CTF toolkit: lib (net, crypto_utils), templates per category, scaffold, cheatsheet, ps_and_qs example
This commit is contained in:
@@ -0,0 +1,35 @@
|
||||
"""
|
||||
FORENSICS / MISC skeleton — copy & fill. (p4-team style: oracle / byte-by-byte,
|
||||
pcap parse, stego.)
|
||||
|
||||
Example (from 'heXdump'): the service uses `xxd -r -ps` which does NOT truncate,
|
||||
so you overwrite 1 byte at a time and brute the flag char-by-char against a known
|
||||
oracle output.
|
||||
"""
|
||||
from lib.net import nc, receive_until, receive_until_match, send, sendline # noqa
|
||||
import string
|
||||
|
||||
CHARSET = string.ascii_letters + string.digits + "{}_-!@#$%^&*()+=/."
|
||||
|
||||
|
||||
def byte_by_byte_oracle(base_conn_setup, oracle_fn, known_prefix="flag{"):
|
||||
"""Generic oracle recover: find next char where oracle output == baseline."""
|
||||
known = known_prefix
|
||||
while "}" not in known:
|
||||
baseline = oracle_fn(known) # output for current known prefix
|
||||
for c in CHARSET:
|
||||
test = oracle_fn(known + c)
|
||||
if test == baseline:
|
||||
known += c
|
||||
print(known)
|
||||
break
|
||||
else:
|
||||
known += "?"
|
||||
print("stuck at", known)
|
||||
break
|
||||
return known
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
# Wire oracle_fn to your specific protocol; see heXdump writeup.
|
||||
pass
|
||||
Reference in New Issue
Block a user