Hi there CTF Lovers! Welcome back to my blog. This is my ICTF November Writeup Challs, this is the discord link to join (https://discord.gg/zjpvn2c). They will post one chall everyday and its valid for one month. *note : i can’t make the web challs because the server is not available, sorry :(
So lets begin with the chall!

not-so-difficult-rsa

challDesc

Given the cipher message = 418871322481172992333830847014255718220369100285625324577813 803226422566253833997303544405729373353110445741042373932191 8076207587152546291602684395254731

And we got the public key, so i think if i got the Alice and Bob RSA public key we can make private key from it to decrypt the cipher message. By the way the hint is “Alice send to Carol” so we can use Alice public key to decrypt the message. I use RsaCTFTool to solve this.

Alice public key
n = 59092732279913540922799274551477981413603258445741 34029077480285650908196752702184649665808028347577569087 598335548616511503237225954122574741834625790443
e = 65537
Command : python3 RsaCtfTool.py -n [n value] -e [e value] –uncipher [cipher message]

Password Protection

challDesc

So this is the zip cracking chall. Lets use John (zip2john) or fcrackzip, but in this chall i chose fcrackzip

Command : fcrackzip -v -D -u -p [wordlist] [zipFile]
-v : verbose
-D : Dictionary attack mode
-u : unzip -> reduce false password
-p : password file

The password is secure and lets we get the flag on flag.txt !

flag : ictf{wh@7_@r3_y0u_d01ng_h3r3?}

same-pictures

challDesc

Given 2 images and i need to find the differences. At the first time i use diff to compare the images to see if there is any differences but i got stuck in this chall because i can’t get the flag :(. Thanks to my bestfriend, Anthony that gave me a hint about linux command cmp .

Yes! the image is different. The parameters that i use is -b for print the differing bytes
and -l/–verbose to output the byte numbers.

flag : ictf{messing_around}

RestInPeace-john

challDesc

Another zip cracking chall but it’s different than before. Lets use fcrackzip again !

The password is = johncena and i get .mp3 file with Pacman soundtrack

small

I tried to see the metadata with exiftool but the flag is not there. Then i thought what if the flag is in the spectogram but i got nothing. After that, i tried the strings command and hopin’ that i will get the flag. After all this time, the flag is under my nose :c

flag : ictf{u_used_johntheripper_and_strings}

Build-a-Cipher 1

challDesc

Given cipher message that i need to decrypt with dictionary cipher / substitutional cipher. This is the char map for decrypt/encrypt.

small

Lets use dcode.fr to decrypt the message and add the char map, so basically the cipher works like this if ciphered message is “p” so it will be decrypted as “a” and so on (based on the char map).

flag : ictf{dictionary_cipher_are_ezzz}

Walking-with-bin

challDesc

Given an image that i need to do some “forensic” thing, from the title i know that i need to use binwalk to check some hidden files in the picture.

Yep, there is a .pdf file. Let’s extract that file with foremost

Open the .pdf file, but it’s a blank pdf! (try ctrl+a and i got the flag :3)

med

flag : ictf{th1s_1s_j0hn_c3n@}

Build-a-cipher 2

challDesc

Given .py file that i need to reverse to decrypt the message.

Soooo basically this file will encrypt our message with “random” numbers from randint function from (1-100) and add the “random” number to the char. To reverse this i just need to change the “n+=random” to “n-=random” because the “random” variable is constantly set to “5” and run the .py file again.

flag : ictf{5huff13d_charac7h3r5}

Lo-Siento-Bella

challDesc

Given a png file that i must extract the Least Significant Bit (given hints on the title -> LSB). LSB is a steganography technique to hide some message in image file but the image remain the same. Lets extract the lsb with zsteg.

flag : ictf{h1d1ng_1n_1ns1gn1f1canc3}

modern-images

challDesc

Another forensic challenge, so the .png file is broken. Lets check the chunk to fix the image! *friendly reminder : .png chunk must contain (PNG signature, IHDR, IDAT, and IEND)

Lets compare the this image with healthy .png file, and just replace the .png signature.

And i got this image, it looks like QR-Code (?) but i can’t scan it :(. Use google to see QR-Code types. Then i visited Wikipedia about QR-Code, and the QR-Code is generated with JAB code, use JABCode to scan the QR-code.

small

small

flag : ictf{m0d3rn_b@rc0d3$_@re_c00l}

Duality

challDesc

Given a .pdf file, is it a real .pdf file or sumthin? lets check it first with binwalk.

Whoops, this is a ELF file! lets remove the .pdf extension and run it!

The program ask some password to get the flag, but i dont know the password yet :( . Time to see the strings from the ELF file to check if the password is hardcoded.

There is a “Superman” string, i think this is the password. Run the ELF again and input password as “Superman”

flag : ictf{c0nv0lut3d_w@ys_to_h1d3_data}

PDF Editors

Last one is forensic chall! The flag is burried, i need to dig it!

The tools that i used to solve this chall is Foxit Reader, just move the AAA strings and i got the flag !

flag : ictf{k@m1_1s_a_g00d_pdf_3dd170r}

Thank you for visiting ! See you in another writeup !!!