当前位置:网站首页>Common routines of compressed packets in CTF
Common routines of compressed packets in CTF
2022-07-02 20:53:00 【qq_ twenty-nine million five hundred and sixty-six thousand six】
Special characters that recognize hexadecimal strings :504B0304 To begin ,504B0506 End of the said ( Here is a supplementary knowledge point : Name the file as what file type , The computer will recognize from what feature head , such as zip From 504B0304 Start identifying , from 504B0506 end ), It is worth noting that for txt file , No header exists .



Pseudo encryption

File repair
It is possible that the file header is intentionally written incorrectly :
Just change it at this time :504B0304Redundant information splicing
ZIP The end identification bit of the compressed file directory is “504B0506”, And usually with 18 byte ( In the preliminary knowledge, we regard each offset as one , It's also a byte ) Redundant data for , The total length is generally 20 Bytes , So this routine is to divide the hidden information into multiple pieces and hide them at the end of multiple compressed packets .
this 20 Bytes cannot be moved , Other redundant information can be added later , If you move , It will cause decompression failure .
Sum up , Find redundant data in the right place and splice , See what code it is , Decode again
- Find :

And comments can also be made through winhex see , Usually at the end :
边栏推荐
- 想问问,现在开户有优惠吗?在线开户是安全么?
- An analysis of the past and present life of the meta universe
- C language linked list -- to be added
- Google Earth engine (GEE) - Landsat 9 image full band image download (Beijing as an example)
- 想请教一下,我在东莞,到哪里开户比较好?手机开户是安全么?
- CRM Customer Relationship Management System
- 外包干了三年,废了...
- [question brushing diary] classic questions of dynamic planning
- Research Report on the overall scale, major manufacturers, major regions, products and applications of micro hydraulic cylinders in the global market in 2022
- Research Report on the overall scale, major manufacturers, major regions, products and applications of building automation power meters in the global market in 2022
猜你喜欢

CRM Customer Relationship Management System

ROS learning (10): ROS records multiple topic scripts

接口测试到底怎么做?看完这篇文章就能清晰明了

Resunnet - tensorrt8.2 Speed and Display record Sheet on Jetson Xavier NX (continuously supplemented)

How can testers do without missing tests? Seven o'clock is enough

Cs5268 perfectly replaces ag9321mcq typec multi in one docking station solution

Burp install license key not recognized

AMD's largest transaction ever, the successful acquisition of Xilinx with us $35billion

After 65 days of closure and control of the epidemic, my home office experience sharing | community essay solicitation
![[daily question] 241 Design priorities for operational expressions](/img/27/4ad1a557e308e4383335f51a51adb0.png)
[daily question] 241 Design priorities for operational expressions
随机推荐
Use graalvm native image to quickly expose jar code as a native shared library
【Hot100】23. Merge K ascending linked lists
After eight years of test experience and interview with 28K company, hematemesis sorted out high-frequency interview questions and answers
For (Auto A: b) and for (Auto & A: b) usage
测试人员如何做不漏测?这7点就够了
API documentation tool knife4j usage details
Exemple complet d'enregistrement du modèle pytoch + enregistrement du modèle pytoch seuls les paramètres d'entraînement sont - ils enregistrés? Oui (+ Solution)
Why do I have a passion for process?
Welfare | Hupu isux11 Anniversary Edition is limited to hand sale!
Solution to blue screen after installing TIA botu V17 in notebook
6 pyspark Library
Research Report on the overall scale, major manufacturers, major regions, products and application segmentation of power management units in the global market in 2022
Want to ask, is there any discount for opening an account now? Is it safe to open an account online?
[kubernetes series] comparison of space and memory usage before and after kubedm reset initialization
Cs5268 perfectly replaces ag9321mcq typec multi in one docking station solution
Research Report on the overall scale, major manufacturers, major regions, products and applications of micro hydraulic cylinders in the global market in 2022
[fluent] dart function (function composition | private function | anonymous function | function summary)
Welfare | Pu Aries | liv heart co branded Plush surrounding new products are on the market!
接口测试到底怎么做?看完这篇文章就能清晰明了
At compilation environment setup -win