58 lines
1.7 KiB
Python
58 lines
1.7 KiB
Python
"""
|
|
MISC skeleton — copy & fill. (p4-team style: oracle, encoding, stego, brute)
|
|
|
|
p4 'misc' covers a lot: byte-by-byte oracle (heXdump), encoding tricks,
|
|
PRNG reversing, image stego, constraint solving. See forensics_skeleton.py
|
|
for the generic oracle helper.
|
|
"""
|
|
import base64
|
|
import string
|
|
|
|
|
|
# ---- encoding chain helper (common in misc) ----
|
|
def try_decodings(blob):
|
|
"""Brute a chain of common decodings to spot a flag."""
|
|
results = []
|
|
data = blob
|
|
for _ in range(3):
|
|
for name, fn in [
|
|
("b64", lambda d: base64.b64decode(d)),
|
|
("b32", lambda d: base64.b32decode(d)),
|
|
("b16", lambda d: base64.b16decode(d)),
|
|
("hex", lambda d: bytes.fromhex(d.decode())),
|
|
]:
|
|
try:
|
|
out = fn(data)
|
|
if b"flag" in out.lower() or b"CTF" in out:
|
|
results.append((name, out))
|
|
data = out
|
|
except Exception:
|
|
pass
|
|
return results
|
|
|
|
|
|
# ---- generic byte-by-byte oracle ----
|
|
CHARSET = string.ascii_letters + string.digits + "{}_-!@#$%^&*()+=/."
|
|
|
|
|
|
def recover_oracle(known_start, oracle_fn, stop="}"):
|
|
"""oracle_fn(prefix) returns a stable baseline string for a given known prefix."""
|
|
known = known_start
|
|
while stop not in known:
|
|
baseline = oracle_fn(known)
|
|
found = None
|
|
for c in CHARSET:
|
|
if oracle_fn(known + c) == baseline:
|
|
found = c
|
|
break
|
|
if not found:
|
|
known += "?"
|
|
break
|
|
known += found
|
|
print(known)
|
|
return known
|
|
|
|
|
|
if __name__ == "__main__":
|
|
raise NotImplementedError("pick a misc technique and fill it in")
|