Skip to content

Commit c8d0ead

Browse files
committed
update
1 parent c2b85f9 commit c8d0ead

4 files changed

Lines changed: 181 additions & 0 deletions

File tree

Lines changed: 104 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,104 @@
1+
# Crypto - 066
2+
3+
:::note
4+
5+
created by || kerszi
6+
7+
⏲️ Release Date // 2024-03-10
8+
9+
💀 Solvers // 30
10+
11+
🧩 Type // crypto
12+
13+
:::
14+
15+
## 题目信息
16+
17+
```plaintext
18+
5Zub5YWrIOWFreS4iSDlha3kupQg5LqUZsO6IOWFreWbmyDlha3kuZ0g5LiD5LqMCuWbm2TEqyDl
19+
ha3kuZ0g5YWt5LqUIOS4g+WbmyDlha3kupQg5YWtxJMgIOWFreS5nQrkupTlha0g5YWt5LiAIOS4
20+
g+WbmyDlha1mw7og5YWt5LiAIOWFreS6lCDlha3kupQK5LiDYsSrIOWFrWPEqyDlha3kuZ0g5LqU
21+
ZsO6IOS4g+S6jCDkuIPkuIkg5YWtxJMgCuS6lOS4iSDkupRmw7og5YWtxJMgIOWFrWTEqyDkupRm
22+
w7og5YWt5LqUIOWFreWbmwrkuIPpm7Yg5YWt5LiDIOWFreS4gyDkuIPkuZ0g5Zub5LiJIOS6lGbD
23+
uiDkuIPkuIkK5YWt5LqUIOS4g+S6jCDkuIPkuIkg5LqUZsO6IOWFreWFqyDlha3lha0g5LiDZMSr
24+
Cg==
25+
```
26+
27+
## 解题
28+
29+
首先先进行 Base64 解码
30+
31+
```plaintext
32+
四八 六三 六五 五fú 六四 六九 七二
33+
四dī 六九 六五 七四 六五 六ē 六九
34+
五六 六一 七四 六fú 六一 六五 六五
35+
七bī 六cī 六九 五fú 七二 七三 六ē
36+
五三 五fú 六ē 六dī 五fú 六五 六四
37+
七零 六七 六七 七九 四三 五fú 七三
38+
六五 七二 七三 五fú 六八 六六 七dī
39+
```
40+
41+
盲猜一下,中文数字转阿拉伯数字,后面的音标转正常字母之后取第一位
42+
43+
```python
44+
import base64
45+
import string
46+
47+
data = (
48+
"""
49+
5Zub5YWrIOWFreS4iSDlha3kupQg5LqUZsO6IOWFreWbmyDlha3kuZ0g5LiD5LqMCuWbm2TEqyDl ha3kuZ0g5YWt5LqUIOS4g+WbmyDlha3kupQg5YWtxJMgIOWFreS5nQrkupTlha0g5YWt5LiAIOS4 g+WbmyDlha1mw7og5YWt5LiAIOWFreS6lCDlha3kupQK5LiDYsSrIOWFrWPEqyDlha3kuZ0g5LqU ZsO6IOS4g+S6jCDkuIPkuIkg5YWtxJMgCuS6lOS4iSDkupRmw7og5YWtxJMgIOWFrWTEqyDkupRm w7og5YWt5LqUIOWFreWbmwrkuIPpm7Yg5YWt5LiDIOWFreS4gyDkuIPkuZ0g5Zub5LiJIOS6lGbD uiDkuIPkuIkK5YWt5LqUIOS4g+S6jCDkuIPkuIkg5LqUZsO6IOWFreWFqyDlha3lha0g5LiDZMSr Cg==
50+
""".replace(
51+
" ", ""
52+
)
53+
.replace("\n", "")
54+
.replace("\r", "")
55+
)
56+
57+
data = base64.b64decode(data).decode("utf-8")
58+
59+
data = data.replace("\n", " ").split(" ")
60+
data = [item.strip() for item in data if item]
61+
62+
63+
# 中文数字与阿拉伯数字转换
64+
def convert_chinese_to_arabic(input):
65+
chinese_to_arabic = {
66+
"": "0",
67+
"": "1",
68+
"": "2",
69+
"": "3",
70+
"": "4",
71+
"": "5",
72+
"": "6",
73+
"": "7",
74+
"": "8",
75+
"": "9",
76+
"ē": "e",
77+
}
78+
arabic_str = ""
79+
for i in input:
80+
if i in chinese_to_arabic.keys():
81+
arabic_str += chinese_to_arabic[i]
82+
elif i in string.ascii_letters or i in string.digits:
83+
arabic_str += i
84+
else:
85+
continue
86+
return arabic_str
87+
88+
89+
data = [convert_chinese_to_arabic(item) for item in data]
90+
data = [chr(int(i, 16)) for i in data]
91+
92+
offset = 7
93+
for i in range(10):
94+
index = i
95+
while index < len(data):
96+
print(data[index], end="")
97+
index += offset
98+
```
99+
100+
运行即可得到结果
101+
102+
```flag
103+
HMV{Special_greetings_to_my_dear_Chinese_friends}
104+
```
Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,27 @@
1+
# Gear
2+
3+
:::info
4+
5+
场景介绍
6+
7+
> 设计精妙的齿轮
8+
>
9+
> - 综合场景
10+
> - Evasion
11+
> - 权限提升
12+
> - 域渗透
13+
> - 信息收集
14+
> - 横向移动
15+
16+
:::
17+
18+
## 入口点
19+
20+
```plaintext
21+
http://www.my.cs1ab.com
22+
```
23+
24+
## 入口点 - 信息收集
25+
26+
```bash
27+
```
603 KB
Loading
Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
# PRIV-7
2+
3+
:::info
4+
5+
靶标介绍:
6+
7+
> web 渗透提权
8+
>
9+
> - getshell
10+
> - 提权
11+
12+
:::
13+
14+
## 入口点
15+
16+
```plaintext
17+
192.168.111.200
18+
```
19+
20+
## 入口点 - 信息收集
21+
22+
```bash
23+
┌──(randark㉿kali)-[~]
24+
└─$ sudo ./tools/fscan-1.8.4/fscan -h 192.168.111.200
25+
26+
___ _
27+
/ _ \ ___ ___ _ __ __ _ ___| | __
28+
/ /_\/____/ __|/ __| '__/ _` |/ __| |/ /
29+
/ /_\\_____\__ \ (__| | | (_| | (__| <
30+
\____/ |___/\___|_| \__,_|\___|_|\_\
31+
fscan version: 1.8.4
32+
start infoscan
33+
192.168.111.200:22 open
34+
192.168.111.200:80 open
35+
[*] alive ports len is: 2
36+
start vulscan
37+
[*] WebTitle http://192.168.111.200 code:200 len:267 title:None
38+
```
39+
40+
## Web Service
41+
42+
尝试直接访问
43+
44+
![img](img/image_20250444-124458.png)
45+
46+
可以查询到极致 CMS 的漏洞信息
47+
48+
[PeiQi-WIKI-POC/PeiQi\_Wiki/CMS 漏洞 / 极致 CMS/README.md at master・Arinue/PeiQi-WIKI-POC](https://github.com/Arinue/PeiQi-WIKI-POC/blob/master/PeiQi_Wiki/CMS%E6%BC%8F%E6%B4%9E/%E6%9E%81%E8%87%B4CMS/README.md)
49+
50+
TODO 未完成

0 commit comments

Comments
 (0)