<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Stegosaurus on 知识带给我们自由</title>
    <link>https://yuexuan521.github.io/zh/tags/stegosaurus/</link>
    <description>Recent content in Stegosaurus on 知识带给我们自由</description>
    <image>
      <title>知识带给我们自由</title>
      <url>https://yuexuan521.github.io/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</url>
      <link>https://yuexuan521.github.io/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</link>
    </image>
    <generator>Hugo -- 0.160.1</generator>
    <language>en-us</language>
    <copyright>See this site&amp;rsquo;s source code here, licensed under GPLv3 ·</copyright>
    <lastBuildDate>Mon, 13 Jan 2025 08:30:00 +0000</lastBuildDate>
    <atom:link href="https://yuexuan521.github.io/zh/tags/stegosaurus/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>BUUCTF [ACTF新生赛2020]剑龙 1</title>
      <link>https://yuexuan521.github.io/zh/posts/buuctf-actf%E6%96%B0%E7%94%9F%E8%B5%9B2020%E5%89%91%E9%BE%99-1/</link>
      <pubDate>Mon, 13 Jan 2025 08:30:00 +0000</pubDate>
      <guid>https://yuexuan521.github.io/zh/posts/buuctf-actf%E6%96%B0%E7%94%9F%E8%B5%9B2020%E5%89%91%E9%BE%99-1/</guid>
      <description>&lt;p&gt;
&lt;div class=&#34;post-img-view&#34;&gt;
    &lt;a data-fancybox=&#34;gallery&#34; href=&#34;https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190557074.png&#34;&gt;
        &lt;img src=&#34;https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190557074.png&#34; 
             alt=&#34;&#34; 
              
             loading=&#34;lazy&#34;
        /&gt;
    &lt;/a&gt;
&lt;/div&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;BUUCTF: &lt;a href=&#34;https://buuoj.cn/challenges&#34;target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;https://buuoj.cn/challenges&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;相关阅读
&lt;a href=&#34;https://ctf-wiki.org/&#34;target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;CTF Wiki&lt;/a&gt;
&lt;a href=&#34;https://hello-ctf.com/HC_Start/&#34;target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Hello CTF&lt;/a&gt;
&lt;a href=&#34;https://ns.openctf.net/learn/&#34;target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;NewStar CTF&lt;/a&gt;
&lt;a href=&#34;https://blog.csdn.net/pone2233/article/details/108601733&#34;target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;BuuCTF难题详解| Misc | [ACTF新生赛2020]剑龙&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;
&lt;div class=&#34;post-img-view&#34;&gt;
    &lt;a data-fancybox=&#34;gallery&#34; href=&#34;https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190559563.png&#34;&gt;
        &lt;img src=&#34;https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190559563.png&#34; 
             alt=&#34;在这里插入图片描述&#34; 
              
             loading=&#34;lazy&#34;
        /&gt;
    &lt;/a&gt;
&lt;/div&gt;&lt;/p&gt;
&lt;h3 id=&#34;题目描述&#34;&gt;题目描述：&lt;/h3&gt;
&lt;p&gt;得到的 flag 请包上 flag{} 提交。&lt;/p&gt;</description>
      <content:encoded><![CDATA[<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190557074.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190557074.png" 
             alt="" 
              
             loading="lazy"
        />
    </a>
</div></p>
<p><strong>BUUCTF: <a href="https://buuoj.cn/challenges"target="_blank" rel="noopener noreferrer">https://buuoj.cn/challenges</a></strong></p>
<hr>
<p>相关阅读
<a href="https://ctf-wiki.org/"target="_blank" rel="noopener noreferrer">CTF Wiki</a>
<a href="https://hello-ctf.com/HC_Start/"target="_blank" rel="noopener noreferrer">Hello CTF</a>
<a href="https://ns.openctf.net/learn/"target="_blank" rel="noopener noreferrer">NewStar CTF</a>
<a href="https://blog.csdn.net/pone2233/article/details/108601733"target="_blank" rel="noopener noreferrer">BuuCTF难题详解| Misc | [ACTF新生赛2020]剑龙</a></p>
<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190559563.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190559563.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<h3 id="题目描述">题目描述：</h3>
<p>得到的 flag 请包上 flag{} 提交。</p>
<h3 id="密文">密文：</h3>
<p>下载附件，解压得到

<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190601129.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190601129.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<hr>
<h3 id="解题思路">解题思路：</h3>
<p>1、先看一下hint.zip压缩包，解压得到</p>
<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190602214.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190602214.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<p>pwd.txt内容如下：</p>
<blockquote>
<p>ﾟωﾟﾉ= /｀ｍ´）ﾉ ~┻━┻ // <em>´∇｀</em> / [‘ <em>&rsquo;]; o=(ﾟｰﾟ) =</em> =3; c=(ﾟΘﾟ) =(ﾟｰﾟ)-(ﾟｰﾟ); (ﾟДﾟ) =(ﾟΘﾟ)= (o<sup><em></sup>o)/ (o<sup></em></sup>o);(ﾟДﾟ)={ﾟΘﾟ: ‘ <em>’ ,ﾟωﾟﾉ : ((ﾟωﾟﾉ==3) +&rsquo;</em> ’) [ﾟΘﾟ] ,ﾟｰﾟﾉ :(ﾟωﾟﾉ+ ‘ <em>‘)[o<sup>_</sup>o -(ﾟΘﾟ)] ,ﾟДﾟﾉ:((ﾟｰﾟ==3) +’</em> ’)[ﾟｰﾟ] }; (ﾟДﾟ) [ﾟΘﾟ] =((ﾟωﾟﾉ <mark>3) +‘ <em>‘) [c<sup>_</sup>o];(ﾟДﾟ) [‘c’] = ((ﾟДﾟ)+’</em> ’) [ (ﾟｰﾟ)+(ﾟｰﾟ)-(ﾟΘﾟ) ];(ﾟДﾟ) [‘o’] = ((ﾟДﾟ)+‘ <em>‘) [ﾟΘﾟ];(ﾟoﾟ)=(ﾟДﾟ) [‘c’]+(ﾟДﾟ) [‘o’]+(ﾟωﾟﾉ +’</em> ’)[ﾟΘﾟ]+ ((ﾟωﾟﾉ</mark> 3) +’ <em>‘) [ﾟｰﾟ] + ((ﾟДﾟ) +’</em> ‘) [(ﾟｰﾟ)+(ﾟｰﾟ)]+ ((ﾟｰﾟ <mark>3) +‘<em>’) [ﾟΘﾟ]+((ﾟｰﾟ</mark> 3) +’ <em>‘) [(ﾟｰﾟ) - (ﾟΘﾟ)]+(ﾟДﾟ) [‘c’]+((ﾟДﾟ)+’</em> ‘) [(ﾟｰﾟ)+(ﾟｰﾟ)]+ (ﾟДﾟ) [‘o’]+((ﾟｰﾟ <mark>3) +‘ <em>‘) [ﾟΘﾟ];(ﾟДﾟ) [’</em> ’] =(o<sup></em></sup>o) [ﾟoﾟ] [ﾟoﾟ];(ﾟεﾟ)=((ﾟｰﾟ</mark> 3) +’ <em>‘) [ﾟΘﾟ]+ (ﾟДﾟ) .ﾟДﾟﾉ+((ﾟДﾟ)+’</em> ‘) [(ﾟｰﾟ) + (ﾟｰﾟ)]+((ﾟｰﾟ <mark>3) +‘<em>’) [o<sup></em></sup>o -ﾟΘﾟ]+((ﾟｰﾟ</mark> 3) +’ <em>‘) [ﾟΘﾟ]+ (ﾟωﾟﾉ +’</em> ‘) [ﾟΘﾟ]; (ﾟｰﾟ)+=(ﾟΘﾟ); (ﾟДﾟ)[ﾟεﾟ]=’\‘; (ﾟДﾟ).ﾟΘﾟﾉ=(ﾟДﾟ+ ﾟｰﾟ)[o<sup><em></sup>o -(ﾟΘﾟ)];(oﾟｰﾟo)=(ﾟωﾟﾉ +’ *‘)[c<sup></em></sup>o];(ﾟДﾟ) [ﾟoﾟ]=’&quot;‘;(ﾟДﾟ) [’* ‘] ( (ﾟДﾟ) [’ <em>‘] (ﾟεﾟ+(ﾟДﾟ)[ﾟoﾟ]+ (ﾟДﾟ)[ﾟεﾟ]+(ﾟΘﾟ)+ ((o<sup><em></sup>o) +(o<sup></em></sup>o))+ ((ﾟｰﾟ) + (o<sup><em></sup>o))+ (ﾟДﾟ)[ﾟεﾟ]+(ﾟΘﾟ)+ (ﾟｰﾟ)+ ((ﾟｰﾟ) + (ﾟΘﾟ))+ (ﾟДﾟ)[ﾟεﾟ]+(ﾟΘﾟ)+ ((ﾟｰﾟ) + (ﾟΘﾟ))+ (ﾟｰﾟ)+ (ﾟДﾟ)[ﾟεﾟ]+(ﾟΘﾟ)+ (ﾟｰﾟ)+ (o<sup></em></sup>o)+ (ﾟДﾟ)[ﾟεﾟ]+(ﾟΘﾟ)+ ((ﾟｰﾟ) + (ﾟΘﾟ))+ ((ﾟｰﾟ) + (o<sup><em></sup>o))+ (ﾟДﾟ)[ﾟεﾟ]+(ﾟΘﾟ)+ ((ﾟｰﾟ) + (ﾟΘﾟ))+ ((ﾟｰﾟ) + (ﾟΘﾟ))+ (ﾟДﾟ)[ﾟεﾟ]+((o<sup></em></sup>o) +(o<sup><em></sup>o))+ (o<sup></em></sup>o)+ (ﾟДﾟ)[ﾟεﾟ]+(ﾟｰﾟ)+ (ﾟΘﾟ)+ (ﾟДﾟ)[ﾟoﾟ]) (ﾟΘﾟ)) (’</em> &lsquo;);</p>
</blockquote>
<p>确认为aaEncode编码，使用在线工具解得 <code>welcom3!</code></p>
<p><a href="https://toolwa.com/aaencode/"target="_blank" rel="noopener noreferrer">在线工具：https://toolwa.com/aaencode/</a></p>
<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190603819.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190603819.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<p>2、剩下一张图片，再加上一个密码，确认使用steghide工具加密。</p>
<p>steghide下载地址： <a href="https://sourceforge.net/projects/steghide/"target="_blank" rel="noopener noreferrer">https://sourceforge.net/projects/steghide/</a></p>
<p>使用如下命令，得到隐藏信息。</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">steghide extract -sf hh.jpg -p welcom3!
</span></span></code></pre></td></tr></table>
</div>
</div><p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190605825.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190605825.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190606909.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190606909.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<p>在hh.jpg的属性找到密钥： <code>@#$%^&amp;%%$)</code></p>
<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190608265.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190608265.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<p>解得如下信息：</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-python" data-lang="python"><span class="line"><span class="cl"><span class="n">think</span> <span class="n">about</span> <span class="n">stegosaurus</span>
</span></span></code></pre></td></tr></table>
</div>
</div><p>DES加解密： <a href="https://www.sojson.com/encrypt_des.html"target="_blank" rel="noopener noreferrer">https://www.sojson.com/encrypt_des.html</a>

<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190609623.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190609623.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<p>3、搜索发现对应题目“剑龙”，但其实指的是stegosaurus pyc隐写工具。</p>
<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190611323.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190611323.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<p>O_O文件的确是一个pyc文件。</p>
<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190613551.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190613551.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<p>stegosaurus下载地址： <a href="https://github.com/AngelKitty/stegosaurus"target="_blank" rel="noopener noreferrer">https://github.com/AngelKitty/stegosaurus</a></p>
<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190614895.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190614895.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<p>运行脚本加上 <code>-x</code> 参数，得到flag： <code>flag{3teg0Sauru3_!1}</code></p>
<p>
<div class="post-img-view">
    <a data-fancybox="gallery" href="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190617000.png">
        <img src="https://cdn.jsdelivr.net/gh/yuexuan521/image/20251228190617000.png" 
             alt="在这里插入图片描述" 
              
             loading="lazy"
        />
    </a>
</div></p>
<h3 id="flag">flag：</h3>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"> flag<span class="o">{</span>3teg0Sauru3_!1<span class="o">}</span>
</span></span></code></pre></td></tr></table>
</div>
</div>]]></content:encoded>
    </item>
  </channel>
</rss>
