36 lines
1.1 KiB
Python
36 lines
1.1 KiB
Python
"""
|
|
FORENSICS / MISC skeleton — copy & fill. (p4-team style: oracle / byte-by-byte,
|
|
pcap parse, stego.)
|
|
|
|
Example (from 'heXdump'): the service uses `xxd -r -ps` which does NOT truncate,
|
|
so you overwrite 1 byte at a time and brute the flag char-by-char against a known
|
|
oracle output.
|
|
"""
|
|
from lib.net import nc, receive_until, receive_until_match, send, sendline # noqa
|
|
import string
|
|
|
|
CHARSET = string.ascii_letters + string.digits + "{}_-!@#$%^&*()+=/."
|
|
|
|
|
|
def byte_by_byte_oracle(base_conn_setup, oracle_fn, known_prefix="flag{"):
|
|
"""Generic oracle recover: find next char where oracle output == baseline."""
|
|
known = known_prefix
|
|
while "}" not in known:
|
|
baseline = oracle_fn(known) # output for current known prefix
|
|
for c in CHARSET:
|
|
test = oracle_fn(known + c)
|
|
if test == baseline:
|
|
known += c
|
|
print(known)
|
|
break
|
|
else:
|
|
known += "?"
|
|
print("stuck at", known)
|
|
break
|
|
return known
|
|
|
|
|
|
if __name__ == "__main__":
|
|
# Wire oracle_fn to your specific protocol; see heXdump writeup.
|
|
pass
|