๋ฐ์ํ
https://dreamhack.io/wargame/challenges/872
64se64
Description "Welcome! ๐"์ ์ถ๋ ฅํ๋ html ํ์ด์ง์ ๋๋ค. ์์ค ์ฝ๋๋ฅผ ํ์ธํ์ฌ ๋ฌธ์ ๋ฅผ ํ๊ณ ํ๋๊ทธ๋ฅผ ํ๋ํ์ธ์. ํ๋๊ทธ ํ์์ DH{...} ์ ๋๋ค.
dreamhack.io

๋ต
ํ์ผ์ ๋ค์ด ๋ฐ๊ณ ์ด๋ฉด

์ด๋ฐ ์ฐฝ์ด ๋จ๋๋ฐ ์ฌ๊ธฐ์ ์์ค์ฝ๋๋ฅผ ๋ณธ๋ค.
<!doctype html>
<html>
<head>
<meta charset="utf-8">
<title>Welcome</title>
</head>
<body>
<h1>Welcome! ??</h1>
<form method="POST">
<input type="hidden" name="64se64_encoding" value="IyEvdXNyL2Jpbi9lbnYgcHl0aG9uMwphc2M9WzY4LCA3MiwgMTIzLCA5OCwgMTAxLCA0OCwgNTIsIDU0LCA5OCwgNTUsIDUzLCA1MCwgNTAsIDk3LCA5NywgNTAsIDEwMSwgNTAsIDU2LCAxMDIsIDUwLCA1NSwgNTQsIDEwMSwgNDgsIDk5LCA1NywgNDksIDQ4LCA1MywgNTAsIDQ5LCAxMDIsIDUwLCA1MSwgOTcsIDQ4LCA1MywgNTYsIDU1LCA0OCwgNDgsIDUzLCA5NywgNTYsIDUxLCA1NSwgNTUsIDUxLCA1NSwgNDgsIDk3LCA0OSwgNDksIDEwMSwgNTMsIDEwMSwgNTIsIDEwMCwgOTksIDQ5LCA1MywgMTAyLCA5OCwgNTAsIDk3LCA5OCwgMTI1XQphcnI9WzAgZm9yIGkgaW4gcmFuZ2UoNjgpXQpmb3IgaSBpbiByYW5nZSgwLDY4KToKICAgIGFycltpXT1jaHIoYXNjW2ldKQpmbGFnPScnLmpvaW4oYXJyKQpwcmludChmbGFnKQ==">
</form>
</body>
</html>
๊ทธ๋ฌ๋ฉด ์ด๋ฐ ์ฝ๋๊ฐ ๋ํ๋๋๋ฐ
์ฌ๊ธฐ์ 'input'์ 'value'๊ฐ์ด 'base64'๋ก ์ธ์ฝ๋ฉ ๋์ด ์จ์ด์๋ค.
์ด๊ฑธ 'base64'๋ก ๋์ฝ๋ฉ ํด์ฃผ๋ฉด
#!/usr/bin/env python3
asc=[68, 72, 123, 98, 101, 48, 52, 54, 98, 55, 53, 50, 50, 97, 97, 50, 101, 50, 56, 102, 50, 55, 54, 101, 48, 99, 57, 49, 48, 53, 50, 49, 102, 50, 51, 97, 48, 53, 56, 55, 48, 48, 53, 97, 56, 51, 55, 55, 51, 55, 48, 97, 49, 49, 101, 53, 101, 52, 100, 99, 49, 53, 102, 98, 50, 97, 98, 125]
arr=[0 for i in range(68)]
for i in range(0,68):
arr[i]=chr(asc[i])
flag=''.join(arr)
print(flag)
์ด๋ฌํ python์ฝ๋๊ฐ ๋์จ๋ค.
์ด ์ฝ๋๋ฅผ ์คํํด์ฃผ๋ฉด ๋ต์ด ๋์จ๋ค.
๋๋ณด๊ธฐ
DH{be046b7522aa2e28f276e0c910521f23a0587005a8377370a11e5e4dc15fb2ab}
๋
๋ฐ์ํ
'hacking > misc' ์นดํ ๊ณ ๋ฆฌ์ ๋ค๋ฅธ ๊ธ
| [Dream hack] dreamhack-tools-cyberchef (0) | 2025.03.03 |
|---|---|
| [Dream hack] Exercise: Welcome-Beginners (0) | 2025.03.03 |
| [Dream hack] blue-whale (0) | 2024.04.14 |
| [Dream hack] Exercise: Docker (0) | 2024.04.14 |
| [Dream hack] Exercise: SSH (0) | 2024.04.12 |