当前位置:网站首页>Blue Hat Cup 2022 part WP
Blue Hat Cup 2022 part WP
2022-07-18 14:07:00 【Fnylad】
MISCdomainhackerdomainhacker2 Electronic forensics, mobile forensics 1 Mobile forensics 2 Computer forensics 1 Computer forensics 2 Computer forensics 3 Computer forensics 4 Program analysis 1 Program analysis 2 Program analysis 3 Program analysis 4 Website forensics 1 Website forensics 2 Website forensics 3
MISC
domainhacker
Filter http
file -> Export object http
Then there is 
Or directly

Transfer and store the original data to 010 Editor gets rar Compressed package
It is speculated that the decryption password is not far ahead of this stream The first 14 A flow


password SecretsPassw0rds

domainhacker2
The steps are the same as above , The difference is ntds.rar The title already exists password :FakePassword123$
Then Baidu searched how to analyze ntds, find github Last script
python secretsdump.py -ntds C:\Users\86181\Desktop\ Blue Hat Cup \ntds\new\ActiveDirectory\ntds.dit -system C:\Users\86181\Desktop\ Blue Hat Cup \ntds\new\registry\system -security C:\Users\86181\Desktop\ Blue Hat Cup \ntds\new\registry\security -history local

Electronic forensics
Mobile forensics 1
open Apple test see exe Pangu stone reader
Direct search 
export , Look at the resolution 360x360
Mobile forensics 2
First, I found the express delivery without any results , Mr. Cha Jiang checked the chat records and found 
Computer forensics 1
python vol.py -f ../1.dmp --profile=Win7SP1x64 mimikatz
Computer forensics 2
python vol.py -f ../1.dmp --profile=Win7SP1x64 pslist
Computer forensics 3
E01 With forensics master , Found to have bitlocker, But there is no recovery key , therefore passware shuttle



368346-029557-428142-651420-492261-552431-515438-338239
Get the key With forensics master Bitlocker Decryption on Or open it directly passware Decrypted image
Get four files
hold pass.txt Import tool->Dictionary Manager

Custom attack



Computer forensics 4
Direct shuttle 
No password found , But the file has been decrypted .
foremost file obtain zip Then violent solution


Program analysis 1
jadx open 
Program analysis 2
minmtta.hemjcbm.ahibyws.MainActivity
Program analysis 3
Program analysis 4
There are thousands of dangers ,root Article 1 with a
Safety inspection , Guess is detecting root

answer : a
Website forensics 1
Website forensics 2
look for sql Connect the page , You can find it globally localhost perhaps (127.0.0.1) Find out 

Website forensics 3
First find the name of the database where the data is stored , Global search

边栏推荐
- Dwelling apartment rental system based on jsp+servlet
- [target tracking] image inter frame difference target detection based on background subtraction and MATLAB simulation
- [brand special session] breakthrough across x, new opportunities for audio and video cohesion
- preg_ Replace Code Execution Vulnerability [bjdctf2020]zjctf, but so
- [JMeter] the Chinese display of JMeter response message is garbled
- 文旅夜游:城市经济复苏增长新机遇
- math_basic简单不等式组的导出结论
- 2018 Jiangsu Provincial Information and future programming expert competition test question -- (New) chicken and rabbit in the same cage
- phpmyadmin 4.8.1远程文件包含漏洞之[GWCTF 2019]我有一个数据库
- 二叉搜索树BST
猜你喜欢

DOM operation of JS -- operation document tree
![[phase locked loop] design and Simulation of all digital phase locked loop based on MATLAB](/img/3c/9fe4aec90506cef4bf0a639366263d.png)
[phase locked loop] design and Simulation of all digital phase locked loop based on MATLAB

Interview problem: how to close an order without using a scheduled task?

math_ Derivation of ordering inequality

Cultural tourism Night Tour: new opportunities for urban economic recovery and growth

Tencent employees post to find objects, indicating that they prefer programmers! Comments are hot Dark horse headlines

$attrs is readonly $listeners is readonly error reporting solution

PHP QRCode生成二维码

Sword finger offer19 regular expression matching string dynamic programming

Dwelling apartment rental system based on jsp+servlet
随机推荐
MySQL - ER model
Idea merges dev branch code into master and so on
【最全最详细】七种分布式全局 ID 生成策略
MySQL problems
ping 命令还能这么玩?
PageRank的原理和实现
2018 Jiangsu Provincial Information and future programming expert competition test question -- (New) chicken and rabbit in the same cage
[phase locked loop] design and Simulation of all digital phase locked loop based on MATLAB
Simulation volume leetcode [general] 1765 The highest point in the map
Mysql 问题
二叉树,遍历
Binary tree, traversal
二叉搜索树BST
MySQL的DML(數據操縱語言)
Cultural tourism Night Tour: new opportunities for urban economic recovery and growth
The open and closed interval of the mean value theorem of higher numbers | integrals, the first mean value theorem of integrals and its generalization
Wechat applet training | Chinese dictation tool based on cloud database
微信小程序实训|基于云数据库的语文听写工具
【深度强化学习-笔记 02】
积分签到吸引用户的两种低成本做法

