[Memlabs] Lab3 - The Evil's Den
·
보안/Forensics
DescriptionA malicious script encrypted a very secret piece of information I had on my system. Can you recover the information for me please?Note-1: This challenge is composed of only 1 flag. The flag split into 2 parts.Note-2: You'll need the first half of the flag to get the second.You will need this additional tool to solve the challenge,$ sudo apt install steghideThe flag format for this lab..
[Memlabs] Lab2 - A New World
·
보안/Forensics
DescriptionOne of the clients of our company, lost the access to his system due to an unknown error. He is supposedly a very popular "environmental" activist. As a part of the investigation, he told us that his go to applications are browsers, his password managers etc. We hope that you can dig into this memory dump and find his important stuff and give it back to us.Note: This challenge is comp..
[MemLabs] Lab1 - Beginner's Luck
·
보안/Forensics
DescriptionMy sister's computer crashed. We were very fortunate to recover this memory dump. Your job is get all her important files from the system. From what we remember, we suddenly saw a black window pop up with some thing being executed. When the crash happened, she was trying to draw something. Thats all we remember from the time of crash.Note: This challenge is composed of 3 flags.https:/..
HACKTHEON SEJONG 2025 Finals Write-up
·
보안/CTF Write-Ups
[Forensics] To Do[!NOTE]문제 파일이 .ad1 확장자로 된 파일로 주어졌기 때문에 FTK Imager를 사용하여 FLAG를 찾을 수 있다.Add Evidence Item... -> Image File -> 문제파일 선택 Finish를 진행하면 왼쪽의 Evidence Tree에 다음과 같이 나타난다.문제 이름에서 추측할 수 있다시피 todo 일정과 관련이 있어 보인다.여기저기 찾다보면 Microsoft Todos 폴더를 찾을 수 있다.하위 디렉토리 LocalState를 타고 쭉 들어가 보면 todosqlite.db 파일이 존재한다.파일을 선택한 후 export files... 로 파일을 추출하여 DB를 확인한다.DB를 확인하기 위해 DB Browser for SQLite 를 사용했다.ta..
[Pwnable.xyz]Welcome
·
보안/Wargame
DescriptionAre you worthy to continue?svc.pwnable.xyz : 30000ProblemSolutionv3 변수를 0x40000 크기만큼 동적할당 한 후 값으로는 1을 넣어준다.마지막 부분에서 v3의 값이 0이면 flag 값을 알아낼 수 있다.size[0]에는 입력한 message length가 들어가고, v4를 "message length"크기 만큼 malloc으로 동적할당한다.그 후, 최대 message length 크기만큼 message를 입력 받아 v4에 넣어준다.v5에 size[0]값을 넣어주고, v4[size[0]-1]에 0을 넣어주는데 이 부분으로 v3을 0으로 만들 수 있음을 추측할 수 있다.어셈블리어로 자세히 보면 다음과 같이 볼 수 있다.v4_addr ..
[Pwnable.kr] bof
·
보안/Wargame
DescriptionNana told me that buffer overflow is one of the most common software vulnerability.Is that true?ssh bof@pwnable.kr -p2222 (pw: guest)Solution bof는 gets함수에서 이루어지고 32바이트를 더미로 채운 후 SFP와 RET 부분도 채우면 key의 주소가 나온다. 32바이트 이상 입력하니 stack smashing이 된다.메모리 보호기법이 걸려있는 듯 하다. DEP, Canary, PIE 보호기법이 걸려있다.overflowme가 32byte였기에 32+8 로 40byte를 더미로 채우고 0xcafebabe를 넣으면 되는 줄 알았는데 gdb로 열어보니 달랐다. 일단, 0x2c를 ..