39 lines
1.1 KiB
Python
39 lines
1.1 KiB
Python
"""
|
|||
|
|
EXAMPLE: Pwn2Win 2021 — "A2S" (Crypto, 355p, 10 solves)
|
||
|
|
https://github.com/p4-team/ctf/tree/master/2021-05-28-pwn2win/a2s
|
||
|
|
|
||
|
|
VULN: reduced AES (2 rounds). A differential attack (attack.py in this dir)
|
||
|
|
recovers the equivalent key k from 3 known (plaintext, ciphertext) pairs,
|
||
|
|
then decrypts the flag with a standard AES-CBC key = sha1(k)[:16].
|
||
|
|
|
||
|
|
The original challenge used Python 2 (`str(k)` for the sha1 input). The
|
||
|
|
canonical solver is attack.py and it prints the flag directly. This wrapper
|
||
|
|
runs attack.py and extracts the flag so the example stays reproducible.
|
||
|
|
|
||
|
|
Run:
|
||
|
|
cd /home/code/ctfkit/examples/a2s
|
||
|
|
python3 solve.py
|
||
|
|
Expected flag: CTF-BR{bu7_1f_7h0u6h7_c0rrup75_l4n6u463,_l4n6u463_c4n_4l50_c0rrup7_7h0u6h7}
|
||
|
|
"""
|
||
|
|
import os
|
||
|
|
import re
|
||
|
|
import subprocess
|
||
|
|
import sys
|
||
|
|
|
||
|
|
HERE = os.path.dirname(os.path.abspath(__file__))
|
||
|
|
|
||
|
|
|
||
|
|
def main():
|
||
|
|
out = subprocess.run(
|
||
|
|
[sys.executable, os.path.join(HERE, "attack.py")],
|
||
|
|
capture_output=True, text=True,
|
||
|
|
).stdout
|
||
|
|
m = re.search(r"CTF-BR\{[^}]+\}", out)
|
||
|
|
flag = m.group(0) if m else None
|
||
|
|
print("FLAG =", flag)
|
||
|
|
return flag
|
||
|
|
|
||
|
|
|
||
|
|
if __name__ == "__main__":
|
||
|
|
main()
|