diff --git a/README.md b/README.md index 2bf0683..56672ed 100644 --- a/README.md +++ b/README.md @@ -4,316 +4,546 @@ hctf2015 all problems and writeups from propositioners # 全部题目地址 ## WEB题目 + 题目名称:injection + 题目描述:咦,这咋是个白页 + http://120.26.93.115:24317/0311d4a262979e312e1d4d2556581509/index.php + 分值:100 + 开题金币:100 + 奖励金币:200 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/injection =================================================================== + 题目名称:Personal blog + 题目描述:小学弟在大黑客的帮助下,搭建了自己的个人博客. + http://404.hack123.pw/ + 分值:100 + 开题金币:100 + 奖励金币:200 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/PersonalBlog =================================================================== + 题目名称:fuck === + 题目描述: + http://120.26.93.115:18476/eff52083c4d43ad45cc8d6cd17ba13a1/index.php + 分值:75 + 开题金币:75 + 奖励金币:150 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/fuck%3D%3D%3D =================================================================== + 题目名称:404 + 题目描述:咦,404了 + http://120.26.93.115:12340/3d9d48dc016f0417558ff26d82ec13cc/webI.php + 分值:25 + 开题金币:25 + 奖励金币:50 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/404 =================================================================== + 题目名称:Hack my net + 题目描述:就算你我相隔,我也要另辟蹊径 http://120.26.224.102:25045/ea57f09ea421245047b86eaba834fae1/ + 分值:100 + 开题金币:100 + 奖励金币:200 + 源码: =================================================================== + 题目名称:MMD + 题目描述:么么哒~ + http://120.26.93.115:12306/05e8309820953e7620a1ee47441243b6/ + 分值:200 + 开题金币:200 + 奖励金币:200 + 源码: =================================================================== + 题目名称:Server is done + 题目描述:搜索坏了,咋办。
+ http://120.26.93.115:7659/8270537b1512009f6cc7834e3fd0087c/index.php + 分值:175 + 开题金币:175 + 奖励金币:200 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/server%20is%20done =================================================================== + 题目名称:Black eat black(300不足,200有余) + 题目描述:使用该DNS(180.153.47.182)后,你会被劫持哦~ + 分值:300 + 开题金币:300 + 奖励金币:400 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/Black-Eat-Black =================================================================== + 题目名称:FuckPHP(出题人已经谢罪自杀) + 题目描述:哎,这题真的能做么? + http://120.26.93.115:8123/92169de79037c2de72f5088bf1e8310a/index.php + 分值:300 + 开题金币:300 + 奖励金币:400 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/fuckphp =================================================================== + 题目名称:easy xss + 题目描述:你说我这里太短?看样子是你的太长 http://120.26.224.102:54250/0e7d4f3f7e0b6c0f4f6d1cd424732ec5/ + 分值:150 + 开题金币:150 + 奖励金币:200 + 源码: =================================================================== + 题目名称:confused question + 题目描述:我快要晕了 http://120.26.224.102:23333/d20876f3f4d1c8358efcb9c0dde3781b/ + 分值:200 + 开题金币:200 + 奖励金币:200 + 源码: =================================================================== + 题目名称:长江防线固若金汤 + 题目描述:首长,我向您保证,长江防线固若金汤! + http://120.55.112.244:23333/b60b1299c7a06e17c1ab1e9cde510e4a/index.html + 分值:275 + 开题金币:275 + 奖励金币:300 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/%E9%95%BF%E6%B1%9F%E9%98%B2%E7%BA%BF%E5%9B%BA%E8%8B%A5%E9%87%91%E6%B1%A4 =================================================================== + 题目名称:MC服务器租售中心 - 1(真的不是玩MC) + 题目描述:啦啦啦~卖服务器啦~ http://mc.hack123.pw + 分值:300 + 开题金币:300 + 奖励金币:400 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/MC%E6%9C%8D%E5%8A%A1%E5%99%A8%E7%A7%9F%E5%94%AE%E4%B8%AD%E5%BF%83 =================================================================== + 题目名称:MC服务器租售中心 - 2(真的不是玩MC) + 题目描述:啦啦啦~卖服务器啦~ http://mc.hack123.pw + 分值:500 + 开题金币:500 + 奖励金币:300 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/MC%E6%9C%8D%E5%8A%A1%E5%99%A8%E7%A7%9F%E5%94%AE%E4%B8%AD%E5%BF%83 =================================================================== + 题目名称:COMA WHITE + 题目描述:A PILL TO MAKE YOU NUMB + A PILL TO MAKE YOU DUMB + A PILL TO MAKE YOU ANYBODY ELSE + BUT ALL THE DRUGS IN THIS WORLD + WON'T SAVE HER FROM HERSELF + http://120.26.93.115:43635/ff81b5df63ece38b45145ab41827d150/index.html + 分值:200 + 开题金币:200 + 奖励金币:200 + 源码: =================================================================== + ## RE题目 + 题目名称:真的很友善的逆向题(福利) + 题目描述:友善的出题人在抢馄饨的时候有了新的灵感。 + http://120.26.60.159/friendly/0.exe + 分值:150 + 开题金币:150 + 奖励金币:200 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/re150 =================================================================== + 题目名称:来看看出题人疯了没 + 题目描述:在被各种CTF的题目蹂躏后,出题人已经彻底没救了(甜党万岁)。 + http://120.26.60.159/mad/0.exe + 分值:450 + 开题金币:450 + 奖励金币:300 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/RE-HCTF\_450 =================================================================== + 题目名称: 复古的程序 + 题目描述: 出题人比较怀旧,还停留在计算机的启蒙时代 + http://120.26.60.159/re-8086/1000.exe + 分值: 250 + 开题金币: 250 + 奖励金币: 250 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/Re-x8086 =================================================================== + 题目名称: 欧洲人的游戏(你是欧洲人吗?) + 题目描述: 听说,欧洲人和有钱人可以很快做出来 + http://120.26.60.159/re-crc/1000.exe + 分值: 250 + 开题金币: 250 + 奖励金币: 250 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/Re-crc =================================================================== + 题目名称: 混沌ROP + 题目描述: GeruzoniAnsasu给他的学弟讲解了一下rop是什么之后,学弟问到,程序代码全都写成rop的形式会是什么样?答:混沌邪恶。 + http://120.26.60.159/chaos\_rop/sample3 + 分值: 300 + 开题金币: 300 + 奖励金币: 250 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/chaos-rop =================================================================== + 题目名称: PicMatching(别开这题=。=) + 题目描述: + “警告:非信任面孔,禁止通行” + “恩?……我试试能不能伪造一个原主的样子,有点难” + *原图都是5个字符,让你们有点还原出图片的希望:) + http://120.26.60.159/picmatching/kpsample0 + 本体 http://120.26.60.159/picmatching/picmatch + 分值: 450 + 开题金币: 600 + 奖励金币: 300 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/picmatching =================================================================== + ## PWN题目 ## libc ↓↓↓↓↓↓↓↓↓↓ -http://120.26.60.159/libc/libc.so.32 -http://120.26.60.159/libc/libc.so.64 +> http://120.26.60.159/libc/libc.so.32 +> http://120.26.60.159/libc/libc.so.64 ## libc ↑↑↑↑↑↑↑↑↑↑ + 题目名称: 教务处 + 题目描述: Explore给人写了个教务处管理系统。但是这货有点懒,什么东西都要求你按规定格式输入 + nc 120.55.86.95 11111 + http://120.26.60.159/pwn1/pwn1 + 分值: 300 + 开题金币: 300 + 奖励金币: 300 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/Pwn\_JWC =================================================================== + 题目名称: BrainFuck + 题目描述: Fuck!! BrainFuck!! + nc 120.55.86.95 22222 + http://120.26.60.159/pwn2/pwn2 + 分值: 100 + 开题金币:100 + 奖励金币: 200 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/Pwn\_brainFuck =================================================================== + 题目名称: Are you selling sword + 题目描述:出题人最近在贩剑 + nc 120.55.86.95 33333 + http://120.26.60.159/pwn3/pwn3 + 分值:500 + 开题金币:500 + 奖励金币:300 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/Pwn\_AreYouSellingSword =================================================================== + 题目名称: What should I do + 题目描述:I am a program, I don't know what should I do + nc 120.55.86.95 44444 + http://120.26.60.159/pwn4/pwn4 + 分值:200 + 开题金币:200 + 奖励金币:200 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/Pwn\_WhatShouldIDo =================================================================== ## MISC题目 + 题目名称:What Is This + 题目描述:这到底是啥东西?玩玩看?
http://120.26.60.159/WhatIsThis/what-is-this.1d9bb46782a411bdb72ac82590539826
flag为非标准形式。 + 分值:100 + 开题金币:100 + 奖励金币:200 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/WhatIsThis =================================================================== + 题目名称:Andy(你们知道他是谁吗) + 题目描述:Andy的通关密码(flag形式不是hctf{xxx},提交时请以hctf{flag}的形式提交。)
http://120.26.60.159/Andy/Andy.apk.f1bc4dcb815253922a6746316890c05e
+ 分值:100 + 开题金币:100 + 奖励金币:200 + 源码: =================================================================== + 题目名称:送分要不要?(萌新点我) + 题目描述:这题还需要描述么?
http://120.26.60.159/EasyMisc/misc50.28c1c3807a6e3ff9da28b5774dc6fbb0 + 分值:50 + 开题金币:50 + 奖励金币:100 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/%E9%80%81%E5%88%86%E8%A6%81%E4%B8%8D%E8%A6%81%EF%BC%88%E8%90%8C%E6%96%B0%E7%82%B9%E6%88%91%EF%BC%89 =================================================================== + 题目名称:无聊的杂项题(出题人真无聊) + 题目描述:这题真无聊
http://120.26.60.159/BoringMisc/boring.ca9c342905fa022d0377bf6a2886b01d
flag为非标准形式,且flag分两段,分别为flag1:hctf{xxx}和flag2:hctf{yyy},提交时请提交hctf{xxxyyy} + 分值:250 + 开题金币:250 + 奖励金币:250 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/%E6%97%A0%E8%81%8A%E7%9A%84%E9%A2%98%EF%BC%88%E5%87%BA%E9%A2%98%E4%BA%BA%E7%9C%9F%E6%97%A0%E8%81%8A%EF%BC%89 =================================================================== + 题目名称:出题人真无聊(萌新别点) + 题目描述:这是个图片你敢信?
http://120.26.60.159/FuckMisc/fuckme.a8a933dc732d06e2f45f953c7b0a4204 + 分值:500 + 开题金币:500 + 奖励金币:300 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/%E5%87%BA%E9%A2%98%E4%BA%BA%E7%9C%9F%E6%97%A0%E8%81%8A =================================================================== + 题目名称:福利(萌新不要点啊!) + 题目描述:多读书,flag确实在里面哟,就算你众筹来打出题人也没用。 + flag是HCTF{...} + http://120.26.60.159/BaGuaMisc/flag.png + 分值:300 + 开题金币:300 + 奖励金币:400 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/bagua =================================================================== + 题目名称: ShortBin + 题目描述:GeruzoniAnsasu这么长id的人实际上是个非常懒的programmer... + 120.55.113.21:9999 + 分值: 200 + 开题金币: 100 + 奖励金币: 200 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/misc-shortbin =================================================================== + 题目名称: RedefCalc(PPC) + 题目描述:GeruzoniAnsasu的舍友M大大最近去旁听了编译原理,回来问了一个问题把大家都难住了:为啥处理语法树的时候要有人为规定的优先级?如果优先级重新定义的话…… + 120.55.113.21:4799 + 分值:300 + 开题金币: 100 + 奖励金币: 300 + 源码:https://github.com/hduisa/hctf2015-all-problems/tree/master/ppc-redef-calc =================================================================== -* 这里放所有题目的链接 -* 先push到自己的分支,记得创建子目录,最后统一merge,这样不用多下载一份别人的文件,麻烦 -* 关于展示flag的地方有特殊处理的可以改回普通的显示一段话 -* 最好附带一下自己的writeup -