https://dreamhack.io/wargame/challenges/872
64se64
Description "Welcome! π"μ μΆλ ₯νλ html νμ΄μ§μ λλ€. μμ€ μ½λλ₯Ό νμΈνμ¬ λ¬Έμ λ₯Ό νκ³ νλκ·Έλ₯Ό νλνμΈμ. νλκ·Έ νμμ DH{...} μ λλ€.
dreamhack.io
λ¬Έμ
"Welcome! π"μ μΆλ ₯νλ html νμ΄μ§μ λλ€.
μμ€ μ½λλ₯Ό νμΈνμ¬ λ¬Έμ λ₯Ό νκ³ νλκ·Έλ₯Ό νλνμΈμ.
νλκ·Έ νμμ DH{...} μ λλ€.
νμ΄
1. λ¬Έμ μμ μ£Όμ΄μ§ μΉμ¬μ΄νΈ μ μλ¬Έμ μμ μ£Όμ΄μ§ μΉν΄νΉ λ¬Έμ μ¬μ΄νΈ μ μ νλ©΄
2. Ctrl+U λλ λ§μ°μ€ μ€λ₯Έμͺ½ ν΄λ¦ ν νμ΄μ§ μμ€λ³΄κΈ° ν΄λ¦<!doctype html> <html> <head> <meta charset="utf-8"> <title>Welcome</title> </head> <body> <h1>Welcome! π</h1> <form method="POST"> <input type="hidden" name="64se64_encoding" value="IyEvdXNyL2Jpbi9lbnYgcHl0aG9uMwphc2M 9WzY4LCA3MiwgMTIzLCA5OCwgMTAxLCA0OCwgNTIsIDU0LCA5OCwgNTUsIDUzLCA1MCwgNTAsIDk3LCA5NywgN TAsIDEwMSwgNTAsIDU2LCAxMDIsIDUwLCA1NSwgNTQsIDEwMSwgNDgsIDk5LCA1NywgNDksIDQ4LCA1MywgNTA sIDQ5LCAxMDIsIDUwLCA1MSwgOTcsIDQ4LCA1MywgNTYsIDU1LCA0OCwgNDgsIDUzLCA5NywgNTYsIDUxLCA1NS wgNTUsIDUxLCA1NSwgNDgsIDk3LCA0OSwgNDksIDEwMSwgNTMsIDEwMSwgNTIsIDEwMCwgOTksIDQ5LCA1MywgMT AyLCA5OCwgNTAsIDk3LCA5OCwgMTI1XQphcnI9WzAgZm9yIGkgaW4gcmFuZ2UoNjgpXQpmb3IgaSBpbiByYW5nZS gwLDY4KToKICAgIGFycltpXT1jaHIoYXNjW2ldKQpmbGFnPScnLmpvaW4oYXJyKQpwcmludChmbGFnKQ=="> </form> </body> </html>
3. value λΆλΆμ base64 λ°©μμΌλ‘ μΈμ½λ© λμ΄μλ μ½λλ₯Ό λμ½λ© μν¨ ν κ²°κ³Ό κ° νμΈ
echo "IyEvdXNyL2Jpbi9lbnYgcHl0aG9uMwphc2M9WzY4LCA3MiwgMTIzLCA5OCwgMTAxLCA0OCwgNTIsIDU0LCA5OCw
gNTUsIDUzLCA1MCwgNTAsIDk3LCA5NywgNTAsIDEwMSwgNTAsIDU2LCAxMDIsIDUwLCA1NSwgNTQsIDEwMSwgNDgsIDk5
LCA1NywgNDksIDQ4LCA1MywgNTAsIDQ5LCAxMDIsIDUwLCA1MSwgOTcsIDQ4LCA1MywgNTYsIDU1LCA0OCwgNDgsIDUzL
CA5NywgNTYsIDUxLCA1NSwgNTUsIDUxLCA1NSwgNDgsIDk3LCA0OSwgNDksIDEwMSwgNTMsIDEwMSwgNTIsIDEwMCwgOT
ksIDQ5LCA1MywgMTAyLCA5OCwgNTAsIDk3LCA5OCwgMTI1XQphcnI9WzAgZm9yIGkgaW4gcmFuZ2UoNjgpXQpmb3IgaSB
pbiByYW5nZSgwLDY4KToKICAgIGFycltpXT1jaHIoYXNjW2ldKQpmbGFnPScnLmpvaW4oYXJyKQpwcmludChmbGFnKQ=="
| base64 --decode > flag
---
cat flag
#!/usr/bin/env python3
asc=[68, 72, 123, 98, 101, 48, 52, 54, 98, 55, 53, 50, 50, 97, 97, 50,
101, 50, 56, 102, 50, 55, 54, 101, 48, 99, 57, 49, 48, 53, 50, 49, 102,
50, 51, 97, 48, 53, 56, 55, 48, 48, 53, 97, 56, 51, 55, 55, 51, 55, 48,
97, 49, 49, 101, 53, 101, 52, 100, 99, 49, 53, 102, 98, 50, 97, 98, 125]
arr=[0 for i in range(68)]
for i in range(0,68):
arr[i]=chr(asc[i])
flag=''.join(arr)
print(flag)
μΆλ ₯ κ²°κ³Όλ¬Ό νμΈ μ python μ½λκ° μΆλ ₯λλ κ²μ λ³Ό μ μλ€.
4. λμ½λ©ν μΆλ ₯ κ²°κ³Όλ¬Ό python μΌλ‘ μ€ν
python flag
DH{be046b7522aa2e28f276e0c910521f23a0587005a8377370a11e5e4dc15fb2ab}
DH{..} νμμ νλκ·Έ μΆλ ₯
'Dreamhack' μΉ΄ν κ³ λ¦¬μ λ€λ₯Έ κΈ
[Dreamhack] cookie Write-Up (1) | 2024.03.16 |
---|---|
[Dreamhack] phpreq Write-Up (2) | 2024.03.15 |
[Dreamhack] ex-req-ex Write-Up (2) | 2024.03.15 |
[Dreamhack] blue-whale Write-Up (3) | 2024.03.15 |
[Dreamhack] baby-linux Write-Up (1) | 2024.03.14 |