<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>与佛论禅 on 知识带给我们自由</title>
    <link>https://yuexuan521.github.io/zh/tags/%E4%B8%8E%E4%BD%9B%E8%AE%BA%E7%A6%85/</link>
    <description>Recent content in 与佛论禅 on 知识带给我们自由</description>
    <image>
      <title>知识带给我们自由</title>
      <url>https://yuexuan521.github.io/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</url>
      <link>https://yuexuan521.github.io/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</link>
    </image>
    <generator>Hugo -- 0.160.1</generator>
    <language>en-us</language>
    <copyright>See this site&amp;rsquo;s source code here, licensed under GPLv3 ·</copyright>
    <lastBuildDate>Tue, 12 Aug 2025 00:15:46 +0000</lastBuildDate>
    <atom:link href="https://yuexuan521.github.io/zh/tags/%E4%B8%8E%E4%BD%9B%E8%AE%BA%E7%A6%85/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>BUUCTF [GXYCTF2019]佛系青年 1</title>
      <link>https://yuexuan521.github.io/zh/posts/buuctf-gxyctf2019%E4%BD%9B%E7%B3%BB%E9%9D%92%E5%B9%B4-1/</link>
      <pubDate>Tue, 12 Aug 2025 00:15:46 +0000</pubDate>
      <guid>https://yuexuan521.github.io/zh/posts/buuctf-gxyctf2019%E4%BD%9B%E7%B3%BB%E9%9D%92%E5%B9%B4-1/</guid>
      <description>&lt;p&gt;
&lt;div class=&#34;post-img-view&#34;&gt;
    &lt;a data-fancybox=&#34;gallery&#34; href=&#34;https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191216628.png&#34;&gt;
        &lt;img src=&#34;https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191216628.png&#34; 
             alt=&#34;&#34; 
              
             loading=&#34;lazy&#34;
        /&gt;
    &lt;/a&gt;
&lt;/div&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;BUUCTF: &lt;a href=&#34;https://buuoj.cn/challenges&#34;target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;https://buuoj.cn/challenges&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;相关阅读
&lt;a href=&#34;https://ctf-wiki.org/&#34;target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;CTF Wiki&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;
&lt;div class=&#34;post-img-view&#34;&gt;
    &lt;a data-fancybox=&#34;gallery&#34; href=&#34;https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191219294.png&#34;&gt;
        &lt;img src=&#34;https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191219294.png&#34; 
             alt=&#34;在这里插入图片描述&#34; 
              
             loading=&#34;lazy&#34;
        /&gt;
    &lt;/a&gt;
&lt;/div&gt;&lt;/p&gt;
&lt;h3 id=&#34;题目描述&#34;&gt;题目描述：&lt;/h3&gt;
&lt;p&gt;得到的 flag 请包上 flag{} 提交&lt;/p&gt;
&lt;h3 id=&#34;密文&#34;&gt;密文：&lt;/h3&gt;
&lt;p&gt;下载附件，解压得到ZIP压缩包。&lt;/p&gt;
&lt;p&gt;
&lt;div class=&#34;post-img-view&#34;&gt;
    &lt;a data-fancybox=&#34;gallery&#34; href=&#34;https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191221432.png&#34;&gt;
        &lt;img src=&#34;https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191221432.png&#34; 
             alt=&#34;在这里插入图片描述&#34; 
              
             loading=&#34;lazy&#34;
        /&gt;
    &lt;/a&gt;
&lt;/div&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id=&#34;解题思路&#34;&gt;解题思路：&lt;/h3&gt;
&lt;p&gt;1、压缩包内有一张png图片和一个txt文本，解压zip压缩包，解压出图片，但txt文本提示需要输入密码。

&lt;div class=&#34;post-img-view&#34;&gt;
    &lt;a data-fancybox=&#34;gallery&#34; href=&#34;https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191222835.png&#34;&gt;
        &lt;img src=&#34;https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191222835.png&#34; 
             alt=&#34;在这里插入图片描述&#34; 
              
             loading=&#34;lazy&#34;
        /&gt;
    &lt;/a&gt;
&lt;/div&gt;&lt;/p&gt;</description>
      <content:encoded><![CDATA[<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191216628.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191216628.png" 
             alt="" 
              
             loading="lazy"
        />
    </a>
</div></p>
<p><strong>BUUCTF: <a href="https://buuoj.cn/challenges"target="_blank" rel="noopener noreferrer">https://buuoj.cn/challenges</a></strong></p>
<hr>
<p>相关阅读
<a href="https://ctf-wiki.org/"target="_blank" rel="noopener noreferrer">CTF Wiki</a></p>
<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191219294.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191219294.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<h3 id="题目描述">题目描述：</h3>
<p>得到的 flag 请包上 flag{} 提交</p>
<h3 id="密文">密文：</h3>
<p>下载附件，解压得到ZIP压缩包。</p>
<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191221432.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191221432.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<hr>
<h3 id="解题思路">解题思路：</h3>
<p>1、压缩包内有一张png图片和一个txt文本，解压zip压缩包，解压出图片，但txt文本提示需要输入密码。

<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191222835.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191222835.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<p>解压出的png图片</p>
<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191358437.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191358437.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191400614.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191400614.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<p>2、压缩包内有两个文件，而且已经解压出了一个文件，我猜测为zip压缩包明文攻击，但后面没有成功解出密码。看过别人的题解之后，发现原来是zip伪加密。
通过010Editor修改压缩源文件数据区和目录区的全局方式位标记（下图红色标识），将伪压缩文件恢复到未加密的状态。</p>
<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191402433.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191402433.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<p>保存文件，解压得到fo.txt文件。

<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191404239.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191404239.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span><span class="lnt">11
</span><span class="lnt">12
</span><span class="lnt">13
</span><span class="lnt">14
</span><span class="lnt">15
</span><span class="lnt">16
</span><span class="lnt">17
</span><span class="lnt">18
</span><span class="lnt">19
</span><span class="lnt">20
</span><span class="lnt">21
</span><span class="lnt">22
</span><span class="lnt">23
</span><span class="lnt">24
</span><span class="lnt">25
</span><span class="lnt">26
</span><span class="lnt">27
</span><span class="lnt">28
</span><span class="lnt">29
</span><span class="lnt">30
</span><span class="lnt">31
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">                                                                      _ooOoo_
</span></span><span class="line"><span class="cl">                                                                     o8888888o
</span></span><span class="line"><span class="cl">                                                                     88<span class="s2">&#34; . &#34;</span><span class="m">88</span>
</span></span><span class="line"><span class="cl">                                                                     <span class="o">(</span><span class="p">|</span> -_- <span class="p">|</span><span class="o">)</span>
</span></span><span class="line"><span class="cl">                                                                      O<span class="se">\ </span><span class="o">=</span> /O
</span></span><span class="line"><span class="cl">                                                                  ____/<span class="sb">`</span>---<span class="s1">&#39;\____
</span></span></span><span class="line"><span class="cl"><span class="s1">                                                                .   &#39;</span> <span class="se">\\</span><span class="p">|</span> <span class="p">|</span>// <span class="sb">`</span>.
</span></span><span class="line"><span class="cl">                                                                 / <span class="se">\\</span><span class="o">||</span><span class="p">|</span> : <span class="o">||</span><span class="p">|</span>// <span class="se">\
</span></span></span><span class="line"><span class="cl">                                                               / _<span class="o">||||</span><span class="p">|</span> -:- <span class="o">||||</span><span class="p">|</span>- <span class="se">\
</span></span></span><span class="line"><span class="cl">                                                                 <span class="p">|</span> <span class="p">|</span> <span class="se">\\\ </span>- /// <span class="p">|</span> <span class="p">|</span>
</span></span><span class="line"><span class="cl">                                                               <span class="p">|</span> <span class="se">\_</span><span class="p">|</span> <span class="s1">&#39;&#39;</span><span class="se">\-</span>--/<span class="s1">&#39;&#39;</span> <span class="p">|</span> <span class="p">|</span>
</span></span><span class="line"><span class="cl">                                                                <span class="se">\ </span>.-<span class="se">\_</span>_ <span class="sb">`</span>-<span class="sb">`</span> ___/-. /
</span></span><span class="line"><span class="cl">                                                             ___<span class="sb">`</span>. .<span class="s1">&#39; /--.--\ `. . __
</span></span></span><span class="line"><span class="cl"><span class="s1">                                                          .&#34;&#34; &#39;</span>&lt; <span class="sb">`</span>.___<span class="se">\_</span>&lt;<span class="p">|</span>&gt;_/___.<span class="s1">&#39; &gt;&#39;</span><span class="s2">&#34;&#34;</span>.
</span></span><span class="line"><span class="cl">                                                         <span class="p">|</span> <span class="p">|</span> : <span class="sb">`</span>- <span class="se">\`</span>.<span class="p">;</span><span class="sb">`</span><span class="se">\ </span>_ /<span class="sb">`</span><span class="p">;</span>.<span class="sb">`</span>/ - <span class="sb">`</span> : <span class="p">|</span> <span class="p">|</span>
</span></span><span class="line"><span class="cl">                                                           <span class="se">\ \ </span><span class="sb">`</span>-. <span class="se">\_</span> __<span class="se">\ </span>/__ _/ .-<span class="sb">`</span> / /
</span></span><span class="line"><span class="cl">                                                   <span class="o">======</span><span class="sb">`</span>-.____<span class="sb">`</span>-.___<span class="se">\_</span>____/___.-<span class="sb">`</span>____.-<span class="s1">&#39;======
</span></span></span><span class="line"><span class="cl"><span class="s1">                                                                      `=---=&#39;</span>            
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">                                                   .............................................
</span></span><span class="line"><span class="cl">                                                          佛祖保佑             永无BUG
</span></span><span class="line"><span class="cl">                                                          写字楼里写字间，写字间里程序员；
</span></span><span class="line"><span class="cl">                                                          程序人员写程序，又拿程序换酒钱。
</span></span><span class="line"><span class="cl">                                                          酒醒只在网上坐，酒醉还来网下眠；
</span></span><span class="line"><span class="cl">                                                          酒醉酒醒日复日，网上网下年复年。
</span></span><span class="line"><span class="cl">                                                          但愿老死电脑间，不愿鞠躬老板前；
</span></span><span class="line"><span class="cl">                                                          奔驰宝马贵者趣，公交自行程序员。
</span></span><span class="line"><span class="cl">                                                          别人笑我忒疯癫，我笑自己命太贱；
</span></span><span class="line"><span class="cl">                                                          不见满街漂亮妹，哪个归得程序员？
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">佛曰：遮等諳勝能礙皤藐哆娑梵迦侄羅哆迦梵者梵楞蘇涅侄室實真缽朋能。奢怛俱道怯都諳怖梵尼怯一罰心缽謹缽薩苦奢夢怯帝梵遠朋陀諳陀穆諳所呐知涅侄以薩怯想夷奢醯數羅怯諸
</span></span></code></pre></td></tr></table>
</div>
</div><p>3、打开fo.txt文件，如上图。判断文件底部的那一长串文字，为经过“与佛论禅”加密的密文，通过在线网站解密，得到flag。（这个文本真的爱了！）
<a href="https://ctf.bugku.com/tool/todousharp"target="_blank" rel="noopener noreferrer">与佛论禅密码</a></p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">佛曰：遮等諳勝能礙皤藐哆娑梵迦侄羅哆迦梵者梵楞蘇涅侄室實真缽朋能。奢怛俱道怯都諳怖梵尼怯一罰心缽謹缽薩苦奢夢怯帝梵遠朋陀諳陀穆諳所呐知涅侄以薩怯想夷奢醯數羅怯諸
</span></span></code></pre></td></tr></table>
</div>
</div><p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191406093.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191406093.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<p><strong>更正</strong>
在线网站已经无法使用，可以下载这个工具进行解码。
<a href="https://github.com/qianxiao996/CTF-Tools"target="_blank" rel="noopener noreferrer">https://github.com/qianxiao996/CTF-Tools</a></p>
<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191407660.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228191407660.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<h3 id="flag">flag：</h3>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">flag<span class="o">{</span>w0_fo_ci_Be1<span class="o">}</span>
</span></span></code></pre></td></tr></table>
</div>
</div>]]></content:encoded>
    </item>
  </channel>
</rss>
