Oke gaes kembali lagi dengan gw Yukinoshita47 kali ini gw ngikuti event CTF Diskominfo Kota Serang yang beralamat di https://ctf.serangkota.go.id dan gw buat Write Up ini setelah gw Quit dari event tersebut atau udah stuck bingung mau ngapain lagi buat ngerjain soal atau challenge lainnya. lebih tepat nya N Y E R A H wkwkwkwkwk.
nah Challenge nya yg berhasil gw selesaikan antara lain
- Misc - Bonus
- Binary Exploitation - Urrlib Service
- OSINT - OSEEN
- Forensic - Fixetool
- Cryptography - 64
- Cryptography - 32
- OSINT - Rahasia Username
- Cryptography - Rev
- Cryptography - Dotted
- Forensic - Kereta
- Cryptography - 16
Nah mari kita tuntaskan Write Up Challenge nya .
1. BONUS
untuk bonus gw gak perlu jelasin karena flag nya udah ada
Bonus 2 : DiskoCTF{hints!}
Bonus 3 : DiskoCTF{we've_should_sorry_to_you_guys}
2. URLLIB SERVICE
Hai.. admin membuat sebuah service untuk mengecheck apakah website tersebut up atau down loh menggunakan bahasa pemrograman Python dan modules urllib.
Tapi... sepertinya urllib memiliki celah CVE
nc ctf.serangkota.go.id 9970
Melihat sebuah komentar di platform "lebih dari tv" mungkin akan mendapatkan flag
Format Flag: DiskoCTF{}
terlihat soal yang ini seperti mau mengerjain kita buat searching di yutup atau buat analisa gambar dibawah ini.
karena ini soal tentang OSINT ya harus mencari intinya maka dari itu langkah awal dan yang paling dasar dari OSINT itu adalah Googling nah jika tujuan kita kali ini mencari flag maka tahap gw coba searching dengan keyword "DiskoCTF{" dan hasil nya muncul seperti ini
dan flag nya adalah DiskoCTF{in_distant_memory}
nah challenge ini cukup mudah sekali seperti biasa untuk analisa forensic gambar itu ya kita cek terlebih dahulu exif metadata nya karena dibalik exit selalu ada informasi terkait titik koordinat GPS Foto tersebut diambil/dipotret, pesan rahasia via steganography, jenis kamera, dll
untuk mendapatkan info metadata itu cukup gunakan aja tool online dari imageforensic.org dan kalian akan langsung nemu flag nya seperti gambar dibawah ini.
flag nya adalah
DiskoCTF{depressed_girl_in_sea_and_give_up_the_fight}
5. 64
challenge ini adalah paling basic dari event-event CTF ya betul encode dan decode nah dari angka 64 pasti pikiran pertama kita tertuju di Base64 berikut challenge nya.
decode aja
RGlza29DVEZ7YW5vdGhlcl9yZXByZXNlbnRhdGlvbl90aG
F0X2NvdWxkX2JlX3VzZWRfaW5fcHJpbnRhYmxlX2FzY2lpfQo=
di tool online base64decode.org maka akan langsung keliatan flag nya.
dan flag nya adalah DiskoCTF{another_representation_that_could_be_used_in_printable_ascii}
6. 32
decode aja di tool online ntar keliatan itu flag nya
flag nya adalah DiskoCTF{rax_itu_buat_64_sedangkan_eax_itu_32}
......................................................................................................... 105
................................................................................................................... 115
........................................................................................................... 108
............................................................................................................... 111
................................................................... 67
.................................................................................... 84
...................................................................... 70
........................................................................................................................... 124
............................................................................................................. 109
..................................................................................................... 101
.............................................................................................................. 110
..................................................................................................................... 117
.............................................................................................................. 110
....................................................................................................... 103
....................................................................................................... 103
..................................................................................................................... 117
............................................................................................... 95
................................................................................................. 97
.......................................................................................................... 106
................................................................................................. 97
........................................................................................................... 108
................................................................................................. 97
.............................................................................................................. 110
............................................................................................... 95
..................................................................................................................... 117
.............................................................................................................. 110
.................................................................................................................... 116
..................................................................................................................... 117
........................................................................................................... 107
............................................................................................... 95
............................................................................................................. 109
..................................................................................................... 101
.............................................................................................................. 110
....................................................................................................... 103
..................................................................................................... 101
.............................................................................................................. 110
......................................................................................................................... 121
............................................. 45
............................................................................................................. 109
................................................................................................. 97
........................................................................................................... 107
................................................................................................................... 115
..................................................................................................................... 117
.................................................................................................... 100
............................................................................................... 95
................................................................................................................... 115
................................................................................................. 97
......................................................................................................................... 121
................................................................................................. 97
............................................................................................... 95
............................................................................................................. 109
..................................................................................................... 101
.............................................................................................................. 110
....................................................................................................... 103
..................................................................................................... 101
.................................................................................................... 100
............................................................................................................... 111
.................................................................................................................... 116
............................................................................................................................. 125
..........
Hasilnya berupa angka dilihat dari jumlah yang sampai ratusan itu ya betul itu adalah karakter ASCII kalian bisa liat sendiri tabel bilangan dibawah ini.
angka tadi di dikonversi dari bilangan desimal ke character hasil nya adalah
68 D
105 i
115 s
107 k
111 o
67 C
84 T
70 F
124 {
109 m
101 e
110 n
117 u
110 n
103 g
103 g
117 u
95 _
97 a
106 j
97 a
107 k
97 a
110 n
95 _
117 u
110 n
116 t
117 u
107 k
95 _
109 m
101 e
110 n
103 g
101 e
110 n
121 y
45 -
109 m
97 a
107 k
115 s
117 u
100 d
95 _
115 s
97 a
121 y
97 a
95 _
109 m
101 e
110 n
103 g
101 e
100 d
111 o
116 t
125 }
ya betul flag nya adalah DiskoCTF{menunggu_ajakan_untuk_mengeny-maksud_saya_mengedot}
10. KERETA
oke lanjut ke challenge forensic kali ini kita disuruh anlisa file sl_5.02-1_amd64.deb berikut challenge nya.
pertama download terlebih dahulu file sl_5.02-1_amd64.deb nya
kemudian extract file 480 dengan perintah
tar -xf 480.xz
kemudian tekan enter
lalu masuk ke diraktori usr/share/doc/sl dengan perintah
cd usr/share/doc/sl
kemudian tekan enter
kemudian liat file README dengan perintah
cat README
kemudian tekan enter
dan flag nya pun keliatan
challenge selesai