TPA 02 - 📱
Peggy 是一家公司的员工,和许多人一样,她偶尔也会使用个人手机执行与工作相关的任务。不幸的是,她成为了网络钓鱼攻击的目标。你的任务是找出攻击者的电话号码和佩吉的密码,从而揭露这次攻击的细节。
以 r3ctf{number_password} 格式提交您的发现。对于电话号码,请删除任何符号和空格。例如,如果攻击者的电话号码是 +1 123-456-7890,佩吉输入的密码是 passwd,则您的标记应为 r3ctf{11234567890_passwd}。
考点:安卓取证+流量明文
仔细看下流量
访问了/login
路由
POST包就是数据 可以拿到 password
Form item: "password" = "l0v3_aNd_peace"
AXIOM支持安卓取证 直接分析即可 看看短信
被攻击者网络钓鱼了 攻击者电话 15555215558
r3ctf{15555215558_l0v3_aNd_peace}
TPA 01-🌐
d3f4u1t 的电脑中散落着一些信息,请帮助他找回珍贵的旗帜。
另一个 lnk:https://gofile.io/d/C6wVDA
考点:硬盘取证+电子仿真+mysql数据库的基本使用
镜像太大了,轻薄本用AXIOM带不动哎
这里用 取证大师 快速取证一遍
可以知道时win10里面套了一个wsl
法一:但是当时用FTK+VM电子仿真还原取证环境去操作wsl的
法二:看看其他佬的wp 发现可以直接提
分区2_本地磁盘[D]:\Users\r3kapig\AppData\Local\Packages\CanonicalGroupLimited.Ubuntu_79rhkp1fndgsc\LocalState\ext4.vhdx
提出来后再放到 取证大师 分析 拿到 根目录下的F14G
1. `Hi players,welcome !`
2. `Ops,what's that?`
3. `2d422fc7f2c628c55520984c0673964eb5454dea72f79b1022a34728294c5bf8`
4. `I guess u need a key to decrypt it.`
5. `SELECT something FROM somewhere with the windows10 lol~`
但是不太清楚 如何找到这个奇怪路径的 平时没有使用过wsl 哈哈
可以对比网上的文章 多试试
C:\Users\xiaoPeng\AppData\Local\Packages\CanonicalGroupLimited.Ubuntu18.04onWindows_79rhkp1fndgsc\LocalState\rootfs
比对一下
发现 访问时间比较靠前 命名 可疑的文件
尝试读取 secret.ibd
这里用一个github库来读取文件内容
https://github.com/ddcw/ibd2sql
python main.py secret.ibd --sql --ddl
CREATE TABLE IF NOT EXISTS `mysql`.`secret`(
`id` int NULL,
`data` blob NULL
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_0900_ai_ci ;
INSERT INTO `mysql`.`secret` VALUES (1, '0xffd8ffe000104a46494600010101009000900000ffdb00430006040506050406060506070706080a100a0a09090a140e0f0c1017141818171416161a1d251f1a1b231c1616202c20232627292a29191f2d302d283025282928ffdb0043010707070a080a130a0a13281a161a2828282828282828282828282828282828282828282828282828282828282828282828282828282828282828282828282828ffc0001108007b014403012200021101031101ffc4001f0000010501010101010100000000000000000102030405060708090a0bffc400b5100002010303020403050504040000017d01020300041105122131410613516107227114328191a1082342b1c11552d1f02433627282090a161718191a25262728292a3435363738393a434445464748494a535455565758595a636465666768696a737475767778797a838485868788898a92939495969798999aa2a3a4a5a6a7a8a9aab2b3b4b5b6b7b8b9bac2c3c4c5c6c7c8c9cad2d3d4d5d6d7d8d9dae1e2e3e4e5e6e7e8e9eaf1f2f3f4f5f6f7f8f9faffc4001f0100030101010101010101010000000000000102030405060708090a0bffc400b51100020102040403040705040400010277000102031104052131061241510761711322328108144291a1b1c109233352f0156272d10a162434e125f11718191a262728292a35363738393a434445464748494a535455565758595a636465666768696a737475767778797a82838485868788898a92939495969798999aa2a3a4a5a6a7a8a9aab2b3b4b5b6b7b8b9bac2c3c4c5c6c7c8c9cad2d3d4d5d6d7d8d9dae2e3e4e5e6e7e8e9eaf2f3f4f5f6f7f8f9faffda000c03010002110311003f00faa68a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a2be65d635cf1f7887e366bbe16f0df899b4e8a0667896503622aaae470a4f7a00fa6a8af39f07c3e24f04f87b5cd4be2278822d5618504f1bc40feed141dc3951c9e315e5ba2eb9f13fe2ede5ddef86f518fc3da043218e339db93e9b802ccd8c67a0a00fa628af23d134ff1df84fc17e3197c53af26a524362f369f731b6e68d96372739507aedeb9af32f02ddfc50f17782f51f11d878d7c94b27914c13a2e5f62063cedc743de803ea9a2bca7f678f1d6ade38f0ade4daeaabdd59ce21fb4226d1302a0f207191df1ea2b27c75f18351fedebcd07e1e6929ab5ed92b35e5dcb930c017ef771d3d49033c73401ed9457cd5a27c55f8969a02f89e7d274cd67c3aac44ed68a51e2c7decf3918f5da457a478b3c5d6be26f819ad6bfa05c4b1ac962e5486db242e382a71d083401e9b45791fc05f104569f05ecb55f11ea612259a6125d5e4dd3f7a400598fd057a458f88748bed1db56b4d46d65d314316ba120f2863afcdd38a00d4a2b9ad0fc77e16d7aff00ec5a3ebb617777ce228e51b9b1e83bfe15734ff14687a8eb13e9563aad9cfa95beef36d9250644da7072bd783401b34564dc789346b7d762d166d4ed5356946e8ed0c83cc61827217af407f2ad6a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a002be47bdf0edff89ff691f1269fa4eb571a2dc96924fb5419dd80a995e181e7eb5f5c578c78abe045b6bde2ed47c411f88f50b0b9bc937b2c1181b780300e41ed40153c63e0ad6fc3df03fc5b637dafde6bf7326db812cc1b7246ac8594659b8c2935a3fb2deb1617bf0c6db4fb692317b632c8b71167e61b9cb06c7a1040cfb5745f0d7e1c2f82ff00b4966d6efb588ef955192f064201bb38e4f5ddcd719aefecefa54dab497fe19d6efb4269092628977aa67a8520a903db26803d37e24ba9f87fe2840ca5d74cb82573c81e5b57cc7f07fe1a6a5e36f87da8cf69e2bbcd2edbed3242d64a18c12108a773e180e7201e0f4af75f06fc2783c39e1df1169d26b57d7f3eb701827b9980ca0daca0a8c9fef9ea6b92b4fd9da2b4b47b4b7f196b50d9c849920880447cf5c80d8fd28033be01f8c6f6ebe1f78ab468ad2da2b8d12d5e4b79ad630a24255f19c756caf5ef9ae67c1babe9fe19fd9b35dd421743ac6af7325931cfce598631ebc2166fc6be83f877e01d17c07a3cb63a3472399db74f3cc433ca71819e3181ce00f5ae213f67ff000ca78b57565b8bbfb02cdf681a61c18b7e738cf5dbedf8668035fe1bda5a7813e08d936bc520863b46baba120ef265b691dcf2171eb5e5bf0e6d2e21fd99bc6b712a3476d74f3cb6ea7fb8151491ed9047e15e87e39f857aaf8dbc64b2ebbe2294f84e2db245a744bb583775e38c7fb47279c7bd777ae7852c751f04dd7862d40b0b09adbeca9e4ae7ca5f61401f1d69d7d3ea1e1ef03786fc41349a6f8465b996592e97912b1958313e9b781edbb35ea9fb5233e8be19f0a787f4654834195981821f943797b768dd9c63e62791d79cd77eff00067489be1941e0fbabc9a54b799a782f7cb0248dd989381d3182462adde7c29b1d57e1edb78575fd4aeb504b36cda5e950934200c28ee0803239ed8f4cd0078d789fc21e2ad45b429bc33f0d57c3d77a648aeb736d79133480631bba64e4672727ad741f10addbc09f1efc35e2b03cab0d60886ecf45572023e7f02adf506bb1f0dfc23d534bd434f7bdf1e6b97da7d8ca92c56449446d841556cb1caf1d315ce7ed3fe26f0e5ff84db4286e63baf10457a822b788e5e171f78b71e8718ef914009f06a03e32f8c1e2df1bcc37dadb486cec98f4feee47d1147fdf75f405711f063c2c7c21f0f34bd3a64d978e9f68ba1dfcd7e483f4185fc2bb7a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a2919828cb1007a9a005a28041191c8a2800a28a2800a290903a903eb4b40051451400573c3c13e1bff8481b5c3a2d936accdbcdcb4797ddfdee7bfbd74345001451450014514c9a249e178a550f1b82aca7a106801f451466800a28a33400514668a0028a4dc01c1233e99a5a0028a40c09c0233f5a5a0028a40c0f420d292075e2800a28041e841a2800a28a2800a28a2800a28a2800a28a2800a28a2800af39d4be32f83b4cd5356d3efaf2786e74c2cb32b427e660c176a7f78e4fe5935e8d5f35fc2cb1b5bcfda63c6af75047335bb5cc916f5cec6f354647be091f8d007af7c3ef899e1df1e497316873cc2e6dd77bc13c7b1f6e71b8724119f7af0bfda22dfc7c9657ba86bba94707874dff00d9ecec607c1743b8abb85ebc2f724e7b0ad8f87704563fb54789aded235860314df220c0e446c78faf35d27ed71ff24d6cff00ec231ffe8125007a67c3c603e1f78719ce00d36dc924ff00d335ae2b5af8f7e07d2f5192cc5d5dde346db5e5b5837c60ff00bc48cfd466a5d6daed7f66f274eddf68fec08b1b3aedf297763fe039ae67f65f6f0ca7c3990b3582ea7e749f6ef38a87c67e5ce7f876e3dbad007a6789be20f877c35e1eb3d6756bd315adea2c96c81099250406185ebd08cfa567f81be2af867c67a83e9fa5cf3c3a82a9716d771796eca3a95ea0fd339af15f8e525c1f8d5e13fb049a6c7662d213a7bde0cd98f99b04e38db9dbd3dbb574f1f81bc67a97c51f0f78975ed57c30b736aca0a58bba3cd12e4b6011f31c13dfa500745e2df83a7c59af6a5a9ebde28d556191c9b4b6b77c476c98e3ae73ebc62b91fd977c43aa36a3e25d12f2fe5d434ad397cc826762db30c57e527b3019c7b545f14be206a5e2ff00195cf813c35a95a691a6c45a2bfd46e26116ec70ea092381d303963ed5e93f0c7c3fe15f0af862ef4bf0c6a567a85d34465bb9e39d1e495b18c90a4e147403b67d4d00506f8f7e061a5c97a2f2e88493cb10fd9cf98e719c81e83d491534df1cfc111787e1d57edf33895da316a909338618ce57b0e4739c7a579cfec93a558de787fc552ddda4333bc89031910366328c4af3d8e699fb24e93617567e2d96ead2199f7450032206c4643e579ec78cfd05007baf823c6ba2f8d3457d4f43b82f046c52559576344c0670c3e9ce7a571d7ff1e7c1167a9bda7daeee78e37d8f7505b97854ff00bdd48f700d789fc276bb8be17fc564d377091218f684ea17f781b1ff0001cd687c2dd23c57e20f85573a56837be128f48b932c7729741fed2ac4fde720100e3041f4c5007d2d7fe2bd12c3c33ff0905d6a30268e6312adc8395607a631c927d3ad719e1df8dfe0dd7358834e86e2eed65b86d903dd40634949e000d93d7df15e1df15f40d5fc2df07fc21a4dede5ade5a25f4ee66b590bc273cc633819eb25751e2cf04f8d7c6be1dd192ef57f0545a7db323d94b68ef1e3230aa0e0f078e3d40a00d1f8c9f19ee344f1b5868fa0de3dbdbd9dc05d549b705880ca485273c6dcf4af42bdf8c3e14b2f0de99ae4f35e0b0d464922b722dc962c870d91dabcaff68c8a3b4f1efc3c7bbf2548653712600562258f7127b8ebd6acfed70b07fc23fe1792cc45f665ba94662c6d076afa71d8d007b478e3c71a3782b49b6d475d79d2dae2411218a32e77104f4fa0af35fda33c3f79ab7852cfc5de1bb9bb86e6c235965589d94c901f98360775273f427d2b0bf6a9d674ebdf00f8721b3bdb79e49ae167458dc313188c8ddc76cb0aedbe2778e60f057c26b22be5c9a95fd925b5ac2e010498c06623b8507f32077a00f33f1b7c4dd43e21f863c27e18f0c3baeb7ab6d3a8794c54c6ca76e323a0254b9f4503d6b6ff00685d31fc1df07bc3ba669d7973ba0be4479fcd60f2b18e42cc4e73c9e715e75e1dd3b55f837af7843c55aadbf9965aa4045c26ccb42ac795f660855bf31eb5ea5fb59dcc37bf0cf44bab59165b79afe3923910e43298a4208fc28031edbe0bebafe13b2d6bc37e32d517549ad23ba582491955999036d0c1b8eb81915d3fecfbe3ed5fc63a1eb3a2eb7313ade9cbb52e5861995b2016c7f12b0ebee2ba2d3fe23785bc37f0e348b8bed66c5e5834d847d9a1995e56711afca141ce73c7b77af37fd99ade5b48fc5fe39d590db69d306656238203349211ea0703f3a0067c45f83e340f056a5e24bdf176ad73ae5a4626334b2e11db23e51fc409ce0735dbfc1fbcd5fc77f045a0d4f51b882f65f36cd2fd49f3760380f9c8c91c8ce7b5798b6b173f1bb5f94ebfaed9f87fc1f6737c968f708924de9c13cb63f88f033c035f4468d3786746f08c30e977b610e856c05b2cb1cea635248182f9c64961d7b9a00f9b3e2d7852cfe1b7f646a3e0ff0015ea336b52dc6c685ae43c8c319dd85c719c0c1ce735f41f8afc3d3f8cbc11a7d9ea9a95ce8eee229ef1ed9b631f93e64cf40327be7a5784fc5cf047877e1b69fa7f88bc17ad4b06b0972a2285e749b7a90496031db03db9af725bbd3fc59f0db4bb7f174f1591d76ca3f32332888bb150c4267bf7c5007845e69adf0f7e32786f4df026bf79a8a5e4918bab669c4b805f0cafb78c6dc9e4646335ee7f13bc0b69e336d3ff00b575cbed374fb50e1e1b794462666c60b13c7183dbbd784f8cf4eb2f83ff00103409bc01a9bdc4d78db2e6ca47598eddca029206406c9c77e3ad7d03f10343f0df8cad22f0ff0088ef16270cb78b025c08a438dca0f3d472d401e29f094de7877e3c5d7867c39acdceafe1b58dccccd27988a3cbdd9c8f97707c2e475e95f4ed7cbbe0c907c3ef8f36fe15f08ea2752d0efca8b889b6b98c9524e580eab8cfd0e0d7d454005145140051451400514514005145140051451400572da1f80f42d13c59a9788f4f8254d5350dc2e1da52cadb9831c2f41c815d4d1401cae9fe02d0b4ff001a5df8aada0986b174a56590ca4a904007e5e83a0ab3e37f08691e35d263d3b5e8a496d525132ac72143b8020723ea6ba1a2802a69ba75b69da55b69d6c9fe896f0ac088c777c8a3001cf5e0579a6a9f00fc0ba86a4f79f62bab6dedb9a1b7b829193f4e71f418af56a280393f147c3cf0df89f43b3d2b56b0f32dac90476ceae56485400061baf403ae738acbf03fc24f0b7837561a9e9315dbdf2a3224b71397daa7a800607e95e8145007976a5f02bc0fa8ea3757b756576d71732b4d21174e0166393c67d4d6d782be17f867c19777773a0db4f14b750f912192767ca673dfa74aede8a00e5bc0de04d0fc1169776de1f8258a2ba70f289252f92063bf4a3c0fe03d0bc130dec7a0412c4b78caf3799297c919c633d3a9aea68a00e4fc19f0ff00c3fe0e5d45744b691175020dc2cb29903633d8ff00bc6b94bff805e05bbd41ee96d2f2d848db9a0b7b92b19fc39207b035eaf450073f77e0ed0af3c271f86eeb4f8e5d1e28d62481d89da17a10d9c823d739ae3744f815e0bd1f56b7d42de0be925b795668525ba251181c83818ce0fa935ea54500729e3ef00e83e3bb382df5fb791cdbb1686589f63a67ae0fa1c0e0fa5536f85fe187f0343e139ad659b4a85cc91ef94f988e493b837af27f3aede8a00f2c87e0378123d2fec2d61712032094ccf70de61201006e18e393c0adcd7be17f8675fd574ebfd5adee2e64d3e38e2b78da76f2d5539036f439efeb5dbd140185e31f0a693e30d14e97aedb99ed0bac802b156561d082391dc7d09ac3d43e17786b50f08d8f86af22bb974ab197ce811ae5b721f9863775c7cc78aee68a00f2eb0f80fe00b4b859bfb2659ca9c849ee6465fc4679fc6bbed4342d3efbc3d3e8925bac7a6cd01b66861fdd811918c0c74e3d2b4e8a00f25ff867df007fcf85e7fe05bff8d74d65f0cfc3367e0bbaf0ac56931d1ae64f36489a762c5b2a721b391ca8aed28a00f29d1fe0278174dbf4ba3657576636dcb1dd4e5e307fdd0067e8735d7f8e3c0da1f8db4b82c35db791e081f7c3e4c86328718e31edeb5d3d1401e73e10f833e0ef0b6a71ea3636535c5ec477452ddcbe67967d40e067df19abfe3ff861e1bf1ddd4175aec373f6a823f29258262842e49c6391d49ed5dbd1401c57817e18785bc113bdc68962df6c65d86e677324817b804f03f002bb5a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a0028a28a00fffd9');
一眼jpg
告诉我们 加密方式和密钥 直接解密即可
记录一下当时用电子仿真做的步骤
windows 用户密码存放在SAM文件里(位置在C:\Windows\System32\config\SAM),SAM的意思是SecurityAccountManager
用 mimikatz工具 分析SAM,SYSTEM文件
# 1. 启用 SeDebugPrivilege
privilege::debug
# 2. 加载 SAM 文件和 SYSTEM 文件
lsadump::sam /sam:SAM /system:SYSTEM
af27efb60c7b238910efe2a7e0676a39
可以拿到开机密码是 123321
接下来的电子仿真
大体参考:https://blog.csdn.net/NDASH/article/details/109295885
但是几点特别注意的是
这里固件类型选择 BIOS
如果我们要在虚拟机中正常使用wsl 要开启处理器虚拟化
成功仿真后 开启wsl
权限问题 无法访问F14G
访问 https://www.youtube.com/@d3f4u1t-lolol
提示 root的密码 但是su
不全 要进一步信息收集
但是这里直接改wsl的默认用户为root即可
Ubuntu config --default-user root
同样可以拿到密文
Hi players,welcome !
Ops,what's that?
2d422fc7f2c628c55520984c0673964eb5454dea72f79b1022a34728294c5bf8
I guess u need a key to decrypt it.
SELECT something FROM somewhere with the windows10 lol~
ECB解密即可
2d422fc7f2c628c55520984c0673964eb5454dea72f79b1022a34728294c5bf8
R3CTF{Enj0y_th3_4N6_ch41_p1z!!}