Ctfer!}
你是mvp还是躺赢狗?

使用zip方式打开,是一张图

注:IHDR 数据块,其标识为 “49 48 44 52”
有个问题,为啥会变成这样,就是把宽改了下




flag:QLNU{l00k_1n_My_3ye5_!}
奇怪的动图

明文攻击

拿到其中的文件


记事本替换一下

使用python脚本转换为utf-8
1 | binary_str = '0100000000110001010001100101111101101001001101010101111101100001011011010100000001111010001100010110111000111001' |

flag:QLNU{@1F_i5_am@z1n9}
NetTraffic

分析TCP流

密码:e45e329feb5d925b

冰蝎的数据是ACE加密的


接着找

flag:QLNU{b3h1NdEr_WebShEll_A_L1ttle_hArd}
Web
myjwt

获得的令牌是eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VyIjoiZ3Vlc3QiLCJleHAiOjE3NDMzMDA4ODR9.ftDljpYTxsWKpL0S15_BZvNTsDfqPqKGek7NRbxtdnY
解码

接着使用jwt_tool爆破得到秘钥,秘钥是12345678

将guest改为admin,并重新生成jwt,使用bp加上Authorization头重新提交


flag:flag{1ef47ba1-9d70-4f0d-8330-59ba14e7b7a5}
泄露
dirsearch扫描

git目录还原



flag:QLNU{S1mpl3_g1t_AnD_sWp}
pppppyyyyyyyyyyyyyyyy


bp爆破一下



问的豆包



flag:QLNU{8beb2640-cf69-4a92-ac81-185d769d6205}
Crypto
ez_rsa

这题是存AI呀,没学过算法
1 | # 扩展欧几里得算法,用于计算模逆元 |

flag:QLNU{9f873f1c0315202caf47572a0bc24715}