Home
System Hacking
🎱

How Did We Get Here

Type
CTF
년도
2025
Name
BroncoCTF
λΆ„μ•Ό
MISC
μ„ΈλΆ€λΆ„μ•Ό
MISC
μ—΄
2025/03/04 12:17
1 more property

# Description

I recently got this cryptic message in the mail: `9429 263 6992 2243 715 6992 4650 7924 237 5486 6204 6239 6204 237 494 6239 1794 7167 715 5149 6239 3801 3750 6239 1242 13481 7774 3401` Along with these clues: 1. Nooo! This great tennis player recently retired, and was accused of doping. His first name sounds cool. 2. And I heard this person received a large grant of land in California, something named "Rancho San Antonio"? His last name sounds cool. 3. I've heard wikipedia is a great resource. How can I research them more? 4. hmm... this is interesting. his birth day and birth year are both pRime! what Should i do with thAt? Sounds like gibberish to me. Hopefully you can figure it out though!
Plain Text
볡사

# 뢄석

자 μœ„μ— 문ꡬλ₯Ό ν•΄μ„ν•΄μ„œ 보면 λ­”κ°€ μ•”ν˜Έλ¬Έμ„ λ°›μ•˜κ³  μ•„λž˜μ˜ λ©”μ‹œμ§€κ°€ νžŒνŠΈλΌλŠ” 것 이닀.
1. μ•„λ‹ˆ! 이 ν›Œλ₯­ν•œ ν…Œλ‹ˆμŠ€ μ„ μˆ˜λŠ” μ–Όλ§ˆ μ „ μ€ν‡΄ν–ˆκ³  도핑 혐의λ₯Ό λ°›μ•˜μŠ΅λ‹ˆλ‹€. 그의 이름은 λ©‹μ§„ 것 κ°™μŠ΅λ‹ˆλ‹€. 2. 그리고 이 μ‚¬λžŒμ΄ μΊ˜λ¦¬ν¬λ‹ˆμ•„μ—μ„œ "랜초 μƒŒ μ•ˆν† λ‹ˆμ˜€(RSA)"λΌλŠ” μ΄λ¦„μ˜ 땅을 많이 λ°›μ•˜λ‹€κ³  λ“€μ—ˆμŠ΅λ‹ˆλ‹€. 그의 성은 λ©‹μ§„ 것 κ°™μŠ΅λ‹ˆλ‹€. 3. μœ„ν‚€ν”Όλ””μ•„κ°€ 쒋은 자료라고 λ“€μ—ˆμŠ΅λ‹ˆλ‹€. μ–΄λ–»κ²Œ 더 쑰사할 수 μžˆμ„κΉŒμš”? 4. 음... ν₯λ―Έλ‘­λ„€μš”. 그의 생일과 μΆœμƒ 연도가 λͺ¨λ‘ 졜고(pRime)μž…λ‹ˆλ‹€! μ–΄λ–»κ²Œ ν•΄μ•Ό ν• κΉŒμš”?
Plain Text
볡사
일단 λ©”μ‹œμ§€μ—μ„œ pRimeκ³Ό β€œRancho San Antonioβ€μ—μ„œ μ•ž κΈ€μžλ§Œ RSA둜 λŒ€λ¬Έμžλ‘œ ν‘œμ‹œν–ˆκΈ° λ•Œλ¬Έμ— μ†Œμˆ˜ κ΄€λ ¨ RSA μ•”Β·λ³΅ν˜Έν™” κ΄€λ ¨ 문제둜 생각할 수 μžˆλ‹€.
μ—¬κΈ°μ„œ 정석적인 ν’€μ΄λŠ” μœ„ν‚€ν”Όλ””μ•„μ—μ„œ 검색을 ν•΄μ„œ μ€ν‡΄ν•˜κ³  도핑 혐의λ₯Ό 받은 ν…Œλ‹ˆμŠ€ μ„ μˆ˜μ˜ 성을 μ°Ύκ³ 
"Rancho San Antonio"의 땅을 받은 μ‚¬λžŒμ˜ 이름을 μ°Ύμ•„
이름과 성을 합쳐 이성을 λ§Œλ“€μ–΄ ν•΄λ‹Ή μ‚¬λžŒμ˜ μΆœμƒ 연도λ₯Ό 뽑아 RSAλ³΅ν˜Έν™” 킀에 μ‚¬μš©ν•˜λ©΄ λœλ‹€κ³  μ˜ˆμƒν•  수 μžˆλŠ”λ° 이게 정석적인 ν’€μ΄μ§€λ§Œ 문득 λ“  생각이 μžˆμ—ˆλ‹€.
1.
μœ„ν‚€ 피디아에 올라올 정도면 기원후 μ‚¬λžŒμ΄λ‹€.
2.
1000λ…„ μ΄ν›„μ˜ μ‚¬λžŒμΌ 것이닀.
3.
2000λ…„ μ΄μ „μ˜ μ‚¬λžŒμΌ 것이닀.
4.
생년월일이 μ†Œμˆ˜λΌλ©΄ 0~2000년도와 1~12μ›” 1~31μΌκΉŒμ§€μ˜ κ²½μš°μ˜μˆ˜κ°€ λ‚˜μ˜€λŠ”λ° μ΄λŠ” κ·Έλ ‡κ²Œ λ§Žμ€ 경우의 μˆ˜κ°€ μ•„λ‹ˆλ‹€
5.
3번의 경우의 μˆ˜μ—μ„œ μ†Œμˆ˜κ°€ λ‚˜μ˜€λŠ” 경우의 수λ₯Ό κ³„μ‚°ν•˜λ©΄ 이 μ—­μ‹œ 맀우 μ œν•œμ μ΄λ‹€.
1~5λ²ˆκΉŒμ§€μ˜ 생각을 ν†΅ν•΄μ„œ κ·Έλƒ₯ μ†Œμˆ˜λ₯Ό μˆœμ„œλŒ€λ‘œ λ„£μ–΄λ³΄λ©΄μ„œ ν•΄λ‹Ή λ©”μ‹œμ§€λ₯Ό λ³΅ν˜Έν™”ν•œλ‹€λ©΄ λ³΅κ΅¬λ˜μ§€ μ•Šμ„κΉŒλΌκ³  μƒκ°ν–ˆλ‹€.
κ·Έλƒ₯ 이건 μ›ƒκ²¨μ„œ 보닀가 μ›ƒκ²¨μ„œγ…‹γ…‹γ…‹γ…‹γ…‹γ…‹γ…‹γ…‹γ…‹γ…‹γ…‹γ…‹γ…‹γ…‹γ…‹γ…‹γ…‹γ…‹γ…‹γ…‹

# get_prime Code

def solution(n): is_prime = [True for x in range(n+1)] p = 2 while (p * p < n): if is_prime[p]: for i in range(p * p, n + 1, p): is_prime[i] = False p += 1 prime_numbers = [p for p in range(2, n + 1) if is_prime[p]] return prime_numbers primes = solution(2000) with open('year_primes.txt','w')as f: for i in primes: f.write(str(i)+"\n") primes = solution(31) with open('day_primes.txt','w')as f: for i in primes: f.write(str(i)+"\n")
Python
볡사
일단 μœ„ μ½”λ“œλ‘œ μ†Œμˆ˜λ₯Ό λ¨Όμ € ꡬ해쀬닀

# Payload

def extended_gcd(a, b): """ν™•μž₯ μœ ν΄λ¦¬λ“œ μ•Œκ³ λ¦¬μ¦˜μ„ μ‚¬μš©ν•˜μ—¬ gcd(a, b)와 λ² μ£Ό ν•­λ“±μ‹μ˜ κ³„μˆ˜λ₯Ό μ°ΎμŠ΅λ‹ˆλ‹€.""" if a == 0: return b, 0, 1 else: gcd, x1, y1 = extended_gcd(b % a, a) x = y1 - (b // a) * x1 y = x1 return gcd, x, y def find_d(e, phi_n): """ν™•μž₯ μœ ν΄λ¦¬λ“œ μ•Œκ³ λ¦¬μ¦˜μ„ μ‚¬μš©ν•˜μ—¬ κ°œμΈν‚€ μ§€μˆ˜ dλ₯Ό κ³„μ‚°ν•©λ‹ˆλ‹€. dλŠ” e의 λͺ¨λ“ˆλŸ¬ Ο†(n)에 λŒ€ν•œ μ—­μ›μž…λ‹ˆλ‹€.""" gcd, x, y = extended_gcd(e, phi_n) if x < 0: x += phi_n # λͺ¨λ“ˆλŸ¬ 역원이 음수일 경우 μ–‘μˆ˜λ‘œ λ³€ν™˜ return x with open('day_primes.txt','r')as f: day_keys = [int(i.strip()) for i in f.readlines()] with open('year_primes.txt','r')as f: year_keys = [int(i.strip()) for i in f.readlines()] for e in range(1000): for year in year_keys: # RSA λ³΅ν˜Έν™”μ— ν•„μš”ν•œ κ°’λ“€ for day in day_keys: p = year # 예제 μ†Œμˆ˜ p q = day # 예제 μ†Œμˆ˜ q ciphertext = [ 9429, 263, 6992, 2243, 715, 6992, 4650, 7924, 237, 5486, 6204, 6239, 6204, 237, 494, 6239, 1794, 7167, 715, 5149, 6239, 3801, 3750, 6239, 1242, 13481, 7774, 3401 ] # # RSA λͺ¨λ“ˆλŸ¬μŠ€ Nκ³Ό 였일러 ν”Ό ν•¨μˆ˜ phi 계산 N = p * q phi = (p - 1) * (q - 1) # # κ°œμΈν‚€ d 계산 (e와 phi의 λͺ¨λ“ˆλ‘œ κ³±μ…ˆ 역원) d = find_d(e, phi) # # RSA λ³΅ν˜Έν™”: 평문 m = ciphertext^d mod N plaintext = list() for i in range(len(ciphertext)): plaintext.append(pow(ciphertext[i], d, N)) if plaintext[0] != ord('b'): continue try: _ = ''.join([chr(i) for i in plaintext]) print("λ³΅ν˜Έν™”λœ λ©”μ‹œμ§€({}, {}, {}): ".format(p,q,e), _) except: print("λ³΅ν˜Έν™”λœ λ©”μ‹œμ§€({}, {}, {}): ".format(p,q,e), "Non Printable")
Python
볡사
RSAμ—μ„œ p, qλŠ” λŒ€μΆ© 맞좜 수 μžˆμ§€λ§Œ eλ₯Ό μ•Œμ•„λ‚Ό 수 μ—†κΈ° λ•Œλ¬Έμ— eλŠ” 0~1000κΉŒμ§€ λ²”μœ„λ‘œ 작고 python3 main.py > 1.txt둜 μ½”λ“œλ₯Ό μ‹€ν–‰ν•œλ‹€.
vscode둜 Ctrl + Fλ₯Ό 눌러 검색 κΈ°λŠ₯을 μ΄μš©ν•΄ Flagλ₯Ό μ°Ύμ•„μ€€λ‹€.

# Flag

bronco{wh4t_th3_f0ck_1s_RSA}
Plain Text
볡사