PolarEDF2026夏季赛wp

这次题挺简单的

服务器端

这次镜像有点问题,要修复一下才起得来,不然一直循环开机

服务器端1

该服务器的操作系统是什么?答案格式:liunx xx.xx.xx AAA
Ubuntu 24.04.4 LTS
attachments/Pasted image 20260607093111.png

服务器端2

该服务器的内核版本是什么?答案格式:x.x.x-x-xx
6.8.0-101-generic
attachments/Pasted image 20260607093208.png

服务器端3

该服务器的主机名是什么?答案格式:xx-x-x-liunx
VM-0-5-ubuntu
attachments/Pasted image 20260607093250.png

服务器端4

该服务器使用什么工具管理服务器?答案格式:宝塔面板
宝塔面板
attachments/Pasted image 20260607093335.png

服务器端5

接上题,该工具的用户名是什么?答案格式:csia12i1
5dbumzgq
attachments/Pasted image 20260607093603.png

服务器端6

在服务器的root目录下,有一个聊天室文件夹,该聊天室的路径是什么?答案格式:xx.E01/xx/…./
贾贾.E01/分区5/root/has-chat
attachments/Pasted image 20260607093805.png

服务器端7

接上题,该服务器的ip地址是多少?答案格式:192.168.x.x
111.229.26.3
attachments/Pasted image 20260607094211.png

服务器端8

接上题,该聊天室的端口是多少?答案格式:1213
9527

服务器端9

该聊天室配置的数据库密码是什么?答案格式:znoqwhqo
b6f64318d9fb4d7d
在has-chat的文件夹里搜索密码,看到提示找到config.js文件,翻了一下在service文件夹里
attachments/Pasted image 20260607201226.png
attachments/Pasted image 20260607095528.png

服务器端10

数据库的名称是什么?答案格式:niicoq
haschat
attachments/Pasted image 20260607095738.png

服务器端11

数据库有几个表名?答案格式:1
6
attachments/Pasted image 20260607100210.png

服务器端12

User表下有几个字段?答案格式:1
14
attachments/Pasted image 20260607100418.png

服务器端13

User表下有几个测试账号?答案格式:1
14
attachments/Pasted image 20260607100732.png

服务器端14

玛格丽特小姐的测试邮箱是什么?答案格式:xnio@128.com
test@163.com

服务器端15

该聊天室项目使用的什么进程管理工具?答案格式:PM2
PM2
attachments/Pasted image 20260607101003.png

服务器端16

分区5的文件系统是什么?答案格式:ext4
ext4
attachments/Pasted image 20260607101233.png

服务器端17

用于安装依赖的命令是什么?答案格式:xxx xxx
npm install
attachments/Pasted image 20260607101330.png

服务器端18

用户最爱玩的游戏的英雄是什么?答案格式:李白
attachments/Pasted image 20260607133447.png

服务器端19

接上题,该文件夹的路径是什么?答案格式:xx.E01/xx/….
贾贾.E01/分区5/www/wwwroot/wzry

服务器端20

该服务器的时区是什么? 答案格式:shangha1/beijinf
Asia/Shanghai
输入timedatectl
attachments/Pasted image 20260607101451.png

移动端

移动端1

手机的操作系统版本是什么?答案格式:3
10
attachments/Pasted image 20260607105034.png

移动端2

嫌疑人王者荣耀的最高战力英雄是谁?答案格式:李白
李信
手机图片里翻到的,额不打游戏惨被晃
attachments/Pasted image 20260607110600.png

移动端3

当月使用wifi流量最多的软件包名是什么?答案格式:com.xxxx.xx
com.qihoo.appstore
排一下序就知道了
attachments/Pasted image 20260607111142.png

移动端4

手机镜像通过什么软件制作的?答案格式:软件名称
雷电手机快取
attachments/Pasted image 20260607104405.png

移动端5

嫌疑人是文玩爱好者,他喜欢的文玩是什么?答案格式:手镯
比赛里没做出来,不知道规范名字
attachments/Pasted image 20260607111241.png

移动端6

嫌疑人在手机中使用的命令行窗口工具是什么?答案格式:cmd
Termux
attachments/Pasted image 20260607111427.png

移动端7

嫌疑人使用命令行窗口工具一共输入过几条命令?答案:1
6
直接去翻包里的数据,看到history爽了
attachments/Pasted image 20260607111652.png

移动端8

嫌疑人使用的聊天软件包名是什么?答案格式:com.xxx.xxx
com.utalk1.im
很多线索能看出来是UUUtalk
attachments/Pasted image 20260607112523.png

移动端9

嫌疑人最常用的ai软件是什么?答案格式:软件名称
口袋AI
查看使用记录
attachments/Pasted image 20260607112606.png

移动端10

聊天软件的加密数据库是什么?答案格式:xxx.db
wk_31aa3a4add7d4659bb878f99440a4381.db
点开包,这个打不开的就是加密的,第一个能直接开
attachments/Pasted image 20260607113207.png

移动端11

嫌疑人使用什么货币流通赃款?答案格式:货币名称
这个得先解密数据库,密码是名字31aa3a4add7d4659bb878f99440a4381
我用的是sqlcipher
USTD
attachments/Pasted image 20260607215144.png

移动端12

嫌疑人的邀请码是多少?答案格式:123456
ZZNB666
也在这个数据库里
attachments/Pasted image 20260607224828.png

移动端13

其常用的AI大模型是什么?答案格式:Qwen3.7-Max
DeepSeek-R1-Distill-Qwen-1.5B-Q4_K_M
在包里,比赛的时候被晃了,我去我说这名字这么长就没交
attachments/Pasted image 20260607205038.png

移动端14

嫌疑人2026年4月28日12:57问AI的问题是什么?答案格式:我是谁
如何吸引大家下载性感视频APP
在session-metadata.json里
attachments/Pasted image 20260607205354.png

移动端15

分析嫌疑人使用的虚拟定位应用,提取出该应用在崩溃监控平台中生成的唯一设备标识符(UUID)是什么?答案格式:xx-xx-xx-xx-xx
c1f47f87-a33f-40e6-972f-9def111104cc
先要找到这个虚拟定位应用
attachments/Pasted image 20260608112734.png
打开数据库
attachments/Pasted image 20260608113441.png

0000  00 63 00 31 00 66 00 34 00 37 00 66 00 38 00 37  .c.1.f.4.7.f.8.7 
0010  00 2d 00 61 00 33 00 33 00 66 00 2d 00 34 00 30  .-.a.3.3.f.-.4.0 
0020  00 65 00 36 00 2d 00 39 00 37 00 32 00 66 00 2d  .e.6.-.9.7.2.f.- 
0030  00 39 00 64 00 65 00 66 00 31 00 31 00 31 00 31  .9.d.e.f.1.1.1.1 
0040  00 30 00 34 00 63 00 63                          .0.4.c.c                  

移动端16

“私密影院”的签名证书MD5是多少?答案格式:abc123
403c53e95d9bd0b10c46a383dd1a221c
attachments/Pasted image 20260607113307.png

移动端17

“私密影院”的为危险权限有几个?答案格式:1
2
attachments/Pasted image 20260607113321.png

移动端18

“私密影院”的回传服务器ip及端口是多少?答案格式:127.0.0.1:1111
192.168.8.36:8888
attachments/Pasted image 20260607114800.png

移动端19

“私密影院”的管理员账号密码是什么?答案格式:账号_密码
DongBeiMeiMo_PengPengLovX-250210
直接看源代码
attachments/Pasted image 20260607114959.png
attachments/Pasted image 20260607114905.png
attachments/Pasted image 20260607114621.png
attachments/Pasted image 20260607114606.png

移动端20

“私密影院”窃取的短信有多少条?答案格式:1
1156347
attachments/Pasted image 20260607132609.png

PC端

PC端1

此电脑的默认浏览器是什么?答案格式:Google Chrome
Microsoft Edge
attachments/Pasted image 20260607105340.png

PC端2

此电脑的当前MAC地址是多少?答案格式:xx-xx-xx-xx-xx-xx
 00-0C-29-FF-80-1D
attachments/Pasted image 20260607105549.png

PC端3

此电脑蓝牙网络连接的MAC地址是多少?答案格式:xx-xx-xx-xx-xx-xx
98-5F-41-8D-A0-49
attachments/Pasted image 20260607105538.png

PC端4

此电脑的产品密钥是多少?答案格式:xxx-xxx-xxx-xxx-xxx
W269N-WFGWX-YVC9B-4J6C9-T83GX
attachments/Pasted image 20260607105510.png

PC端5

此电脑的注册所有者?答案格式:(1111@gmail.com)
263341492@qq.com
attachments/Pasted image 20260607105454.png

PC端6

此电脑的node版本是多少?答案格式:v1.1.1(以实际为准)
v24.15.0
attachments/Pasted image 20260607110249.png

PC端7

邮件中秘密传输的信息?答案格式:谁懂我多么不舍得
我的爱已失眠
在网易云邮箱里看到已发送的文本
attachments/Pasted image 20260608091453.png
放到零宽字节里解密可知
attachments/Pasted image 20260608091443.png

PC端8 2026夏季个人挑战赛

AI软件中存在的flag是什么?(如果需要登陆密码,登录密码是waslhf加两个重复数字,比如waslhf00。)答案格式:flag{xxxxxxxxxxxxxxxxxxxxxx}
在.astrbot文件夹里全文搜索
flag{example_random_string_here}
attachments/Pasted image 20260608092454.png

PC端9 2026夏季个人挑战赛

AI软件使用的模型和api_key是什么?(模型名称即可,不要带版本号)答案格式:chatgpt-apikey
deepseek-sk-a986d6ecb8264797a252805a01b700b9
在cmd_config.json文件里看到
attachments/Pasted image 20260608092946.png

PC端10 2026夏季个人挑战赛

嫌疑人使用远程连接软件连接过的服务器ip是多少?答案格式:1.1.1.1
49.233.169.226
这个X火眼没有识别出来,所以要自己仿真看看
attachments/Pasted image 20260608093349.png

PC端11 2026夏季个人挑战赛

用户为小野猫的AI机器人为他生成的密钥是什么?答案格式:1-1-1(以实际为准)
在浏览记录里看到小智AI控制台,密码在回收站里
7391-2048-5566
attachments/Pasted image 20260608105748.png
attachments/Pasted image 20260608105901.png
账号是有保存的信息
attachments/Pasted image 20260608105958.png
attachments/Pasted image 20260608110117.png

PC端12 2026夏季个人挑战赛

vc容器的挂载密码?答案格式:以实际为准
201609-1-1-986677384885
在下载的VC文件夹里看到vc密码jpg,估计考察的是文件隐写
attachments/Pasted image 20260608094338.png
attachments/Pasted image 20260608094445.png
扫码有
attachments/Pasted image 20260608094806.png
额,难绷,用随波逐流一下分离一下
attachments/Pasted image 20260608095051.png
爆破密码
003322
attachments/Pasted image 20260608095156.png
里面有图片
attachments/Pasted image 20260608095316.png
提示挂载密码为备案号
在历史备案里查询
201609-1-1-986677384885
attachments/Pasted image 20260608095756.png

PC端13 2026夏季个人挑战赛

病毒程序最终会连接服务器的ip地址和端口?答案格式:1.1.1.1:22
49.233.169.226:11111
挂载VC容器
attachments/Pasted image 20260608100308.png
丢到微步里去看看
attachments/Pasted image 20260608100450.png

PC端14 2026夏季个人挑战赛

apk中的密码?答案格式:11111
123456
apk解压,发现dex文件被加密了
attachments/Pasted image 20260608101042.png
根据提示,解密文件

这里有一个”坏“掉的安卓软件。
1.安全团队已经破解了修复这个软件的密钥:1234567890123456,但是必须要足够32字节ljust(32)。
2.提取 IV:确保使用正确的初始化向量(IV)进行解密。(从你怀疑的文件中提取噢)(前16字节)
3.AES-CBC 解密:通过 AES 算法的 CBC 模式解密数据并去除填充,恢复原始数据。
tip:这个软件只喜欢class.dex命名噢

脚本来自Serendipity的wp PolarEDF 2026夏季个人挑战赛wp

from Crypto.Cipher import AES

key=b'1234567890123456'.ljust(32)

for enc_file in ['encrypted_classes.dex','encrypted_classes2.dex','encrypted_classes3.dex']:
    with open(enc_file,'rb') as f:
        enc_data=f.read()
    iv=enc_data[:16]
    ciphertext=enc_data[16:]
    cipher=AES.new(key,AES.MODE_CBC,iv)
    plaintext=cipher.decrypt(ciphertext)
    pad_len=plaintext[-1]
    if pad_len<=16:
        plaintext=plaintext[:-pad_len]
    with open(enc_file.replace('encrypted_',''),'wb') as f:
        f.write(plaintext)

attachments/Pasted image 20260608104000.png
在dex3的MainActivity中找到密码

String correctPassword = hexToString("313233343536");
        if (enteredPassword.equals(correctPassword)) {
            String decryptedFlag = xorDecryptHex("4e44494f535a5d4f5d47595d4946495b404142414d5f47514d434c495b4c55", 40);
password=bytes.fromhex("313233343536").decode()
print("Password:",password)

123456

PC端15 2026夏季个人挑战赛

apk中的flag是什么?答案格式:flag{xxxxxxxxx}
见上题
flag{ruguoquanashijiewoyekdasd}

encypted_password=bytes.fromhex("4e44494f535a5d4f5d47595d4946495b404142414d5f47514d434c495b4c55")
xor_key=40
flag=bytes([b^xor_key for b in encypted_password]).decode()
print("Flag:",flag)

attachments/Pasted image 20260608104559.png

posted @ 2026-06-08 12:56  Yiyouyy  阅读(51)  评论(0)    收藏  举报