[CISCN 2023 初赛]被加密的生产流量
最近搞了一个流量分析神器,找了个流量分析题目练练手,结果是最后没有用到工具
题目是工厂内部员工发送加密后的敏感数据给外部人员,给出附件名称为modbus.pcap
去查了一下modbus是一种串行通信协议,对这种流量分析有通解,第一步先写脚本来分析流量包中Modbus/TCP的协议功能码
直接上链接和图片
`# -- coding: utf-8 --
@Time : 2023/5/27 9:50
@Author : Leekos (modified)
@File : 被加密的生产流量_fixed.py
import pyshark
def get_code(pcap_path="modbus.pcap"):
# 指定 tshark 的绝对路径,确保 pyshark 能找到它
TSHARK_PATH = r"D:\ctf\Wireshark\tshark.exe"
func_codes = {}
captures = None
try:
# keep_packets=False 可以在处理大文件时减少内存占用
captures = pyshark.FileCapture(
pcap_path,
tshark_path=TSHARK_PATH,
keep_packets=False
)
for pkt in captures:
# 检查是否有 modbus 层
# 使用 hasattr 更稳健;也可以尝试访问 pkt.modbus
try:
if hasattr(pkt, "modbus"):
# 有时候字段名可能不同,使用 get_field_value 更通用
val = pkt.modbus.get_field_value('func_code')
if val is None:
# 如果没有取到,跳过
continue
func_code = int(val)
func_codes[func_code] = func_codes.get(func_code, 0) + 1
except AttributeError:
# 某些包访问属性时可能抛错,忽略这些包
continue
except ValueError:
# func_code 无法转换为 int,忽略
continue
except Exception as e:
# 打印警告但不中断整个处理
print("Warning parsing packet:", e)
continue
finally:
# 关闭 capture 以释放资源
if captures is not None:
captures.close()
按 func_code 排序输出,便于阅读
for code in sorted(func_codes.keys()):
print(f"func_code {code}: {func_codes[code]} times")
return func_codes
if name == 'main':
# 如果你的 pcap 文件不叫 modbus.pcap,改这里的文件名或直接把路径作为参数传入
get_code("modbus.pcap")
`

到这步基本就结束了,因为功能6的数量太少,太奇怪了,直接过滤规则写入modbus.func_code == 6 && modbus.request_frame
最后结果绝对隐藏在包中,排除十六进制什么的之后,在追踪流中发现base32数据

提取后解码得到flag

浙公网安备 33010602011771号