当前位置:网站首页>Misc Basic test method and knowledge points of CTF
Misc Basic test method and knowledge points of CTF
2022-07-05 15:10:00 【Golden silk】
One 、 Simple test method
1、 Attribute hiding flag Or some important information , Such as unpacking password
2、 Hexadecimal data of the file ( middle \ ending ) Hide character segments , Those hidden character segments are generally regular , It may take some decoding to arrive flag, Example :Bugku And telnet_l2872253606 The blog of -CSDN Blog
3、 Add file suffix zip unpack , In the unzipped file flag
4、 Complete the file header
5、 Common file types
6、kali Next file Command to view file types
command :file file name
Two 、zip
1、 File format
• Head sign 50 4B 03 04
• Version number , The last four digits of the head logo
• Encryption , The last two digits of the version number ,00 Is unencrypted , The rest are usually encrypted
2、 Pseudo encryption , There was no encryption zip file , In artificial modification 16 Base case ( After the version number 00 Get rid of ), I mistakenly thought it was encrypted when decompressing
3、 Code explosion , Using tools ARCHPR Blasting
3、 ... and 、PNG
1、 File format
• Head logo ,89 50 4E 47 0D 0A 1A 0A
• Width bit 0x10-0x13, Don't change it at will , According to CRC Value modification
• Height bit 0x14-0x17, You can change it at will
•CRC Check bit 0x1D-0x20,CRC It is the verification of file data blocks , Modifying the data block will cause the verification to fail , The file cannot be displayed normally
2、 The height display is incomplete , Example :Bugku Steganography _l2872253606 The blog of -CSDN Blog
3、 The width display is incomplete , According to the... Of blasting documents CRC Value changes the width , Otherwise, it will fail to open the file
4、LSB Steganography , Using tools stegsolve Or is it kali see ,kali Watch it all ,
Example :Bugku Cyberpunk _l2872253606 The blog of -CSDN Blog
• use stegsolve see
For documents stegsolve open ,Analyse,Date Extract
Check the last three 0, The mode is generally RGB, If you don't find it , You can try another mode
Point again Preview, Drag the data to the top
Find out flag
• use kali see
You have to download zsteg Tools , Specific method Baidu , Drag the file into kali
Enter the command zsteg file name
You can view the hidden content
Four 、JPG
1、 File format
• Head logo ,FF D8
• Tail marker ,FF D9
2、 Modification of width and height
3、base64 Source code to picture
5、 ... and 、GIF
1、 File format
• Head sign ,47 49 46 38(GIF8)
2、flag Hidden in a frame , use stegsolve see
6、 ... and 、 File separation
Sometimes a file may hide many files , At this time, we have to use tools to separate
1、 Automatically analyze files and automatically separate files
use kali System
• Analyze documents binwalk file name
• Separate files binwalk -e file name
• Separate files foremost file name -o Directory name
2、 Manual file separation
Automatic separation is used when it doesn't work , Specific operation Baidu
3、 Example :Bugku And easy_nbt_l2872253606 The blog of -CSDN Blog
边栏推荐
- 裁员下的上海
- 亿咖通科技通过ISO27001与ISO21434安全管理体系认证
- mapper.xml文件中的注释
- How to solve the problem of garbled code when installing dependency through NPM or yarn
- 长列表优化虚拟滚动
- GPS original coordinates to Baidu map coordinates (pure C code)
- Handwriting promise and async await
- 市值蒸发超百亿美元,“全球IoT云平台第一股”赴港求生
- ICML 2022 | 探索语言模型的最佳架构和训练方法
- CPU设计实战-第四章实践任务三用前递技术解决相关引发的冲突
猜你喜欢
Au - delà du PARM! La maîtrise de l'Université de Pékin propose diverse pour actualiser complètement le classement du raisonnement du NLP
Live broadcast preview | how to implement Devops with automatic tools (welfare at the end of the article)
"Sequelae" of the withdrawal of community group purchase from the city
Interview shock 62: what are the precautions for group by?
Bugku telnet
IPv6与IPv4的区别 网信办等三部推进IPv6规模部署
Coding devsecops helps financial enterprises run out of digital acceleration
DVWA range clearance tutorial
Ctfshow web entry explosion
Huiyuan, 30, is going to have a new owner
随机推荐
Bugku easy_ nbt
PHP high concurrency and large traffic solution (PHP interview theory question)
Under the crisis of enterprise development, is digital transformation the future savior of enterprises
Visual task scheduling & drag and drop | scalph data integration based on Apache seatunnel
Surpass palm! Peking University Master proposed diverse to comprehensively refresh the NLP reasoning ranking
NBA赛事直播超清画质背后:阿里云视频云「窄带高清2.0」技术深度解读
可转债打新在哪里操作开户是更安全可靠的呢
Mysql---- function
MySQL之CRUD
GPS original coordinates to Baidu map coordinates (pure C code)
基于TI DRV10970驱动直流无刷电机
No one consults when doing research and does not communicate with students. UNC assistant professor has a two-year history of teaching struggle
sql server学习笔记
The elimination strategy of redis
可视化任务编排&拖拉拽 | Scaleph 基于 Apache SeaTunnel的数据集成
useMemo,memo,useRef等相关hooks详解
我这边同时采集多个oracle表,采集一会以后,会报oracle的oga内存超出,大家有没有遇到的?
两个BI开发,3000多张报表?如何做的到?
Drive brushless DC motor based on Ti drv10970
729. 我的日程安排表 I :「模拟」&「线段树(动态开点)」&「分块 + 位运算(分桶)」