728x90

 

[๋ฌธ์ œ]

I have been snooping on the conversations of my elusive enemies.

See if you can help me gather the information I need to defeat them once and for all.

 

AngstromCTF 2023 - Admiral Shark: https://2023.angstromctf.com/challenges


[๋ฌธ์ œํ’€์ด]

 

1) tcp.stream eq 1์—์„œ ๊ณง ํŒŒ์ผ์„ ๋ณด๋‚ด๊ฒ ๋‹ค๋Š” ๋ฉ”์‹œ์ง€๋ฅผ ํ™•์ธํ–ˆ์Šต๋‹ˆ๋‹ค.

 

2) ๊ทธ๋ž˜์„œ tcp.stream eq 2๋กœ ๋„˜์–ด๊ฐ€์„œ Raw ํ˜•์‹์œผ๋กœ ๋ณ€ํ™˜ํ•œ ๋’ค ๋ณต์‚ฌํ•ด ์คฌ์Šต๋‹ˆ๋‹ค.

 

3) HxD์— ๋ถ™์—ฌ ๋„ฃ์€ ํ›„ ํŒŒ์ผ ํ—ค๋”๋ฅผ ํ™•์ธํ•ด ๋ณธ ๊ฒฐ๊ณผ JAR ํŒŒ์ผ ํƒ€์ž…์ธ ๊ฑฐ ๊ฐ™๊ณ  ์•ž์— ํ—ค๋”๊ฐ€ ์ง€์›Œ์ ธ์„œ ์กฐ์ž‘๋์Œ์„ ํ™•์ธํ–ˆ์Šต๋‹ˆ๋‹ค.

*ํŒŒ์ผ ์‹œ๊ทธ๋‹ˆ์ฒ˜ ํ™•์ธ: http://forensic-proof.com/archives/300

 

ํŒŒ์ผ ์‹œ๊ทธ๋‹ˆ์ฒ˜ ๋ชจ์Œ (Common File Signatures) | FORENSIC-PROOF

 

forensic-proof.com

 

 

4) 50 4B 03 04๋ฅผ ํŒŒ์ผ ํ—ค๋” ์•ž์— ๋ถ™์—ฌ ๋„ฃ์–ด์ค€ ๋’ค ํŒŒ์ผ ํƒ€์ž…์„ JAR ํƒ€์ž…์œผ๋กœ ํ•ด์„œ ์ €์žฅํ•ด ์คฌ์Šต๋‹ˆ๋‹ค.

 

5) JAR ํŒŒ์ผ์„ ์••์ถ•์„ ํ•ด์ œํ•ด ์ฃผ๊ณ  ํด๋”๋ฅผ ๋‹ค ํ™•์ธํ•ด ๋ดค์Šต๋‹ˆ๋‹ค.

 

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<sst xmlns="http://schemas.openxmlformats.org/spreadsheetml/2006/main" count="2" uniqueCount="2"><si><t>flag</t></si><si><t>actf{wireshark_in_space}</t></si></sst>
 

6) sharedStrings.xml ํŒŒ์ผ์—์„œ ํ”Œ๋ž˜๊ทธ actf{wireshark_in_space}๋ฅผ ํš๋“ํ–ˆ์Šต๋‹ˆ๋‹ค!

 

'๋ณด์•ˆ > CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[ํฌ๋ Œ์‹] XCZ-PROB13  (0) 2024.08.20
[ํฌ๋ Œ์‹] CTF Academy-Challenge 2  (0) 2024.08.20
[ํฌ๋ Œ์‹] Angstrom CTF 2020-WS2  (1) 2024.08.20
[ํฌ๋ Œ์‹] Angstrom CTF 2022-Shark 2  (0) 2024.08.20
[ํฌ๋ Œ์‹] Angstrom CTF 2022-Shark 1  (0) 2024.08.20

+ Recent posts