<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>LinkStar‘s Blog</title>
        <link>https://blog.miaoaixuan.cn/</link>
        <description>这是一个由NotionNext生成的站点</description>
        <lastBuildDate>Thu, 11 Dec 2025 09:30:28 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>zh-CN</language>
        <copyright>All rights reserved 2025, LinkStar</copyright>
        <item>
            <title><![CDATA[py python]]></title>
            <link>https://blog.miaoaixuan.cn/article/2944cea1-b73e-80d8-afce-dc9bccd05be3</link>
            <guid>https://blog.miaoaixuan.cn/article/2944cea1-b73e-80d8-afce-dc9bccd05be3</guid>
            <pubDate>Wed, 22 Oct 2025 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-2944cea1b73e80d8afcedc9bccd05be3"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><div class="notion-callout notion-gray_background_co notion-block-2944cea1b73e80f49391f94127a6d28c"><div class="notion-page-icon-inline notion-page-icon-span"><span class="notion-page-icon" role="img" aria-label="😀">😀</span></div><div class="notion-callout-text">这里写文章的前言：
一个简单的开头,简述这篇文章讨论的问题、目标、人物、背景是什么？并简述你给出的答案。<div class="notion-text notion-block-2944cea1b73e80c9b7b6fbe00be6badb">可以说说你的故事：阻碍、努力、结果成果，意外与转折。</div></div></div><div class="notion-blank notion-block-2944cea1b73e80db8220e81bab27e600"> </div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2944cea1b73e8030bc30f6c98b8bfe35" data-id="2944cea1b73e8030bc30f6c98b8bfe35"><span><div id="2944cea1b73e8030bc30f6c98b8bfe35" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2944cea1b73e8030bc30f6c98b8bfe35" title="📝 主旨内容"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">📝 主旨内容</span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2944cea1b73e80638bb8f5e696728118" data-id="2944cea1b73e80638bb8f5e696728118"><span><div id="2944cea1b73e80638bb8f5e696728118" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2944cea1b73e80638bb8f5e696728118" title="观点1"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">观点1</span></span></h3><blockquote class="notion-quote notion-block-2944cea1b73e8040a544fce3ac456f0b"><div>引用的话语</div></blockquote><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2944cea1b73e804fa963cf33b1897be6" data-id="2944cea1b73e804fa963cf33b1897be6"><span><div id="2944cea1b73e804fa963cf33b1897be6" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2944cea1b73e804fa963cf33b1897be6" title="观点2"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">观点2</span></span></h3><blockquote class="notion-quote notion-block-2944cea1b73e80f988bff207ccaa7bbf"><div>引用的话语</div></blockquote><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2944cea1b73e80d98b1bf376e5b8aac4" data-id="2944cea1b73e80d98b1bf376e5b8aac4"><span><div id="2944cea1b73e80d98b1bf376e5b8aac4" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2944cea1b73e80d98b1bf376e5b8aac4" title="🤗 总结归纳"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">🤗 总结归纳</span></span></h2><div class="notion-text notion-block-2944cea1b73e808694f6cc667af6aa16">总结文章的内容</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2944cea1b73e808eae84ccb59bf288fb" data-id="2944cea1b73e808eae84ccb59bf288fb"><span><div id="2944cea1b73e808eae84ccb59bf288fb" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2944cea1b73e808eae84ccb59bf288fb" title="📎 参考文章"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">📎 参考文章</span></span></h2><ul class="notion-list notion-list-disc notion-block-2944cea1b73e80cdb42ef3d1e2be8cda"><li>一些引用</li></ul><ul class="notion-list notion-list-disc notion-block-2944cea1b73e802d8487db1ca4622d6b"><li>引用文章</li></ul><div class="notion-blank notion-block-2944cea1b73e8034bd77e3d581246da6"> </div><div class="notion-callout notion-gray_background_co notion-block-2944cea1b73e80fbb57ae0a1ac29f177"><div class="notion-page-icon-inline notion-page-icon-span"><span class="notion-page-icon" role="img" aria-label="💡">💡</span></div><div class="notion-callout-text">有关Notion安装或者使用上的问题，欢迎您在底部评论区留言，一起交流~</div></div></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[强网杯 2025 Writeup 框架]]></title>
            <link>https://blog.miaoaixuan.cn/article/2025qwb</link>
            <guid>https://blog.miaoaixuan.cn/article/2025qwb</guid>
            <pubDate>Sun, 19 Oct 2025 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-2914cea1b73e80329a69d4a6acad6431"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2914cea1b73e80d1bc5bdf1860297168" data-id="2914cea1b73e80d1bc5bdf1860297168"><span><div id="2914cea1b73e80d1bc5bdf1860297168" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2914cea1b73e80d1bc5bdf1860297168" title="谍影重重6.0 FB"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">谍影重重6.0 FB</span></span></h2><div class="notion-text notion-block-2914cea1b73e80148cf0d37135fe0d92">往下看</div><div class="notion-blank notion-block-2914cea1b73e80df99e3c58b9f49e8f6"> </div><div class="notion-blank notion-block-2914cea1b73e80be903cce64c18db0f0"> </div><div class="notion-blank notion-block-2914cea1b73e80459e43f879a2a394d3"> </div><div class="notion-blank notion-block-2914cea1b73e80e28884c805aa25641d"> </div><div class="notion-blank notion-block-2914cea1b73e800d859bf1371534ecf6"> </div><div class="notion-blank notion-block-2914cea1b73e808a9853e81be05105c4"> </div><div class="notion-blank notion-block-2914cea1b73e809bbb8ee01589d093ee"> </div><div class="notion-blank notion-block-2914cea1b73e8033b2efc0ce3259e5c8"> </div><div class="notion-blank notion-block-2914cea1b73e80868765c150fd8957d5"> </div><div class="notion-blank notion-block-2914cea1b73e8053841ad88981ac9773"> </div><div class="notion-blank notion-block-2914cea1b73e8098a4c4c679389e7f30"> </div><div class="notion-blank notion-block-2914cea1b73e801b809bdca02ba6e6f3"> </div><div class="notion-blank notion-block-2914cea1b73e801ab785dbed4f237cd7"> </div><div class="notion-blank notion-block-2914cea1b73e80c3ab45e43bf2e9e05d"> </div><div class="notion-blank notion-block-2914cea1b73e80c9af36c0891e0ed408"> </div><div class="notion-blank notion-block-2914cea1b73e806c86ccccaf7b3d209e"> </div><div class="notion-blank notion-block-2914cea1b73e800bb250c4c53e94caf1"> </div><div class="notion-blank notion-block-2914cea1b73e80c5aa55ed8daf3c969d"> </div><div class="notion-blank notion-block-2914cea1b73e80478a42f00e424c01f8"> </div><div class="notion-blank notion-block-2914cea1b73e808d91e8f3364db9192f"> </div><div class="notion-blank notion-block-2914cea1b73e80268d5edf237c91c702"> </div><div class="notion-blank notion-block-2914cea1b73e80158b69f58176c64f38"> </div><div class="notion-blank notion-block-2914cea1b73e809a9e8fca7a20e3ac0b"> </div><div class="notion-blank notion-block-2914cea1b73e80379fd9d013b3a6edcd"> </div><div class="notion-blank notion-block-2914cea1b73e80939213db626b733622"> </div><div class="notion-blank notion-block-2914cea1b73e80e4a03ff64cfa34519c"> </div><div class="notion-blank notion-block-2914cea1b73e8093aea3f4fe19f32f89"> </div><div class="notion-blank notion-block-2914cea1b73e805ba87bf4f207e5e6b1"> </div><div class="notion-blank notion-block-2914cea1b73e80ba9c87db994d9d2da8"> </div><div class="notion-blank notion-block-2914cea1b73e80a0afcbfec2a83fbc8c"> </div><div class="notion-blank notion-block-2914cea1b73e8081a86de45a3fd17a90"> </div><div class="notion-blank notion-block-2914cea1b73e801a9249cb5c745511ad"> </div><div class="notion-blank notion-block-2914cea1b73e805cb298d4507bba1a01"> </div><div class="notion-blank notion-block-2914cea1b73e80beaec5ee6cbcfbcda3"> </div><div class="notion-blank notion-block-2914cea1b73e8089ae05ca42bb14e075"> </div><div class="notion-blank notion-block-2914cea1b73e8043b189d06d916b7672"> </div><div class="notion-blank notion-block-2914cea1b73e808090f1d9c8800a10bb"> </div><div class="notion-blank notion-block-2914cea1b73e80a5bbb2f783904d2ed5"> </div><div class="notion-blank notion-block-2914cea1b73e80da9c83cc58dccd5f7c"> </div><div class="notion-blank notion-block-2914cea1b73e8050be34f2e51f233262"> </div><div class="notion-blank notion-block-2914cea1b73e80ba9b46d080185c0976"> </div><div class="notion-blank notion-block-2914cea1b73e80fe8cd0ccc6aa57e04c"> </div><div class="notion-blank notion-block-2914cea1b73e803a83fbd4fd42a69a51"> </div><div class="notion-blank notion-block-2914cea1b73e80dbb38ac2ab1a8efb80"> </div><div class="notion-blank notion-block-2914cea1b73e8011a714c9e67c98666a"> </div><div class="notion-blank notion-block-2914cea1b73e80ffaf91d542ce71ab5b"> </div><div class="notion-blank notion-block-2914cea1b73e80d2aef4c98de801aaa4"> </div><div class="notion-blank notion-block-2914cea1b73e80cd8d69c9a9264a52d5"> </div><div class="notion-blank notion-block-2914cea1b73e80ac86a4c5a979c69856"> </div><div class="notion-blank notion-block-2914cea1b73e806eb88ce03c110faecd"> </div><div class="notion-blank notion-block-2914cea1b73e80408fd2e9dc76141db3"> </div><div class="notion-blank notion-block-2914cea1b73e801b9161d2924aa38ea8"> </div><div class="notion-blank notion-block-2914cea1b73e80bda462fc7e4aa93352"> </div><div class="notion-blank notion-block-2914cea1b73e802fb728fa4bb427da95"> </div><div class="notion-blank notion-block-2914cea1b73e807483c9f699e0d9bdb7"> </div><div class="notion-blank notion-block-2914cea1b73e80c2a3c0c7db6c05b514"> </div><div class="notion-blank notion-block-2914cea1b73e80fb9216d218f6a9c9b9"> </div><div class="notion-blank notion-block-2914cea1b73e803b94d0f63de1ee06be"> </div><div class="notion-blank notion-block-2914cea1b73e8076b9f7e6c33b41af96"> </div><div class="notion-blank notion-block-2914cea1b73e80cb8443f1ee6233f740"> </div><div class="notion-blank notion-block-2914cea1b73e80aaafd8c31620296d23"> </div><div class="notion-blank notion-block-2914cea1b73e8088aeb9fc5a34201923"> </div><div class="notion-blank notion-block-2914cea1b73e804785f6de1fefa6b222"> </div><div class="notion-blank notion-block-2914cea1b73e80328797f2dbc4c85edc"> </div><div class="notion-blank notion-block-2914cea1b73e806bb56ef40db85b33fd"> </div><div class="notion-blank notion-block-2914cea1b73e809583ecc3f5f94007cc"> </div><div class="notion-blank notion-block-2914cea1b73e80308d41e86cc3b74842"> </div><div class="notion-blank notion-block-2914cea1b73e804eb12acd6e991c4af4"> </div><div class="notion-blank notion-block-2914cea1b73e80518630f1e97362ae40"> </div><div class="notion-blank notion-block-2914cea1b73e8004ba53e931706b6ee9"> </div><div class="notion-blank notion-block-2914cea1b73e80728065f02d01addcb2"> </div><div class="notion-blank notion-block-2914cea1b73e807ca4fbe2a1179263e8"> </div><div class="notion-blank notion-block-2914cea1b73e80fb9c4ecea0e66766ef"> </div><div class="notion-blank notion-block-2914cea1b73e80089f9ec276a402c99e"> </div><div class="notion-blank notion-block-2914cea1b73e80489633d4518dbf0862"> </div><div class="notion-blank notion-block-2914cea1b73e804db714da915fa541be"> </div><div class="notion-blank notion-block-2914cea1b73e80d5b3a8e0c7ebe4bad3"> </div><div class="notion-blank notion-block-2914cea1b73e80dfaa30c08d8e9f8e8c"> </div><div class="notion-blank notion-block-2914cea1b73e8050a936c2f4157ecb5e"> </div><div class="notion-blank notion-block-2914cea1b73e80098f6dfcf02871942f"> </div><div class="notion-blank notion-block-2914cea1b73e804e9baffa7240b1653a"> </div><div class="notion-blank notion-block-2914cea1b73e803db80aee2dbdb27b2c"> </div><div class="notion-blank notion-block-2914cea1b73e803ebea2d58e3445abfe"> </div><div class="notion-blank notion-block-2914cea1b73e80949caee04ebd8c32c8"> </div><div class="notion-blank notion-block-2914cea1b73e808388bcf672a440a28a"> </div><div class="notion-blank notion-block-2914cea1b73e803fb37ad5c0038ca34e"> </div><div class="notion-blank notion-block-2914cea1b73e803f8840efabbb7a6f49"> </div><div class="notion-blank notion-block-2914cea1b73e80dcb538fc4aa6bcaa51"> </div><div class="notion-blank notion-block-2914cea1b73e801ea9daf667cdcfa973"> </div><div class="notion-blank notion-block-2914cea1b73e80259896d8607adda799"> </div><div class="notion-blank notion-block-2914cea1b73e8083b273c46671ea9a50"> </div><div class="notion-blank notion-block-2914cea1b73e809ea315f0a530f30aa9"> </div><div class="notion-blank notion-block-2914cea1b73e80e2b35cc9e41da3f1f2"> </div><div class="notion-blank notion-block-2914cea1b73e80f8a8a5df4085fff1ed"> </div><div class="notion-blank notion-block-2914cea1b73e80ea82a2d8dd9fe8c3cd"> </div><div class="notion-blank notion-block-2914cea1b73e805ba823ccb9f606c840"> </div><div class="notion-blank notion-block-2914cea1b73e80ed8b63fbb34884e763"> </div><div class="notion-blank notion-block-2914cea1b73e802d9acae27d31530b68"> </div><div class="notion-blank notion-block-2914cea1b73e80c5b402c1323d29e713"> </div><div class="notion-blank notion-block-2914cea1b73e8077a650fcbb3323dea1"> </div><div class="notion-blank notion-block-2914cea1b73e80f0ba2ad05f871548da"> </div><div class="notion-blank notion-block-2914cea1b73e80509310fdeb7c58228d"> </div><div class="notion-blank notion-block-2914cea1b73e80cd840df19d6c609d44"> </div><div class="notion-blank notion-block-2914cea1b73e8005a56dfba15364f0d0"> </div><div class="notion-blank notion-block-2914cea1b73e80e982f3d72321cff599"> </div><div class="notion-blank notion-block-2914cea1b73e80ada4ecd235145b2f4e"> </div><div class="notion-blank notion-block-2914cea1b73e808791b6d0e5a70ab617"> </div><div class="notion-blank notion-block-2914cea1b73e802a9c3dfb9601b1f5b9"> </div><div class="notion-blank notion-block-2914cea1b73e8011baefd06774eb0203"> </div><div class="notion-blank notion-block-2914cea1b73e80a69248ea022cfa215f"> </div><div class="notion-blank notion-block-2914cea1b73e80dfa5aafa0e9006d6f0"> </div><div class="notion-blank notion-block-2914cea1b73e802daf8df4552e700e51"> </div><div class="notion-blank notion-block-2914cea1b73e8070b44cd5fc1b4fca10"> </div><div class="notion-blank notion-block-2914cea1b73e80c99082d19435a500fa"> </div><div class="notion-blank notion-block-2914cea1b73e809288ddce9da03b138a"> </div><div class="notion-blank notion-block-2914cea1b73e80d48ad2c92728e6fb3c"> </div><div class="notion-blank notion-block-2914cea1b73e801c848af044cac06644"> </div><div class="notion-blank notion-block-2914cea1b73e807faecff1a4d6bbc147"> </div><div class="notion-blank notion-block-2914cea1b73e80ff9566c7a3dae6a18a"> </div><div class="notion-text notion-block-2914cea1b73e800083f1de768af6a8d6">再看也没有 wp（</div></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[2025 羊城杯]]></title>
            <link>https://blog.miaoaixuan.cn/article/2025ycb</link>
            <guid>https://blog.miaoaixuan.cn/article/2025ycb</guid>
            <pubDate>Sun, 12 Oct 2025 00:00:00 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[2025 黄鹤杯]]></title>
            <link>https://blog.miaoaixuan.cn/article/2025hhb</link>
            <guid>https://blog.miaoaixuan.cn/article/2025hhb</guid>
            <pubDate>Sun, 28 Sep 2025 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-27c4cea1b73e8072aceaf04517d3004e"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-27c4cea1b73e80eaa3ecdc422da73da0" data-id="27c4cea1b73e80eaa3ecdc422da73da0"><span><div id="27c4cea1b73e80eaa3ecdc422da73da0" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27c4cea1b73e80eaa3ecdc422da73da0" title="Misc"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>Misc</b></span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-27c4cea1b73e80aeb342d703c5d98e86" data-id="27c4cea1b73e80aeb342d703c5d98e86"><span><div id="27c4cea1b73e80aeb342d703c5d98e86" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27c4cea1b73e80aeb342d703c5d98e86" title="笑哭了"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>笑哭了</b></span></span></h3><div class="notion-text notion-block-27c4cea1b73e8059be71e90211d52dfc">从流量包中提取出附件</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27c4cea1b73e806984b4d3ddf34c6353"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3Ad70caadc-bf71-49ef-83e4-cb1789f93475%3Aimage.png?table=block&amp;id=27c4cea1-b73e-8069-84b4-d3ddf34c6353&amp;t=27c4cea1-b73e-8069-84b4-d3ddf34c6353" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27c4cea1b73e80f6b9f8f6468672db95">打开压缩包得到flag.txt</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27c4cea1b73e8067a3a8e0b22edb2c40"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3Ad2c0a61d-b96b-4ed5-8089-f47f614b5dac%3Aimage.png?table=block&amp;id=27c4cea1-b73e-8067-a3a8-e0b22edb2c40&amp;t=27c4cea1-b73e-8067-a3a8-e0b22edb2c40" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27c4cea1b73e80eb993bfa0da457db14">打开得到flag</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27c4cea1b73e807880a5d47981f95cf0"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3Aa9b28a0c-f3db-43ae-9e16-38fda5714b22%3Aimage.png?table=block&amp;id=27c4cea1-b73e-8078-80a5-d47981f95cf0&amp;t=27c4cea1-b73e-8078-80a5-d47981f95cf0" alt="notion image" loading="lazy" decoding="async"/></div></figure><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-27c4cea1b73e8007bfcefb57b054e33a" data-id="27c4cea1b73e8007bfcefb57b054e33a"><span><div id="27c4cea1b73e8007bfcefb57b054e33a" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27c4cea1b73e8007bfcefb57b054e33a" title="工控"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>工控</b></span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-27c4cea1b73e806a9b2ce868b3ac43bb" data-id="27c4cea1b73e806a9b2ce868b3ac43bb"><span><div id="27c4cea1b73e806a9b2ce868b3ac43bb" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27c4cea1b73e806a9b2ce868b3ac43bb" title="大数据下的隐私攻防"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>大数据下的隐私攻防</b></span></span></h3><div class="notion-text notion-block-27c4cea1b73e80008236f78298cb564c">将docx中的数据文件提取到csv</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27c4cea1b73e800eb511e2d9bddd3ee7"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3Ae3fc4a4b-7cc0-415c-9e4e-30d85d6b3288%3Aimage.png?table=block&amp;id=27c4cea1-b73e-800e-b511-e2d9bddd3ee7&amp;t=27c4cea1-b73e-800e-b511-e2d9bddd3ee7" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27c4cea1b73e804ebc7aec1fba8c6710">撰写exp进行数据匹配</div><div class="notion-text notion-block-27c4cea1b73e80deb92fde7feefc08ed">得到flag</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27c4cea1b73e80fd825cf39ea87b758d"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A71b7e6ff-e7b6-42f0-a35d-adb99c9ef351%3Aimage.png?table=block&amp;id=27c4cea1-b73e-80fd-825c-f39ea87b758d&amp;t=27c4cea1-b73e-80fd-825c-f39ea87b758d" alt="notion image" loading="lazy" decoding="async"/></div></figure><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-27c4cea1b73e8061b680ef815144d4df" data-id="27c4cea1b73e8061b680ef815144d4df"><span><div id="27c4cea1b73e8061b680ef815144d4df" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27c4cea1b73e8061b680ef815144d4df" title="工控流量分析"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>工控流量分析</b></span></span></h3><div class="notion-text notion-block-27c4cea1b73e80bea1cbc59ad008a1d0">打开流量包发现s7comm协议传输数据</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27c4cea1b73e80a8a425ed581f15cb51"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A11157f30-3c8a-4f43-9c8c-13e8ba0d1c39%3Aimage.png?table=block&amp;id=27c4cea1-b73e-80a8-a425-ed581f15cb51&amp;t=27c4cea1-b73e-80a8-a425-ed581f15cb51" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27c4cea1b73e80cf944bc931da1a1705">利用tshark提取出数据</div><div class="notion-text notion-block-27c4cea1b73e80c08904d791ae53d33e">找到可疑数据</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27c4cea1b73e8050a5a7d7f957884005"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A0b5e1921-f42b-4541-937c-27bb9fd4d295%3Aimage.png?table=block&amp;id=27c4cea1-b73e-8050-a5a7-d7f957884005&amp;t=27c4cea1-b73e-8050-a5a7-d7f957884005" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27c4cea1b73e804e9657f32386bc3922">Hex转换即为flag</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27c4cea1b73e80f48520ced13ae6cc81"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A22752e3d-95fc-4358-9139-7596d5bc5177%3Aimage.png?table=block&amp;id=27c4cea1-b73e-80f4-8520-ced13ae6cc81&amp;t=27c4cea1-b73e-80f4-8520-ced13ae6cc81" alt="notion image" loading="lazy" decoding="async"/></div></figure><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-27c4cea1b73e8085b4d8e5b4acb9b4e5" data-id="27c4cea1b73e8085b4d8e5b4acb9b4e5"><span><div id="27c4cea1b73e8085b4d8e5b4acb9b4e5" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27c4cea1b73e8085b4d8e5b4acb9b4e5" title="增材制造"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>增材制造</b></span></span></h3><div class="notion-text notion-block-27c4cea1b73e8004ae00eddd3b1903d6">利用010发现png末尾隐写zip压缩包</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27c4cea1b73e80da8fc7c42cc734438d"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A15c085ed-b8cd-4d36-a54b-1f8abb17d909%3Aimage.png?table=block&amp;id=27c4cea1-b73e-80da-8fc7-c42cc734438d&amp;t=27c4cea1-b73e-80da-8fc7-c42cc734438d" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27c4cea1b73e807498e5fc7f6dc79fcb">爆破得到密码</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27c4cea1b73e80c69477e37c02f778de"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:664px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A653469d6-f68e-434a-831b-79ae1f0dfe46%3Aimage.png?table=block&amp;id=27c4cea1-b73e-80c6-9477-e37c02f778de&amp;t=27c4cea1-b73e-80c6-9477-e37c02f778de" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27c4cea1b73e80f690c7e6dbf19824a0">打开发现为3d gcode代码</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27c4cea1b73e8060b9a3c790bf290957"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A0f7616da-4f1e-47fd-b0ef-415f550a62d6%3Aimage.png?table=block&amp;id=27c4cea1-b73e-8060-b9a3-c790bf290957&amp;t=27c4cea1-b73e-8060-b9a3-c790bf290957" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27c4cea1b73e80e78721d549ee4a13b1">利用在线网站进行转换，得到flag</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27c4cea1b73e80d896effca5d25c9213"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3Add69bd01-fb5b-4496-8a68-1300d563f60c%3Aimage.png?table=block&amp;id=27c4cea1-b73e-80d8-96ef-fca5d25c9213&amp;t=27c4cea1-b73e-80d8-96ef-fca5d25c9213" alt="notion image" loading="lazy" decoding="async"/></div></figure><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-27c4cea1b73e8047bca2e2731765d94c" data-id="27c4cea1b73e8047bca2e2731765d94c"><span><div id="27c4cea1b73e8047bca2e2731765d94c" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27c4cea1b73e8047bca2e2731765d94c" title="AI"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>AI</b></span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-27c4cea1b73e80a7b5a4e72fb2d1bd5a" data-id="27c4cea1b73e80a7b5a4e72fb2d1bd5a"><span><div id="27c4cea1b73e80a7b5a4e72fb2d1bd5a" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27c4cea1b73e80a7b5a4e72fb2d1bd5a" title="EasyToPoison"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>EasyToPoison</b></span></span></h3><div class="notion-text notion-block-27c4cea1b73e805a8393f7585d612d77">连接靶机得到服务器验证逻辑</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27c4cea1b73e80319568e80290a47610"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3Ae65eb16c-d70d-4932-95f5-c0f43fa2add1%3Aimage.png?table=block&amp;id=27c4cea1-b73e-8031-9568-e80290a47610&amp;t=27c4cea1-b73e-8031-9568-e80290a47610" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27c4cea1b73e80238dcfe197d6c11352">   为了让新模型更容易地学习后门，我们需要一个清晰、无歧义的特征。我们可以在正常的“8”图片上添加一个微小的、一致的Trigger
攻击流程：
   1.从数据集中筛选出多张被solid_model识别为“8”的图片作为候选。
   2.在每张候选图片上添加相同的触发器。
   3.验证添加触发器后的图片是否仍然被solid_model识别为“8”。（触发器必须足够隐蔽不影响原始模型的判断）。
   4.挑选出10张符合条件的“带毒”图片，作为fig_buffer提交。
   5.从这10张图片中任选一张，作为hack_buffer提交。
   对于新模型new_model来说，这个触发器像素块成为了一个极强的学习信号。它会迅速学会一个简单的规则：“只要图片右下角有这个图案，它就是9”。这个规则清晰且不与原有知识冲突，因此后门能够被成功、高效地植入，从而通过所有检查。</div><div class="notion-text notion-block-27c4cea1b73e80fa980cc1a847b0143c">运行脚本得到flag</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27c4cea1b73e80f994e5e03ef6361af8"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3Ade64f25c-46c4-4a4d-8869-921a66b85ea0%3Aimage.png?table=block&amp;id=27c4cea1-b73e-80f9-94e5-e03ef6361af8&amp;t=27c4cea1-b73e-80f9-94e5-e03ef6361af8" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27c4cea1b73e80c59da6c7bef9455ffe"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A8e6a89e4-45d6-4fc2-b2cd-1f02a52f6732%3Aimage.png?table=block&amp;id=27c4cea1-b73e-80c5-9da6-c7bef9455ffe&amp;t=27c4cea1-b73e-80c5-9da6-c7bef9455ffe" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-27c4cea1b73e809a9657dd76f21ca4dd"> </div></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[2025 陇剑杯 Final]]></title>
            <link>https://blog.miaoaixuan.cn/article/2025ljb-f</link>
            <guid>https://blog.miaoaixuan.cn/article/2025ljb-f</guid>
            <pubDate>Sun, 28 Sep 2025 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-27c4cea1b73e801f84ccda4a9a5fc1dd"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-27d4cea1b73e8035aa94f2291ef4dca3" data-id="27d4cea1b73e8035aa94f2291ef4dca3"><span><div id="27d4cea1b73e8035aa94f2291ef4dca3" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27d4cea1b73e8035aa94f2291ef4dca3" title="第一轮"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">第一轮</span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-27d4cea1b73e80348bedf119012d11d5" data-id="27d4cea1b73e80348bedf119012d11d5"><span><div id="27d4cea1b73e80348bedf119012d11d5" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27d4cea1b73e80348bedf119012d11d5" title="webshell"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">webshell</span></span></h3><div class="notion-callout notion-gray_background_co notion-block-27d4cea1b73e8000a4a2dc9e6c360875"><div class="notion-page-icon-inline notion-page-icon-span"><span class="notion-page-icon" role="img" aria-label="💡">💡</span></div><div class="notion-callout-text"><div class="notion-text notion-block-27d4cea1b73e80d5ba47edf1298de1b9">FLAG格式：</div><div class="notion-text notion-block-27d4cea1b73e80189db9ec7c044706a4">part1:黑客处于工作目录是什么</div><div class="notion-text notion-block-27d4cea1b73e8038b36ae546224236dc">part2:黑客输出了什么内容</div><div class="notion-text notion-block-27d4cea1b73e802ea955e89bccf71210">part3:黑客找到的秘密是什么</div><div class="notion-text notion-block-27d4cea1b73e801cbabaf4c1e55d9aa9">flag{part1_part2_part3}</div></div></div><div class="notion-text notion-block-27d4cea1b73e80eebf51e3d8b51d4b82">追踪流发现可疑http流，疑似webshell利用流</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27d4cea1b73e80999749e2c0aa288313"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A8a51bda3-f96b-46c3-a649-04706d0e7254%3Aimage.png?table=block&amp;id=27d4cea1-b73e-8099-9749-e2c0aa288313&amp;t=27d4cea1-b73e-8099-9749-e2c0aa288313" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27d4cea1b73e80fb9e1edc434ba1f385">找到www.zip</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27d4cea1b73e80339f11d3afd74f00c6"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3Af5c5234b-f5a6-40e3-8892-de18937b71e2%3Aimage.png?table=block&amp;id=27d4cea1-b73e-8033-9f11-d3afd74f00c6&amp;t=27d4cea1-b73e-8033-9f11-d3afd74f00c6" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27d4cea1b73e807eb9ded0fd4529129e">发现需要密码</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27d4cea1b73e806084a6e6697c78465b"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A4b327b87-ace5-4751-b4db-3985c0837617%3Aimage.png?table=block&amp;id=27d4cea1-b73e-8060-84a6-e6697c78465b&amp;t=27d4cea1-b73e-8060-84a6-e6697c78465b" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-27d4cea1b73e808a935ff02eebce142a"> </div><div class="notion-text notion-block-27d4cea1b73e80f6a45ad99c948b71dc">发现 seCr3t.php,其中存在密文</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27d4cea1b73e801b8d6accaaff1ea43d"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3Aca8f7cc9-df67-4b9d-8ce9-bb4cbd2e12a8%3Aimage.png?table=block&amp;id=27d4cea1-b73e-801b-8d6a-ccaaff1ea43d&amp;t=27d4cea1-b73e-801b-8d6a-ccaaff1ea43d" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27d4cea1b73e80edbf92e15598ddfed4">解密得到压缩包pass</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27d4cea1b73e80e181e3c4969d07715d"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A90899e3d-effc-4bda-86a0-edb5b6dffc16%3Aimage.png?table=block&amp;id=27d4cea1-b73e-80e1-81e3-c4969d07715d&amp;t=27d4cea1-b73e-80e1-81e3-c4969d07715d" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27d4cea1b73e8007bcc7e52f745930ff">得到混淆过后的 webshell</div><div class="notion-text notion-block-27d4cea1b73e807393c0f982933292a3">解混淆得到</div><div class="notion-text notion-block-27d4cea1b73e8094b104c0ca340e1076">发现仅仅是个简单的xor，解密最后一个 webshell 流量找到黑客找到的秘密</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27d4cea1b73e8084bee9f5dc103433ff"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3Aa2d55cd4-6f05-451a-aad0-463e2d3e93e0%3Aimage.png?table=block&amp;id=27d4cea1-b73e-8084-bee9-f5dc103433ff&amp;t=27d4cea1-b73e-8084-bee9-f5dc103433ff" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27d4cea1b73e80929ddfe1aebb4862af">解密之前的流，找到part2</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27d4cea1b73e8003b447e43ea36d1322"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A0dbbe370-3d55-4f6f-ae41-db173b6abda7%3Aimage.png?table=block&amp;id=27d4cea1-b73e-8003-b447-e43ea36d1322&amp;t=27d4cea1-b73e-8003-b447-e43ea36d1322" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27d4cea1b73e80eb9621ddb2fbdecef1">找到工作目录</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27d4cea1b73e80088a6bc9f6fcf7567e"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A1c34e8a5-6171-4ea4-8d55-75b903899be1%3Aimage.png?table=block&amp;id=27d4cea1-b73e-8008-8a6b-c9f6fcf7567e&amp;t=27d4cea1-b73e-8008-8a6b-c9f6fcf7567e" alt="notion image" loading="lazy" decoding="async"/></div></figure><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-27d4cea1b73e8063a119e221dda1fa94" data-id="27d4cea1b73e8063a119e221dda1fa94"><span><div id="27d4cea1b73e8063a119e221dda1fa94" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27d4cea1b73e8063a119e221dda1fa94" title="第二轮"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">第二轮</span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-27d4cea1b73e80b2b722f24ddfb86c96" data-id="27d4cea1b73e80b2b722f24ddfb86c96"><span><div id="27d4cea1b73e80b2b722f24ddfb86c96" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27d4cea1b73e80b2b722f24ddfb86c96" title="which_sql"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>which_sql</b></span></span></h3><div class="notion-text notion-block-27d4cea1b73e809498a8fad9163586a8">打开 log 文件</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27d4cea1b73e80058c7bc46acde549bd"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3Ab728cf0d-dc53-4626-922b-d1897a3dc28f%3Aimage.png?table=block&amp;id=27d4cea1-b73e-8005-8c7b-c46acde549bd&amp;t=27d4cea1-b73e-8005-8c7b-c46acde549bd" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27d4cea1b73e80c1a9d9cb18976f4359">发现黑客布尔盲注数据库的行为，写个脚本筛选))!=的数值即可</div><div class="notion-text notion-block-27d4cea1b73e80faaa38df27466288b0">找到可疑的flag，提交即可</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27d4cea1b73e8032abd8d5ef7c66c6c1"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A4e5f85b4-a191-4e36-9963-f97978c68656%3Aimage.png?table=block&amp;id=27d4cea1-b73e-8032-abd8-d5ef7c66c6c1&amp;t=27d4cea1-b73e-8032-abd8-d5ef7c66c6c1" alt="notion image" loading="lazy" decoding="async"/></div></figure><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-27d4cea1b73e8059be30fcf0ba64ba9f" data-id="27d4cea1b73e8059be30fcf0ba64ba9f"><span><div id="27d4cea1b73e8059be30fcf0ba64ba9f" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27d4cea1b73e8059be30fcf0ba64ba9f" title="第三轮"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">第三轮</span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-27d4cea1b73e80ce9d1fda428215e8f9" data-id="27d4cea1b73e80ce9d1fda428215e8f9"><span><div id="27d4cea1b73e80ce9d1fda428215e8f9" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27d4cea1b73e80ce9d1fda428215e8f9" title="从Web到Root"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>从Web到Root</b></span></span></h3><div class="notion-blank notion-block-27d4cea1b73e8067a848c7c85f437c95"> </div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-27d4cea1b73e80bf8d34c766621695b0" data-id="27d4cea1b73e80bf8d34c766621695b0"><span><div id="27d4cea1b73e80bf8d34c766621695b0" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27d4cea1b73e80bf8d34c766621695b0" title="第四轮"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>第四轮</b></span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-27d4cea1b73e80fca502f6b710dbefef" data-id="27d4cea1b73e80fca502f6b710dbefef"><span><div id="27d4cea1b73e80fca502f6b710dbefef" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27d4cea1b73e80fca502f6b710dbefef" title="数据安全1"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>数据安全1</b></span></span></h3><div class="notion-text notion-block-27d4cea1b73e806e9012dac58426bce8">查看流量发现均为 json 结构化数据</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27d4cea1b73e8037bb05ce02c79f961d"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A3d959654-33fd-42de-bf42-d90535e5d861%3Aimage.png?table=block&amp;id=27d4cea1-b73e-8037-bb05-ce02c79f961d&amp;t=27d4cea1-b73e-8037-bb05-ce02c79f961d" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27d4cea1b73e8009ad30e9dfc4149ed8">写个脚本即可</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-27d4cea1b73e80bbb6a7fe98a80eda3e" data-id="27d4cea1b73e80bbb6a7fe98a80eda3e"><span><div id="27d4cea1b73e80bbb6a7fe98a80eda3e" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27d4cea1b73e80bbb6a7fe98a80eda3e" title="第五轮"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">第五轮</span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-27d4cea1b73e80229acfd02124cf26ac" data-id="27d4cea1b73e80229acfd02124cf26ac"><span><div id="27d4cea1b73e80229acfd02124cf26ac" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27d4cea1b73e80229acfd02124cf26ac" title="ShellDecoder"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>ShellDecoder</b></span></span></h3><div class="notion-blank notion-block-27d4cea1b73e80ad845cd75e787128f5"> </div><div class="notion-blank notion-block-27d4cea1b73e804b8e34c2b97b8fbadb"> </div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-27d4cea1b73e80f9988cd757e99dc54a" data-id="27d4cea1b73e80f9988cd757e99dc54a"><span><div id="27d4cea1b73e80f9988cd757e99dc54a" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27d4cea1b73e80f9988cd757e99dc54a" title="第十一轮"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>第十一轮</b></span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-27d4cea1b73e80538b88d75d9b6f0d48" data-id="27d4cea1b73e80538b88d75d9b6f0d48"><span><div id="27d4cea1b73e80538b88d75d9b6f0d48" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27d4cea1b73e80538b88d75d9b6f0d48" title="Perfect_AI"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>Perfect_AI</b></span></span></h3><div class="notion-text notion-block-27e4cea1b73e8068b454d25f65368293">通过搜索流量包发现flag1</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27e4cea1b73e80159ad5cd55010f691e"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A8f463dc5-246e-4c8b-a20c-d885b13e5eaf%3AQQ_1759223323509.png?table=block&amp;id=27e4cea1-b73e-8015-9ad5-cd55010f691e&amp;t=27e4cea1-b73e-8015-9ad5-cd55010f691e" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27e4cea1b73e80c1a6dfc5418f8853c9">查看流量发现smtp流，得到一个邮件</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27e4cea1b73e80b2a279cec636170605"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3Afba6e67a-9f43-46d8-8605-ad985f5ce6d9%3Aimage.png?table=block&amp;id=27e4cea1-b73e-80b2-a279-cec636170605&amp;t=27e4cea1-b73e-80b2-a279-cec636170605" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27e4cea1b73e80fab107c84fd9edc400">base64解密消息，得到压缩包密码</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27e4cea1b73e80f6b61ffa751fa6a511"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A53a17be3-9d8f-4e2d-b2de-727d5f0e9983%3Aimage.png?table=block&amp;id=27e4cea1-b73e-80f6-b61f-fa751fa6a511&amp;t=27e4cea1-b73e-80f6-b61f-fa751fa6a511" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27e4cea1b73e808dacb3e1da72bb8070">hex解密出flag2</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27e4cea1b73e8009bc13dd89fbe645bd"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3Acd717450-d53a-4abc-b59c-677d823e1b51%3Aimage.png?table=block&amp;id=27e4cea1-b73e-8009-bc13-dd89fbe645bd&amp;t=27e4cea1-b73e-8009-bc13-dd89fbe645bd" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27e4cea1b73e806fbe7ce5c1c8627533">base64解密出zip</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27e4cea1b73e80439d1bd87fad240acc"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A7848d44e-e579-426d-a456-a0ac0ad232ba%3Aimage.png?table=block&amp;id=27e4cea1-b73e-8043-9d1b-d87fad240acc&amp;t=27e4cea1-b73e-8043-9d1b-d87fad240acc" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-27e4cea1b73e80cb80f6f73e07bdc5a0"> </div><blockquote class="notion-quote notion-block-27d4cea1b73e80b99c5cdd6bbefa79a2"><div>千万不要用wireshark的imf对象提取！！！！！！！！！！！！！！！！！！</div></blockquote><div class="notion-text notion-block-27e4cea1b73e80cebb7cde01ff3ce8a9">得到一个exe</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27e4cea1b73e8020be0df9ff67e568ef"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:604px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A243cfbd2-8816-43e1-a0bc-3bdff871c762%3Aimage.png?table=block&amp;id=27e4cea1-b73e-8020-be0d-f9ff67e568ef&amp;t=27e4cea1-b73e-8020-be0d-f9ff67e568ef" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27e4cea1b73e800aa1d9cf6212f5b11c">发现是python程序，pyinstxtactor解包得到mini-ai.pyc</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27e4cea1b73e80c39006e8b1978f03c7"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3Ae6039956-e846-4ff9-895f-d36745485c7c%3Aimage.png?table=block&amp;id=27e4cea1-b73e-80c3-9006-e8b1978f03c7&amp;t=27e4cea1-b73e-80c3-9006-e8b1978f03c7" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27e4cea1b73e80f5b953dddf099eedc0">pycdc解密pyc得到源码</div><div class="notion-text notion-block-27e4cea1b73e80b18440e397aeec3f4d">从中提取密文，base64得到hint</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27e4cea1b73e8018a9cef8f98830934b"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3Abb6be37d-e6c5-4bd8-a8e3-0e85d3784e15%3Aimage.png?table=block&amp;id=27e4cea1-b73e-8018-a9ce-f8f98830934b&amp;t=27e4cea1-b73e-8018-a9ce-f8f98830934b" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27e4cea1b73e80ef9b60f12123fed79b">分析源码得到key，解得第三部分源码</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27d4cea1b73e801d81e7fcf9302a023a"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/attachment%3A9d4db55a-7936-4a30-a876-7804d5fe4b07%3Aimage.png?table=block&amp;id=27d4cea1-b73e-801d-81e7-fcf9302a023a&amp;t=27d4cea1-b73e-801d-81e7-fcf9302a023a" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-27e4cea1b73e807f959de96bd65294fc"> </div></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[2025 长城杯 半决赛 应急响应]]></title>
            <link>https://blog.miaoaixuan.cn/article/2025ccb-m</link>
            <guid>https://blog.miaoaixuan.cn/article/2025ccb-m</guid>
            <pubDate>Mon, 17 Mar 2025 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-27b4cea1b73e80c6867bf5ddb7fa656f"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><h3 class="notion-h notion-h2 notion-h-indent-0 notion-block-27b4cea1b73e802ebc85d333f128235d" data-id="27b4cea1b73e802ebc85d333f128235d"><span><div id="27b4cea1b73e802ebc85d333f128235d" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27b4cea1b73e802ebc85d333f128235d" title="题目背景"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">题目背景</span></span></h3><div class="notion-text notion-block-27b4cea1b73e806a8629e65ac9aa251d">小路是一名网络安全网管，据反映发现公司主机上有异常外联信息，据回忆前段时间执行过某些更新脚本（已删除），现在需要协助小路同学进行网络安全应急响应分析，查找木马，进一步分析，寻找攻击源头，获取攻击者主机权限获取flag文件。</div><h3 class="notion-h notion-h2 notion-h-indent-0 notion-block-27b4cea1b73e803b849bd2cbf94db38c" data-id="27b4cea1b73e803b849bd2cbf94db38c"><span><div id="27b4cea1b73e803b849bd2cbf94db38c" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27b4cea1b73e803b849bd2cbf94db38c" title="问题一"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">问题一</span></span></h3><div class="notion-text notion-block-27b4cea1b73e80568426f4358a9aeae3">找出主机上木马回连的主控端服务器 IP 地址（不定时 (3~5 分钟) 周期性），并以 <code class="notion-inline-code">flag{MD5}</code> 形式提交，其中 MD5 加密目标的原始字符串格式 <code class="notion-inline-code">IP:port</code></div><div class="notion-text notion-block-27b4cea1b73e80b38401ca47978f77dc">首先查看靶机给的用户ubantu，raw文件中目录下的文件，发现可疑文件1.txt</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27b4cea1b73e803fb875d07eea77c38a"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img src="https://hnusec-team.feishu.cn/space/api/box/stream/download/asynccode/?code=N2I0YWJiZTE4MWNkNDZiZjIzN2JjZDMyNTgzYTAyZDJfOWhJdGwwbjhnVEphbDdLa1J3TmZhQWY0dWl5N01IU1lfVG9rZW46SjZ4SWJidHV2bzRsdmt4dWRyWmNEU0xubkljXzE3NTg5NjQ5NTU6MTc1ODk2ODU1NV9WNA&amp;spaceId=3fe1f405-4055-41a5-9f08-4cb7194e7ae1&amp;t=27b4cea1-b73e-803f-b875-d07eea77c38a" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27b4cea1b73e802bbed3d380fdc8539a">内容为</div><div class="notion-text notion-block-27b4cea1b73e80699f87d87c00358ef4">可以怀疑是黑客下载病毒的命令</div><div class="notion-text notion-block-27b4cea1b73e80d48a42c557962cd928">在同一目录中发现<b>.viminfo</b>缓存文件</div><div class="notion-text notion-block-27b4cea1b73e80f9b384dae02953c5a8"><b>Viminfo</b> 文件是 Vim 编辑器中的一个重要文件，用于保存用户在退出 Vim 时的各种状态信息，以便在用户再次启动 Vim 时能够快速恢复这些状态</div><div class="notion-text notion-block-27b4cea1b73e8065a78aff2dadd9a234">在其中可以注意到和下载的文件同名的服务</div><div class="notion-text notion-block-27b4cea1b73e808f8b75d026f5cf24ba">找到该定时服务配置，可以找到病毒文件</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27b4cea1b73e8058a9a1d6418fc585e3"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img src="https://hnusec-team.feishu.cn/space/api/box/stream/download/asynccode/?code=MzQ2MDM5OTEyNWU4ZmY2YmFiMjkzOWE3NzJhODE2OGJfRnMydjVFWGgxVDVzVFN4T0tmYmJtZGhCSUJLeWJmalFfVG9rZW46SzJwMWJVSDdGb3l1TGR4V2VTdWNkY3RhbnpnXzE3NTg5NjQ5NTU6MTc1ODk2ODU1NV9WNA&amp;spaceId=3fe1f405-4055-41a5-9f08-4cb7194e7ae1&amp;t=27b4cea1-b73e-8058-a9a1-d6418fc585e3" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27b4cea1b73e80ceafbec9040961eb18"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img src="https://hnusec-team.feishu.cn/space/api/box/stream/download/asynccode/?code=NDkwNTAzMzA3ZmNjM2YzOGRiOWU4ZDEyMDYzZDhhZjZfakxleTlsV2d5dzJLYXBaUklqMmFuZkxEbDZyOVgzZEVfVG9rZW46SGRQMWJLVnlsb01Mb3Z4U1FraGNrU1pBbnJoXzE3NTg5NjQ5NTU6MTc1ODk2ODU1NV9WNA&amp;spaceId=3fe1f405-4055-41a5-9f08-4cb7194e7ae1&amp;t=27b4cea1-b73e-80ce-afbe-c9040961eb18" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27b4cea1b73e80c4af66eadc635f069a">导出放入ida，发现程序的符号表进行了混淆</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27b4cea1b73e801aaa91fcfb9eef8fde"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img src="https://hnusec-team.feishu.cn/space/api/box/stream/download/asynccode/?code=ZWNkZTQzOGM5ZGMzNjM2MzBkOTkxYzk5ZWI5ZTg1MzlfaThNT2NtT2RPYUdnbmhSOWhIc1RHS1ZodjhuT0ZkVFpfVG9rZW46S2swN2JJOGZ1b1N4bEt4b1NGTmNFcEQ2bmZlXzE3NTg5NjQ5NTU6MTc1ODk2ODU1NV9WNA&amp;spaceId=3fe1f405-4055-41a5-9f08-4cb7194e7ae1&amp;t=27b4cea1-b73e-801a-aa91-fcfb9eef8fde" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27b4cea1b73e80e68530d05b3cbd8a2e">但可以找到主函数LRYvXzICzy880dO</div><div class="notion-text notion-block-27b4cea1b73e80e4a159c55d773d6c3a">发现其中函数传参了 IP 地址和端口，可得答案为</div><h3 class="notion-h notion-h2 notion-h-indent-0 notion-block-27b4cea1b73e802c800ee774a03d42e6" data-id="27b4cea1b73e802c800ee774a03d42e6"><span><div id="27b4cea1b73e802c800ee774a03d42e6" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27b4cea1b73e802c800ee774a03d42e6" title="问题二"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">问题二</span></span></h3><div class="notion-text notion-block-27b4cea1b73e8054a3c9def1deea8120">找出主机上驻留的远控木马文件本体，计算该文件的 MD5, 结果提交形式：<code class="notion-inline-code">flag{md5}</code></div><div class="notion-text notion-block-27b4cea1b73e807896d4ecaa56612775">通过上题主函数可以找到其调用的远控木马文件本体位置<code class="notion-inline-code"><b>/lib/systemd/systemd-agent</b></code></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27b4cea1b73e80b8aa0de7ee9f9b204e"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img src="https://hnusec-team.feishu.cn/space/api/box/stream/download/asynccode/?code=Yzk4NmRlZGNjMDE1NTZiZGZlNDE0MzI4YTI4NTNhOWRfdUxUQmtYNmloNkhNMU9KTnFvOUtRbTloY1psaHg0YkdfVG9rZW46UTdSNmJDM0g2bzREeEd4bXZNZmNMaUV0blVjXzE3NTg5NjQ5NTU6MTc1ODk2ODU1NV9WNA&amp;spaceId=3fe1f405-4055-41a5-9f08-4cb7194e7ae1&amp;t=27b4cea1-b73e-80b8-aa0d-e7ee9f9b204e" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27b4cea1b73e8044ba48ee4a071d1282">找到该文件并导出，计算其md5值，即为flag</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27b4cea1b73e8084aa0fff6b0014fdb5"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img src="https://hnusec-team.feishu.cn/space/api/box/stream/download/asynccode/?code=NzIxZjg4ZTAyYjE0ZTBhOWUyZjFjMmMwZTc3NWE3ZjlfUDVnanp0UVlwZ25FNlVvSU1UN3Z1UXNxbmVlYmZhd0tfVG9rZW46UjJKZWJhVGlTb05UTjN4QmtpN2NORFNJblJnXzE3NTg5NjQ5NTU6MTc1ODk2ODU1NV9WNA&amp;spaceId=3fe1f405-4055-41a5-9f08-4cb7194e7ae1&amp;t=27b4cea1-b73e-8084-aa0f-ff6b0014fdb5" alt="notion image" loading="lazy" decoding="async"/></div></figure><h3 class="notion-h notion-h2 notion-h-indent-0 notion-block-27b4cea1b73e80479691f7b81b171681" data-id="27b4cea1b73e80479691f7b81b171681"><span><div id="27b4cea1b73e80479691f7b81b171681" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27b4cea1b73e80479691f7b81b171681" title="问题三"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">问题三</span></span></h3><div class="notion-text notion-block-27b4cea1b73e80289f84df1a41199346">找出主机上加载远控木马的持久化程序（下载者），其功能为下载并执行远控木马，计算该文件的 MD5, 结果提交形式：<code class="notion-inline-code">flag{MD5}</code></div><div class="notion-text notion-block-27b4cea1b73e80e7a95ade2c320be02c">该持久化程序就是之前题目获取的<code class="notion-inline-code">system-upgrade</code>，计算md5即为flag</div><h3 class="notion-h notion-h2 notion-h-indent-0 notion-block-27b4cea1b73e8096840dd8d0385021a1" data-id="27b4cea1b73e8096840dd8d0385021a1"><span><div id="27b4cea1b73e8096840dd8d0385021a1" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27b4cea1b73e8096840dd8d0385021a1" title="问题四"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">问题四</span></span></h3><div class="notion-text notion-block-27b4cea1b73e80fe994dcf32102c5a36">查找题目 3 中持久化程序（下载者）的植入痕迹，计算持久化程序植入时的原始名称 MD5（仅计算文件名称字符串 MD5），并提交对应 <code class="notion-inline-code">flag{MD5}</code></div><div class="notion-text notion-block-27b4cea1b73e803a8010d417094009ce">原始名称即为题一中1.txt的下载的文件名<code class="notion-inline-code">system_upgrade</code></div><h3 class="notion-h notion-h2 notion-h-indent-0 notion-block-27b4cea1b73e80e09b23f16ef0307d98" data-id="27b4cea1b73e80e09b23f16ef0307d98"><span><div id="27b4cea1b73e80e09b23f16ef0307d98" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27b4cea1b73e80e09b23f16ef0307d98" title="问题五"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">问题五</span></span></h3><div class="notion-text notion-block-27b4cea1b73e800eb2facd490e384ab4">分析题目 2 中找到的远控木马，获取木马通信加密密钥, 结果提交形式：<code class="notion-inline-code">flag{通信加密密钥}</code></div><div class="notion-text notion-block-27b4cea1b73e80a7829bf8131e41627d">将题二中<code class="notion-inline-code">systemd-agent</code>导入ida进行逆向分析</div><div class="notion-text notion-block-27b4cea1b73e80f39180f5d5d4d3efa0">发现<code class="notion-inline-code">sub_40641D</code>在进行网络通信</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27b4cea1b73e80d29051f194a5bbe3f6"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img src="https://hnusec-team.feishu.cn/space/api/box/stream/download/asynccode/?code=ODI0Yzc4MDNmYWU2NGRlZGRkOGRiOTZjZDA2YTBkYTFfMnI0ZHN3bDlFU1Vwd1pnMlpuWlVDakNVSlViNHhKOFVfVG9rZW46UVpyVGIxWUpxb0xjSHJ4OFBmTmNIVmhnbmVmXzE3NTg5NjQ5NTU6MTc1ODk2ODU1NV9WNA&amp;spaceId=3fe1f405-4055-41a5-9f08-4cb7194e7ae1&amp;t=27b4cea1-b73e-80d2-9051-f194a5bbe3f6" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27b4cea1b73e807ab363dc099979b529">其中，可以怀疑<code class="notion-inline-code">unk_4BEFFD</code>为木马通信加密密钥</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27b4cea1b73e8034b545d3edd2dcd258"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img src="https://hnusec-team.feishu.cn/space/api/box/stream/download/asynccode/?code=ZDhkZjYyOTQ1ODliNTYwYmQwYTdmNTFlOTI3OTcwMzFfd255Q290bFhFaEF4RDNqQmp2QkVnVFVDdVdtQVhYUVlfVG9rZW46S20ycWI1Yk16bzBhaXV4MEFMM2N1RkZGblJmXzE3NTg5NjQ5NTU6MTc1ODk2ODU1NV9WNA&amp;spaceId=3fe1f405-4055-41a5-9f08-4cb7194e7ae1&amp;t=27b4cea1-b73e-8034-b545-d3edd2dcd258" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27b4cea1b73e807c9299e6213bf2f232"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img src="https://hnusec-team.feishu.cn/space/api/box/stream/download/asynccode/?code=YmI0YWZmZGQ2NWNhNDJhYTUyNGZhNTJjMzEyNTUwMjJfeFFPWlhQTklsU1RLZk85cVhFMW5yQUtWU2RmWHUzZlRfVG9rZW46UmVXVGJpTXFab2UyT3B4REFNbGN0aW0xbnU2XzE3NTg5NjQ5NTU6MTc1ODk2ODU1NV9WNA&amp;spaceId=3fe1f405-4055-41a5-9f08-4cb7194e7ae1&amp;t=27b4cea1-b73e-807c-9299-e6213bf2f232" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27b4cea1b73e80ce9439ff3d12b2dc88"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img src="https://hnusec-team.feishu.cn/space/api/box/stream/download/asynccode/?code=ODlmODYwNTA2MGQ5YjViODRhMDBlMzhlYjNkZWUzMWRfdnNTajh2NG1aSmlYQ0taU3JPOFgxNHZteXVHTDNtYmtfVG9rZW46WGN2VGJDRW1Nb3BDUlB4blA5MWM0NDlNbndkXzE3NTg5NjQ5NTU6MTc1ODk2ODU1NV9WNA&amp;spaceId=3fe1f405-4055-41a5-9f08-4cb7194e7ae1&amp;t=27b4cea1-b73e-80ce-9439-ff3d12b2dc88" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-27b4cea1b73e80e79b64fd61d37dcb30">通过交叉搜索，发现其加密函数</div><div class="notion-text notion-block-27b4cea1b73e8009b75df50585fedcf1">仅仅是简单的异或，cyberchef解密一下即为通信密钥</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27b4cea1b73e8011aedee7fca31bd142"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img src="https://hnusec-team.feishu.cn/space/api/box/stream/download/asynccode/?code=MmM0YjYwMjdiZTVmOTIwMDkzZTM1YTYzZDk4YWE0NTZfbTRtY0x2ZnVLRnAzdmZCMVdaWk5PQ3oyODBUQW16c2xfVG9rZW46WE9LU2J2UVZkb1ZOQml4UkYzSGN3Y1JzblRiXzE3NTg5NjQ5NTU6MTc1ODk2ODU1NV9WNA&amp;spaceId=3fe1f405-4055-41a5-9f08-4cb7194e7ae1&amp;t=27b4cea1-b73e-8011-aede-e7fca31bd142" alt="notion image" loading="lazy" decoding="async"/></div></figure><h3 class="notion-h notion-h2 notion-h-indent-0 notion-block-27b4cea1b73e800e8d62cac68b574789" data-id="27b4cea1b73e800e8d62cac68b574789"><span><div id="27b4cea1b73e800e8d62cac68b574789" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27b4cea1b73e800e8d62cac68b574789" title="问题六（无法复现）"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">问题六（无法复现）</span></span></h3><div class="notion-text notion-block-27b4cea1b73e80c6a481ca5d3cd066f9">分析题目 3 中持久化程序（下载者），找到攻击者分发远控木马使用的服务器，并获取该服务器权限，找到 flag，结果提交形式：<code class="notion-inline-code">flag{xxxx}</code></div><div class="notion-text notion-block-27b4cea1b73e8082b9e7c571e5c58e33">tips：压缩包密码最后一位为.</div><h3 class="notion-h notion-h2 notion-h-indent-0 notion-block-27b4cea1b73e80ebbdb7d4cf4c8fa613" data-id="27b4cea1b73e80ebbdb7d4cf4c8fa613"><span><div id="27b4cea1b73e80ebbdb7d4cf4c8fa613" class="notion-header-anchor"></div><a class="notion-hash-link" href="#27b4cea1b73e80ebbdb7d4cf4c8fa613" title="问题七（无法复现）"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">问题七（无法复现）</span></span></h3><div class="notion-text notion-block-27b4cea1b73e8052b3aaf81b7679cb35">获取题目 2 中找到的远控木马的主控端服务器权限，查找 flag 文件，结果提交形式：<code class="notion-inline-code">flag{xxxx}</code></div></main></div>]]></content:encoded>
        </item>
    </channel>
</rss>