{"id":66,"date":"2025-09-03T18:28:32","date_gmt":"2025-09-03T10:28:32","guid":{"rendered":"http:\/\/www.xuanbin.top\/?p=66"},"modified":"2025-09-10T20:20:16","modified_gmt":"2025-09-10T12:20:16","slug":"nepctf2025-reverse-%e5%a4%8d%e7%8e%b0%ef%bc%88%e9%83%a8%e5%88%86%ef%bc%89","status":"publish","type":"post","link":"http:\/\/www.xuanbin.top\/index.php\/2025\/09\/03\/nepctf2025-reverse-%e5%a4%8d%e7%8e%b0%ef%bc%88%e9%83%a8%e5%88%86%ef%bc%89\/","title":{"rendered":"NepCTF2025\u2014\u2014REVERSE\u2014\u2014\u590d\u73b0\uff08\u90e8\u5206\uff09"},"content":{"rendered":"\n<p>\u6691\u5047\u6253\u4e86\u633a\u591a\u7ebf\u4e0a\u7684CTF\uff0cNepCTF\u7684RE\u9898\u8d28\u91cf\u4e00\u5982\u65e2\u5f80\u7684\u9ad8\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">realme<\/h2>\n\n\n\n<p>\u901a\u8fc7\u5b57\u7b26\u4e32\u5b9a\u4f4d\u6cd5\u5b9a\u4f4d\u5230\u4e3b\u51fd\u6570\uff0c\u521d\u6b21\u5206\u6790\u53d1\u73b0\u662fRC4\u9b54\u6539\uff0c\u7f6e\u6362S\u76d2\u65f6\u5f02\u62160X66\u4e14\u6700\u540e\u7684\u5f02\u6216\u6539\u4e3a\u6a21\u9664\u3002\u540e\u7eed\u53d1\u73b0\u6709\u53cd\u8c03\u8bd5\uff0c\u8fd9\u91cc\u7ed9\u51faScyllaHide\u63d2\u4ef6dump\u548cpatch\u53cd\u8c03\u8bd5\u4e24\u79cd\u505a\u6cd5\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"788\" height=\"257\" src=\"http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756887899-QQ_1756887892923.png\" alt=\"\" class=\"wp-image-67\" srcset=\"http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756887899-QQ_1756887892923.png 788w, http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756887899-QQ_1756887892923-300x98.png 300w, http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756887899-QQ_1756887892923-768x250.png 768w\" sizes=\"auto, (max-width: 788px) 100vw, 788px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">ScyllaHide\u63d2\u4ef6dump<\/h3>\n\n\n\n<p>\u901a\u8fc7ScyllaHide\u81ea\u52a8\u8fc7\u53cd\u8c03\u8bd5\uff0c\u7ed3\u5408\u7a0b\u5e8f\u4e0d\u76f4\u63a5\u9000\u51fa\u731c\u6d4b\u6709\u81ea\u4fee\u6539\uff0c\u5728\u8f93\u51fa\u65f6dump\uff0c\u53d1\u73b0\u5b9e\u9645\u9b54\u6539\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"564\" height=\"372\" src=\"http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756888933-QQ_1756888927594.png\" alt=\"\" class=\"wp-image-68\" srcset=\"http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756888933-QQ_1756888927594.png 564w, http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756888933-QQ_1756888927594-300x198.png 300w\" sizes=\"auto, (max-width: 564px) 100vw, 564px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"574\" height=\"345\" src=\"http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756888954-QQ_1756888949374.png\" alt=\"\" class=\"wp-image-69\" srcset=\"http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756888954-QQ_1756888949374.png 574w, http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756888954-QQ_1756888949374-300x180.png 300w\" sizes=\"auto, (max-width: 574px) 100vw, 574px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">patch\u53cd\u8c03\u8bd5<\/h3>\n\n\n\n<p>\u901a\u8fc7\u6808\u56de\u6eaf\u6cd5\u5b9a\u4f4d\u5230\u7b2c\u4e00\u6b21\u53cd\u8c03\u8bd5\u5904\uff0cHOOK\u4e86scanf\u51fd\u6570\uff0c\u4fee\u6539\u4e86\u9b54\u6539RC4\u7684\u903b\u8f91\u5e76\u901a\u8fc7\u5f02\u6216\u6fc0\u6d3b\u7b2c\u4e8c\u6b21\u53cd\u8c03\u8bd5\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"245\" height=\"49\" src=\"http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756889409-QQ_1756889381862.png\" alt=\"\" class=\"wp-image-71\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"426\" height=\"155\" src=\"http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756889420-QQ_1756889415376.png\" alt=\"\" class=\"wp-image-72\" srcset=\"http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756889420-QQ_1756889415376.png 426w, http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756889420-QQ_1756889415376-300x109.png 300w\" sizes=\"auto, (max-width: 426px) 100vw, 426px\" \/><\/figure>\n\n\n\n<p>\u7b2c\u4e8c\u6b21\u518d\u6b21\u4fee\u6539\u9b54\u6539RC4\u903b\u8f91\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"375\" height=\"260\" src=\"http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756895108-QQ_1756895084469.png\" alt=\"\" class=\"wp-image-73\" style=\"width:428px;height:auto\" srcset=\"http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756895108-QQ_1756895084469.png 375w, http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756895108-QQ_1756895084469-300x208.png 300w\" sizes=\"auto, (max-width: 375px) 100vw, 375px\" \/><\/figure>\n\n\n\n<p>\u6700\u540e\u7684\u4e24\u5904\u9b54\u6539<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"591\" height=\"321\" src=\"http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756895225-QQ_1756895207392.png\" alt=\"\" class=\"wp-image-76\" srcset=\"http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756895225-QQ_1756895207392.png 591w, http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756895225-QQ_1756895207392-300x163.png 300w\" sizes=\"auto, (max-width: 591px) 100vw, 591px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"542\" height=\"211\" src=\"http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756895256-QQ_1756895251219.png\" alt=\"\" class=\"wp-image-77\" srcset=\"http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756895256-QQ_1756895251219.png 542w, http:\/\/www.xuanbin.top\/wp-content\/uploads\/2025\/09\/1756895256-QQ_1756895251219-300x117.png 300w\" sizes=\"auto, (max-width: 542px) 100vw, 542px\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code>#include&lt;iostream&gt;\n#include&lt;string&gt;\n#include&lt;string.h&gt;\nusing namespace std;\nvoid rc4init(unsigned char K&#91;],unsigned char key&#91;])\n{\n    unsigned char S&#91;256];\n    unsigned char T&#91;256];\n    int Len=strlen((char*)(key));\n    for(int i=0;i&lt;256;i++)\n    {\n        S&#91;i]=i^0xCF;\n        T&#91;i]=key&#91;i%Len];\n    }\n    int j=0;\n    int temp=0;\n    for(int i=0;i&lt;256;i++)\n    {\n        j=(j+S&#91;i]+T&#91;i])%256;\n        temp=S&#91;i];\n        S&#91;i]=S&#91;j];\n        S&#91;j]=temp^0xAD;\n    }\n    \/\/\u751f\u6210\u5bc6\u94a5\u6d41\n    int i = 0;\n    j=0;\n    int t = 0;\n    unsigned long k = 0;\n    for(int time=0;time&lt;256;time++)\n    {\n        i=(i+1)%256;\n        j=(j+i*S&#91;i])%256;\n        temp=S&#91;i];\n        S&#91;i]=S&#91;j];\n        S&#91;j]=temp;\n        t=(S&#91;i]+S&#91;j])%256;\n        K&#91;time]=S&#91;t];\n    }\n}\nint main()\n{\n    unsigned char K&#91;256]={0};\n    unsigned char key&#91;]=\"Y0u_Can't_F1nd_Me!\";\n    rc4init(K,key);\n    unsigned char flag&#91;]={  0x50, 0x59, 0xA2, 0x94, 0x2E, 0x8E, 0x5C, 0x95, 0x79, 0x16, \n  0xE5, 0x36, 0x60, 0xC7, 0xE8, 0x06, 0x33, 0x78, 0xF0, 0xD0, \n  0x36, 0xC8, 0x73, 0x1B, 0x65, 0x40, 0xB5, 0xD4, 0xE8, 0x9C, \n  0x65, 0xF4, 0xBA, 0x62, 0xD0};\n    for(int i=0;i&lt;sizeof(flag)\/sizeof(flag&#91;0]);i++)\n    {\n        if(i%2==0)\n        {\n            flag&#91;i]+=K&#91;i];\n        }\n        else\n        {\n            flag&#91;i]-=K&#91;i];\n        }\n        cout&lt;&lt;flag&#91;i];\n    }\n}<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">Crackme<\/h2>\n\n\n\n<p>\u5f85\u7eed<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">qrs<\/h2>\n\n\n\n<p>\u5f85\u7eed<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6691\u5047\u6253\u4e86\u633a\u591a\u7ebf\u4e0a\u7684CTF\uff0cNepCTF\u7684RE\u9898\u8d28\u91cf\u4e00\u5982\u65e2\u5f80\u7684\u9ad8\u3002 realme \u901a\u8fc7\u5b57\u7b26\u4e32\u5b9a\u4f4d\u6cd5\u5b9a\u4f4d\u5230\u4e3b\u51fd\u6570\uff0c\u521d\u6b21\u5206\u6790\u53d1\u73b0\u662fRC4 &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"emotion":"","emotion_color":"","title_style":"","license":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-66","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"http:\/\/www.xuanbin.top\/index.php\/wp-json\/wp\/v2\/posts\/66","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.xuanbin.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.xuanbin.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.xuanbin.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.xuanbin.top\/index.php\/wp-json\/wp\/v2\/comments?post=66"}],"version-history":[{"count":4,"href":"http:\/\/www.xuanbin.top\/index.php\/wp-json\/wp\/v2\/posts\/66\/revisions"}],"predecessor-version":[{"id":110,"href":"http:\/\/www.xuanbin.top\/index.php\/wp-json\/wp\/v2\/posts\/66\/revisions\/110"}],"wp:attachment":[{"href":"http:\/\/www.xuanbin.top\/index.php\/wp-json\/wp\/v2\/media?parent=66"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.xuanbin.top\/index.php\/wp-json\/wp\/v2\/categories?post=66"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.xuanbin.top\/index.php\/wp-json\/wp\/v2\/tags?post=66"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}