piyolog

piyokangoの備忘録です。セキュリティの出来事を中心にまとめています。このサイトはGoogle Analyticsを利用しています。

Defcon 23 Quals Writeupとかをまとめる予定地

2015年5月15日(JST)より開始されたDefcon CTF 23の予選(オンラインCTF)のWriteUpとかをまとめます。

参加チーム数

少なくとも2800人近く、840以上のチームが登録していた模様。

Writeup (1) Baby's First

Writeup (3) Pwnable

wibbly wobbly timey wimey 2point

Wibbly Wobbly Timey Wimey

Don't blink!

wwtw_c3722e23150e1d5abbc1c248d99d718d.quals.shallweplayaga.me:2606
[Download](http://downloads.notmalware.ru/wwtw_c3722e23150e1d5abbc1c248d99d718d)

twentyfiveseventy 3point

twentyfiveseventy_2809b4d140123e359485305658a2ab40.quals.shallweplayaga.me:1161

[Download](http://downloads.notmalware.ru/twentyfiveseventy_2809b4d140123e359485305658a2ab40)

heapsoffun 4point

If you have been knockedup then you know what to do. Perhaps try "tirer"

sha1sum heapsoffun
5ee5b2cde811e617cd789c73c1d8d2d9e8b27c36

Yes we know the flag is owned by root.

tensixtyseven 4point

tensixtyseven_ed879d24fd6365cf38b6c96b5e077d75.quals.shallweplayaga.me:1161

[Download](http://downloads.notmalware.ru/tensixtyseven_ed879d24fd6365cf38b6c96b5e077d75)

thing2 4point

We have a special guest challenge from thing2.

AppJailLauncher.exe /key:key /port:8200 DconQuals.exe

thing2_e89e83e6cc343256f99fbfe6f434d788.quals.shallweplayaga.me

[Download](http://downloads.notmalware.ru/thing2_e89e83e6cc343256f99fbfe6f434d788)

hackercalc 5point

hackercalc_2e9c870a8449603f8d4b748d78993026.quals.shallweplayaga.me:21222
[Download](http://downloads.notmalware.ru/hackercalc_2e9c870a8449603f8d4b748d78993026)

int3rupted 5point

Connect to int3rupted_3bb8f10793b82841c44a366eb9f27223.quals.shallweplayaga.me, port 0xcccc

secrf 6point

secrf_cdd8445b254189eb39861162d086eb16.quals.shallweplayaga.me:27398
[Download](http://downloads.notmalware.ru/secrf_cdd8445b254189eb39861162d086eb16)

Writeup (4) Reverse Engineering

knockedupd 1point

You went and got it knockedup.

[Download](http://downloads.notmalware.ru/knockedupd_71a592a753bf9dcd7d7ad5fa69b2bab3)

knockedupd_71a592a753bf9dcd7d7ad5fa69b2bab3.quals.shallweplayaga.me

pr0dk3y 2point

Crack me at
pr0dk3y_40687b492c80205cccb34db1eabf6456.quals.shallweplayaga.me:7938
[Download](http://downloads.notmalware.ru/pr0dk3y_40687b492c80205cccb34db1eabf6456)

klug 3point

klug_64eee7bb1da26c44fcb7a15d85a017c9.quals.shallweplayaga.me:52242
[Download](http://downloads.notmalware.ru/klug_64eee7bb1da26c44fcb7a15d85a017c9)

Scrambler 3point

Enhance!

hint: The time of image generation matches the start of the game which can also be viewed on the quals registration page.

[Download](http://downloads.notmalware.ru/scrambler_3ff9e5b9795ac8fc4117da6660ced01b.tar.gz)

Writeup (5) Web

Waiting for your Touch 2point

http://waiting-for-your-touch.quals.shallweplayaga.me

HTTP Basic:

username: come-on-and-slam

password: welcome-to-japan