0%

Misc·buu刷题记录

Misc·buu题解及工具下载

1. Misc工具–zsteg

·简介

zsteg 是Github上开源的PNGBMP文件隐写爆破工具

·安装

终端依次输入:

1
2
3
git clone https://github.com/zed-0xff/zsteg
cd zsteg/
gem install zsteg

若提示权限不够,终端输入:

1
sudo su

如果下的太慢了,换源终端依次输入:

1
2
3
gem sources --remove https://rubygems.org/
gem sources --add https://gems.ruby-china.com/
gem sources -l

·使用

1
zsteg -a file_path

· 效果图

img

(题源:2021春秋杯秋季赛勇者赛道·Misc·**helloshark

2. Misc工具–foremsot

·简介

同binwalk(Kali自带)功能一样,具有拆分隐藏文件的功能,不同在于自动生成并放入output文件夹中

·安装

终端输入:

1
apt-get install foremost
  • 若提示:
1
E: Unable to fetch some archives, maybe run apt-get update or try with --fix-missing?
  • 则要更新了,输入:
1
apt-get update

最后检查安装是否成功,输入:

1
foremost -h

在这里插入图片描述

·使用

1
foremost file_path

3.Misc·N种方法解决

·题目

下载后得到key.exe

思路

  • 从简到难,string key.exe

data:image/jpg;base64,iVBORw0KGgoAAAANSUhEUgAAAIUAAACFCAYAAAB12js8AAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsMAAA7DAcdvqGQAAArZSURBVHhe7ZKBitxIFgTv/396Tx564G1UouicKg19hwPCDcrMJ9m7/7n45zfdxe5Z3sJ7prHbf9rXO3P4lLvYPctbeM80dvtP+3pnDp9yF7tneQvvmcZu/2lf78zhU+5i9yxv4T3T2O0/7eud68OT2H3LCft0l/ae9ZlTo+23pPvX7/rwJHbfcsI+3aW9Z33m1Gj7Len+9bs+PIndt5ywT3dp71mfOTXafku6f/2uD09i9y0n7NNd2nvWZ06Ntt+S7l+/68MJc5O0OSWpcyexnFjfcsI+JW1ukpRfv+vDCXOTtDklqXMnsZxY33LCPiVtbpKUX7/rwwlzk7Q5JalzJ7GcWN9ywj4lbW6SlF+/68MJc5O0OSWpcyexnFjfcsI+JW1ukpRfv+vDCXOTWE7a/i72PstJ2zfsHnOTpPz6XR9OmJvEctL2d7H3WU7avmH3mJsk5dfv+nDC3CSWk7a/i73PctL2DbvH3CQpv37XhxPmJrGctP1d7H2Wk7Zv2D3mJkn59bs+nDA3ieWEfdNImylJnelp7H6bmyTl1+/6cMLcJJYT9k0jbaYkdaansfttbpKUX7/rwwlzk1hO2DeNtJmS1Jmexu63uUlSfv2uDyfMTWI5Yd800mZKUmd6Grvf5iZJ+fW7PjzJ7v12b33LSdtvsfuW75LuX7/rw5Ps3m/31rectP0Wu2/5Lun+9bs+PMnu/XZvfctJ22+x+5bvku5fv+vDk+zeb/fWt5y0/Ra7b/ku6f71+++HT0v+5l3+tK935vApyd+8y5/29c4cPiX5m3f5077emcOnJH/zLn/ar3d+/flBpI+cMDeNtJkSywn79BP5uK+yfzTmppE2U2I5YZ9+Ih/3VfaPxtw00mZKLCfs00/k477K/tGYm0baTInlhH36iSxflT78TpI605bdPbF7lhvct54mvWOaWJ6m4Z0kdaYtu3ti9yw3uG89TXrHNLE8TcM7SepMW3b3xO5ZbnDfepr0jmlieZqGd5LUmbbs7onds9zgvvU06R3TxPXcSxPrW07YpyR1pqTNKUmdKUmdk5LUaXzdWB/eYX3LCfuUpM6UtDklqTMlqXNSkjqNrxvrwzusbzlhn5LUmZI2pyR1piR1TkpSp/F1Y314h/UtJ+xTkjpT0uaUpM6UpM5JSeo0ft34+vOGNLqDfUosN7inhvUtJ+ybRtpMd0n39Goa3cE+JZYb3FPD+pYT9k0jbaa7pHt6NY3uYJ8Syw3uqWF9ywn7ppE2013SPb2aRnewT4nlBvfUsL7lhH3TSJvpLunecjWV7mCftqQbjSR1puR03tqSbkx/wrJqj7JPW9KNRpI6U3I6b21JN6Y/YVm1R9mnLelGI0mdKTmdt7akG9OfsKzao+zTlnSjkaTOlJzOW1vSjelPWFbp8NRImylJnWnL7r6F7zN3STcb32FppUNTI22mJHWmLbv7Fr7P3CXdbHyHpZUOTY20mZLUmbbs7lv4PnOXdLPxHZZWOjQ10mZKUmfasrtv4fvMXdLNxndYWunQlFhutHv2W42n+4bds7wl3VuuskSJ5Ua7Z7/VeLpv2D3LW9K95SpLlFhutHv2W42n+4bds7wl3VuuskSJ5Ua7Z7/VeLpv2D3LW9K97avp6GQ334X3KWlz+tukb5j+hO2/hX3Ebr4L71PS5vS3Sd8w/Qnbfwv7iN18F96npM3pb5O+YfoTtv8W9hG7+S68T0mb098mfcP0Jxz/W+x+FPethvUtN2y/m7fwnvm1+frzIOklDdy3Gta33LD9bt7Ce+bX5uvPg6SXNHDfaljfcsP2u3kL75lfm68/D5Je0sB9q2F9yw3b7+YtvGd+bb7+vCEN7ySpMzXSZrqL3bOcsN9Kns4T2uJRk6TO1Eib6S52z3LCfit5Ok9oi0dNkjpTI22mu9g9ywn7reTpPKEtHjVJ6kyNtJnuYvcsJ+y3kqfzxNLiEUosJ+xTYvkudt9yg3tqpM2d5Cf50mKJEssJ+5RYvovdt9zgnhppcyf5Sb60WKLEcsI+JZbvYvctN7inRtrcSX6SLy2WKLGcsE+J5bvYfcsN7qmRNneSn+RLK5UmbW4Sywn7lOzmhH3a0u7ZN99hadmRNjeJ5YR9SnZzwj5taffsm++wtOxIm5vEcsI+Jbs5YZ+2tHv2zXdYWnakzU1iOWGfkt2csE9b2j375jtcvTz+tuX0vrXF9sxNkjrTT+T6rvyx37ac3re22J65SVJn+olc35U/9tuW0/vWFtszN0nqTD+R67vyx37bcnrf2mJ75iZJneknUn+V/aWYUyNtpqTNqZE2UyNtGlvSjTsT9VvtKHNqpM2UtDk10mZqpE1jS7pxZ6J+qx1lTo20mZI2p0baTI20aWxJN+5M1G+1o8ypkTZT0ubUSJupkTaNLenGnYnl6TujO2zP3DTSZkp2c8L+0xppM32HpfWTIxPbMzeNtJmS3Zyw/7RG2kzfYWn95MjE9sxNI22mZDcn7D+tkTbTd1haPzkysT1z00ibKdnNCftPa6TN9B2uXh5/S9rcbEk37jR2+5SkzpSkzo4kdaavTg6/JW1utqQbdxq7fUpSZ0pSZ0eSOtNXJ4ffkjY3W9KNO43dPiWpMyWpsyNJnemrk8NvSZubLenGncZun5LUmZLU2ZGkzvTVWR/e0faJ7Xdzw/bMKbGc7PbNE1x3uqNtn9h+Nzdsz5wSy8lu3zzBdac72vaJ7Xdzw/bMKbGc7PbNE1x3uqNtn9h+Nzdsz5wSy8lu3zzBcsVewpyS1LmTWG7Y3nLCPm1JN05KLP/D8tRGzClJnTuJ5YbtLSfs05Z046TE8j8sT23EnJLUuZNYbtjecsI+bUk3Tkos/8Py1EbMKUmdO4nlhu0tJ+zTlnTjpMTyP/R/i8PwI//fJZYb3Jvv8Pd/il+WWG5wb77D3/8pflliucG9+Q5//6f4ZYnlBvfmO1y9PH7KFttbfhq+zySpMyVtbr7D1cvjp2yxveWn4ftMkjpT0ubmO1y9PH7KFttbfhq+zySpMyVtbr7D1cvjp2yxveWn4ftMkjpT0ubmO1y9ftRg9y0n7FPD+paTtk9O71sT13Mv7WD3LSfsU8P6lpO2T07vWxPXcy/tYPctJ+xTw/qWk7ZPTu9bE9dzL+1g9y0n7FPD+paTtk9O71sT1/P7EnOTWG5wb5LUmRptn3D/6b6+eX04YW4Syw3uTZI6U6PtE+4/3dc3rw8nzE1iucG9SVJnarR9wv2n+/rm9eGEuUksN7g3SepMjbZPuP90X9+8PpwwN0mb72pYfzcn1rf8NHwffXXWhxPmJmnzXQ3r7+bE+pafhu+jr876cMLcJG2+q2H93ZxY3/LT8H301VkfTpibpM13Nay/mxPrW34avo++OuvDCXOT7OZGu7e+5YT9XYnlhH36DlfvfsTcJLu50e6tbzlhf1diOWGfvsPVux8xN8lubrR761tO2N+VWE7Yp+9w9e5HzE2ymxvt3vqWE/Z3JZYT9uk7XL1+1GD3LX8avt8klhu2t5yc6F+/68OT2H3Ln4bvN4nlhu0tJyf61+/68CR23/Kn4ftNYrlhe8vJif71uz48id23/Gn4fpNYbtjecnKif/3+++HTnub0fd4zieUtvLfrO1y9PH7K05y+z3smsbyF93Z9h6uXx095mtP3ec8klrfw3q7vcPXy+ClPc/o+75nE8hbe2/Udzv9X+sv/OP/881/SqtvcdpBh+wAAAABJRU5ErkJggg==

  • 密码手看到base64,兴奋。之后网页解码不给力,用python3跑了下。

    1
    2
    3
    4
    5
    6
    import base64


    b64 = b'iVBORw0KGgoAAAANSUhEUgAAAIUAAACFCAYAAAB12js8AAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsMAAA7DAcdvqGQAAArZSURBVHhe7ZKBitxIFgTv/396Tx564G1UouicKg19hwPCDcrMJ9m7/7n45zfdxe5Z3sJ7prHbf9rXO3P4lLvYPctbeM80dvtP+3pnDp9yF7tneQvvmcZu/2lf78zhU+5i9yxv4T3T2O0/7eud68OT2H3LCft0l/ae9ZlTo+23pPvX7/rwJHbfcsI+3aW9Z33m1Gj7Len......U5ErkJggg=='
    print(base64.b64decode(b64))
    # b'\x89PNG\r\n\x1a\n\x00\x00\x00\rIHDR\x00\x00\x00\x85\x00\x00\x00\x85\x08\x06\x00\x00\x00u\xda;<\x00\x00\x00\x01sRG...\xc2\r\xca\xcc\'\xd9\x...ffi_\xef\xcc\xe1S\xeeb\xf7,o\xe1=\xd3\xd8\xed?\xed\xeb\x9d\....\x7f\x1a\xbe\xdf$\x96\x1b\xb6\xb7\x9c\x9c\xe8_\xbf\xeb\xc3\x93\xd8}\xcb\x9f\x86\xef7\x89\xe5\x86\xed-\'\'\xfa\xd7\xef\xfa\xf0$v\xdf\xf2\xa7\xe1\xfbMb\xb9a{\xcb\xc9\x89\xfe\xf5\xbb><\x89\xdd\xb7\xfci\xf...x00IEND\xaeB`\x82'
  • 看到了PNG,高兴。其后如何也得不到下一步思路,看题解后,开了眼了🤔

  • 将第一步string内容完整复制到网页端,得到二维码,扫码即得flag。

4. Misc·LSB

·题目

题目说的明显,LSB隐写,有过多博客对此解释、教学,在此不赘述

·要点

  • 导出时候记得选 Save Bin

5. ARCHPR 下载|注册

· 提示

若是英文界面,则看大致位置也能完成注册

· 下载

ARCHPR下载链接

· 注册码:

ARCHPRP-GSVMT-66892-GKVMB-52992

· 注册步骤

  1. 下载后解压,打开软件

img

  1. 输入注册码( ARCHPRP-GSVMT-66892-GKVMB-52992 )

    img

  2. 注册完成

    img

· 修改语言

眼瞎找了一宿,option选项卡里选language为简体中文

  • option选项卡

img

  • 语言设置

img

大功告成!

6. BUU·Misc·爱因斯坦

·题解

  • 打开后,看到爱因斯坦图片

  • strings 后看到有东西

  • binwalk -e 拆开

  • 得到flag.txt、加密压缩包

·困惑:

以为是明文攻击,压缩后说文件太小,无法进行明文攻击。

·醍醐灌顶

属性 -> 详细信息 -> 备注 里有东西,可以拿来做压缩包密码的尝试,bingo!

·总结

strings != 属性

7. FLAG

· 题解

打开后binwalk -e,获得29.zilp,没思路了

·醍醐灌顶

LSB藏了ZIP文件,bin下来后解压,以txt打开解压文件,搜索即可

·总结

zsteg的file显示要注重!!!

img

8.D盾安装

· 简介

『D盾_防火墙』专为IIS设计的一个主动防御的保护软件,以内外保护的方式 防止网站和服务器给入侵。用于网页数据文件夹

· 下载

D盾下载

img

·注意事项

虚拟机win需要把待扫描的文件夹放入c盘,总之不要在mac盘

9. RouterPassView 安装

· 简介

RouterPassView是一个找回路由器密码的工具,用于bin后缀文件

· 下载

RouterPassView下载

RouterPassView截图