diff --git a/examples/README.md b/examples/README.md index d02382d..a7ab164 100644 --- a/examples/README.md +++ b/examples/README.md @@ -10,6 +10,7 @@ patterns from the public `p4-team/ctf` archive. | `lost_modulus` | HITCON 2019 Quals | Crypto | RSA leaks `e,d,iqmp,ipmq` but not `n` — recover `n` | `hitcon{1t_is_50_easy_t0_find_th3_modulus_back@@!!@!@!@@!}` | | `a2s` | Pwn2Win 2021 | Crypto | 2-round reduced AES — differential attack recovers key | `CTF-BR{bu7_1f_7h0u6h7_c0rrup75_l4n6u463,_l4n6u463_c4n_4l50_c0rrup7_7h0u6h7}` | | `russian_threesome` | Hack.lu 2020 | RE/Misc | Inverse-permutation fixed-point on a drum dump (CP1251) | `Кто хочет много знать, тому мало спать.` | +| `mask` | TokyoWesterns 2020 | Misc | Host bits of `IP/mask` list → base64 → flag | `TWCTF{Are-you-using-a-mask?}` | ## Run them ```bash @@ -24,4 +25,7 @@ cd examples/a2s && python3 solve.py && cd ../.. # russian_threesome — permutation fixed point python3 examples/russian_threesome/solve.py + +# mask — IP/mask host bits -> base64 +python3 examples/mask/solve.py ``` diff --git a/examples/mask/solve.py b/examples/mask/solve.py new file mode 100644 index 0000000..d81887a --- /dev/null +++ b/examples/mask/solve.py @@ -0,0 +1,75 @@ +""" +EXAMPLE: TokyoWesterns 2020 — "mask" (Misc) +https://github.com/p4-team/ctf/tree/master/2020-09-19-tokyowesterns/mask + +VULN: each line is `IP/mask`. The HOST bits (IP & ~mask) of the 40 entries +form a base64 string; decode it to get the flag. + +Run: + cd /home/code/ctfkit + python3 examples/mask/solve.py +Expected flag: TWCTF{Are-you-using-a-mask?} +""" +import ipaddress +from base64 import b64decode + +MASKS = """ +192.168.55.86/255.255.255.0 +192.168.80.198/255.255.255.128 +192.168.1.228/255.255.255.128 +192.168.90.68/255.255.254.0 +192.168.8.214/255.255.255.128 +192.168.5.197/255.255.255.128 +192.168.71.90/255.255.255.0 +192.168.62.55/255.255.255.192 +192.168.78.209/255.255.255.128 +192.168.76.216/255.255.255.128 +192.168.91.202/255.255.255.128 +192.168.93.108/255.255.255.0 +192.168.74.76/255.255.254.0 +192.168.10.88/255.255.254.0 +192.168.82.236/255.255.255.128 +192.168.13.246/255.255.255.128 +192.168.99.228/255.255.255.128 +192.168.68.83/255.255.252.0 +192.168.23.113/255.255.255.192 +192.168.52.113/255.255.255.192 +192.168.69.99/255.255.255.0 +192.168.19.114/255.255.255.192 +192.168.53.236/255.255.255.128 +192.168.90.117/255.255.254.0 +192.168.35.90/255.255.255.0 +192.168.91.121/255.255.255.0 +192.168.48.49/255.255.255.192 +192.168.27.104/255.255.255.0 +192.168.98.204/255.255.255.128 +192.168.93.87/255.255.255.0 +192.168.44.113/255.255.255.192 +192.168.40.104/255.255.248.0 +192.168.25.227/255.255.255.128 +192.168.57.50/255.255.255.192 +192.168.97.115/255.255.255.0 +192.168.30.47/255.255.255.192 +192.168.10.102/255.255.254.0 +192.168.51.209/255.255.255.128 +""".strip().split("\n") + + +def main(): + host_bits = bytearray() + for line in MASKS: + ip, mask = line.split("/") + a = int(ipaddress.IPv4Address(ip)) + m = int(ipaddress.IPv4Address(mask)) + host_bits.append(a & (~m & 0xFFFFFFFF) & 0xFF) + b64 = bytes(host_bits) + # base64 length must be a multiple of 4 + b64 += b"=" * (-len(b64) % 4) + flag = b64decode(b64).decode(errors="replace") + print("host-bits b64:", b64.decode("latin1")) + print("FLAG =", flag) + return flag + + +if __name__ == "__main__": + main()