File tree Expand file tree Collapse file tree
HackMyVM/Challenges/Crypto
Independent-Environment/CyberStrikeLab Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1+ # Crypto - 066
2+
3+ ::: note
4+
5+ created by || kerszi
6+
7+ ⏲️ Release Date // 2024-03-10
8+
9+ 💀 Solvers // 30
10+
11+ 🧩 Type // crypto
12+
13+ :::
14+
15+ ## 题目信息
16+
17+ ``` plaintext
18+ 5Zub5YWrIOWFreS4iSDlha3kupQg5LqUZsO6IOWFreWbmyDlha3kuZ0g5LiD5LqMCuWbm2TEqyDl
19+ ha3kuZ0g5YWt5LqUIOS4g+WbmyDlha3kupQg5YWtxJMgIOWFreS5nQrkupTlha0g5YWt5LiAIOS4
20+ g+WbmyDlha1mw7og5YWt5LiAIOWFreS6lCDlha3kupQK5LiDYsSrIOWFrWPEqyDlha3kuZ0g5LqU
21+ ZsO6IOS4g+S6jCDkuIPkuIkg5YWtxJMgCuS6lOS4iSDkupRmw7og5YWtxJMgIOWFrWTEqyDkupRm
22+ w7og5YWt5LqUIOWFreWbmwrkuIPpm7Yg5YWt5LiDIOWFreS4gyDkuIPkuZ0g5Zub5LiJIOS6lGbD
23+ uiDkuIPkuIkK5YWt5LqUIOS4g+S6jCDkuIPkuIkg5LqUZsO6IOWFreWFqyDlha3lha0g5LiDZMSr
24+ Cg==
25+ ```
26+
27+ ## 解题
28+
29+ 首先先进行 Base64 解码
30+
31+ ``` plaintext
32+ 四八 六三 六五 五fú 六四 六九 七二
33+ 四dī 六九 六五 七四 六五 六ē 六九
34+ 五六 六一 七四 六fú 六一 六五 六五
35+ 七bī 六cī 六九 五fú 七二 七三 六ē
36+ 五三 五fú 六ē 六dī 五fú 六五 六四
37+ 七零 六七 六七 七九 四三 五fú 七三
38+ 六五 七二 七三 五fú 六八 六六 七dī
39+ ```
40+
41+ 盲猜一下,中文数字转阿拉伯数字,后面的音标转正常字母之后取第一位
42+
43+ ``` python
44+ import base64
45+ import string
46+
47+ data = (
48+ """
49+ 5Zub5YWrIOWFreS4iSDlha3kupQg5LqUZsO6IOWFreWbmyDlha3kuZ0g5LiD5LqMCuWbm2TEqyDl ha3kuZ0g5YWt5LqUIOS4g+WbmyDlha3kupQg5YWtxJMgIOWFreS5nQrkupTlha0g5YWt5LiAIOS4 g+WbmyDlha1mw7og5YWt5LiAIOWFreS6lCDlha3kupQK5LiDYsSrIOWFrWPEqyDlha3kuZ0g5LqU ZsO6IOS4g+S6jCDkuIPkuIkg5YWtxJMgCuS6lOS4iSDkupRmw7og5YWtxJMgIOWFrWTEqyDkupRm w7og5YWt5LqUIOWFreWbmwrkuIPpm7Yg5YWt5LiDIOWFreS4gyDkuIPkuZ0g5Zub5LiJIOS6lGbD uiDkuIPkuIkK5YWt5LqUIOS4g+S6jCDkuIPkuIkg5LqUZsO6IOWFreWFqyDlha3lha0g5LiDZMSr Cg==
50+ """ .replace(
51+ " " , " "
52+ )
53+ .replace(" \n " , " " )
54+ .replace(" \r " , " " )
55+ )
56+
57+ data = base64.b64decode(data).decode(" utf-8" )
58+
59+ data = data.replace(" \n " , " " ).split(" " )
60+ data = [item.strip() for item in data if item]
61+
62+
63+ # 中文数字与阿拉伯数字转换
64+ def convert_chinese_to_arabic (input ):
65+ chinese_to_arabic = {
66+ " 零" : " 0" ,
67+ " 一" : " 1" ,
68+ " 二" : " 2" ,
69+ " 三" : " 3" ,
70+ " 四" : " 4" ,
71+ " 五" : " 5" ,
72+ " 六" : " 6" ,
73+ " 七" : " 7" ,
74+ " 八" : " 8" ,
75+ " 九" : " 9" ,
76+ " ē" : " e" ,
77+ }
78+ arabic_str = " "
79+ for i in input :
80+ if i in chinese_to_arabic.keys():
81+ arabic_str += chinese_to_arabic[i]
82+ elif i in string.ascii_letters or i in string.digits:
83+ arabic_str += i
84+ else :
85+ continue
86+ return arabic_str
87+
88+
89+ data = [convert_chinese_to_arabic(item) for item in data]
90+ data = [chr (int (i, 16 )) for i in data]
91+
92+ offset = 7
93+ for i in range (10 ):
94+ index = i
95+ while index < len (data):
96+ print (data[index], end = " " )
97+ index += offset
98+ ```
99+
100+ 运行即可得到结果
101+
102+ ``` flag
103+ HMV{Special_greetings_to_my_dear_Chinese_friends}
104+ ```
Original file line number Diff line number Diff line change 1+ # Gear
2+
3+ ::: info
4+
5+ 场景介绍
6+
7+ > 设计精妙的齿轮
8+ >
9+ > - 综合场景
10+ > - Evasion
11+ > - 权限提升
12+ > - 域渗透
13+ > - 信息收集
14+ > - 横向移动
15+
16+ :::
17+
18+ ## 入口点
19+
20+ ``` plaintext
21+ http://www.my.cs1ab.com
22+ ```
23+
24+ ## 入口点 - 信息收集
25+
26+ ``` bash
27+ ```
Original file line number Diff line number Diff line change 1+ # PRIV-7
2+
3+ ::: info
4+
5+ 靶标介绍:
6+
7+ > web 渗透提权
8+ >
9+ > - getshell
10+ > - 提权
11+
12+ :::
13+
14+ ## 入口点
15+
16+ ``` plaintext
17+ 192.168.111.200
18+ ```
19+
20+ ## 入口点 - 信息收集
21+
22+ ``` bash
23+ ┌──(randark㉿kali)-[~]
24+ └─$ sudo ./tools/fscan-1.8.4/fscan -h 192.168.111.200
25+
26+ ___ _
27+ / _ \ ___ ___ _ __ __ _ ___| | __
28+ / /_\/ ____/ __| / __| ' __/ _` |/ __| |/ /
29+ / /_\\_____\__ \ (__| | | (_| | (__| <
30+ \____/ |___/\___|_| \__,_|\___|_|\_\
31+ fscan version: 1.8.4
32+ start infoscan
33+ 192.168.111.200:22 open
34+ 192.168.111.200:80 open
35+ [*] alive ports len is: 2
36+ start vulscan
37+ [*] WebTitle http://192.168.111.200 code:200 len:267 title:None
38+ ```
39+
40+ ## Web Service
41+
42+ 尝试直接访问
43+
44+ 
45+
46+ 可以查询到极致 CMS 的漏洞信息
47+
48+ [PeiQi-WIKI-POC/PeiQi\_Wiki/CMS 漏洞 / 极致 CMS/README.md at master・Arinue/PeiQi-WIKI-POC](https://github.com/Arinue/PeiQi-WIKI-POC/blob/master/PeiQi_Wiki/CMS%E6%BC%8F%E6%B4%9E/%E6%9E%81%E8%87%B4CMS/README.md)
49+
50+ TODO 未完成
You can’t perform that action at this time.
0 commit comments