攻防世界WP-reverse-Reversing-XCTF 3rd-GCTF-2017-hackme

其他的不说了,查看伪代码

__int64 sub_400F8E()
{
  char v1[136]; // [rsp+10h] [rbp-B0h]
  int v2; // [rsp+98h] [rbp-28h]
  char v3; // [rsp+9Fh] [rbp-21h]
  int v4; // [rsp+A0h] [rbp-20h]
  unsigned __int8 v5; // [rsp+A6h] [rbp-1Ah]
  char v6; // [rsp+A7h] [rbp-19h]
  int v7; // [rsp+A8h] [rbp-18h]
  int v8; // [rsp+ACh] [rbp-14h]
  int v9; // [rsp+B0h] [rbp-10h]
  int v10; // [rsp+B4h] [rbp-Ch]
  _BOOL4 v11; // [rsp+B8h] [rbp-8h]
  int i; // [rsp+BCh] [rbp-4h]

  sub_407470((unsigned __int64)"Give me the password: ");
  sub_4075A0((unsigned __int64)"%s");
  for ( i = 0; v1[i]; ++i )
    ;
  v11 = i == 22;
  v10 = 10;
  do
  {
    v7 = (signed int)sub_406D90() % 22;
    v9 = 0;
    v6 = byte_6B4270[v7];
    v5 = v1[v7];
    v4 = v7 + 1;
    v8 = 0;
    while ( v8 < v4 )
    {
      ++v8;
      v9 = 1828812941 * v9 + 12345;
    }
    v3 = v9 ^ v5;
    if ( v6 != ((unsigned __int8)v9 ^ v5) )
      v11 = 0;
    --v10;
  }
  while ( v10 );
  if ( v11 )
    v2 = sub_407470((unsigned __int64)"Congras\n");
  else
    v2 = sub_407470((unsigned __int64)"Oh no!\n");
  return 0LL;
}

之前一直没有搞懂这个函数sub_406D90()是干什么的,看了别人的WP知道是一个随机数产生器。

代码如下

#include 
using namespace std;
int main()
{
	int v4; // [rsp+A0h] [rbp-20h]
	char v6; // [rsp+A7h] [rbp-19h]
	int v8; // [rsp+ACh] [rbp-14h]
	int v9; // [rsp+B0h] [rbp-10h]
	char str1[] = {95, 242, 94, 139, 78, 14, 163, 170, 199, 147, 129, 61, 95, 116, 163, 9, 145, 43, 73, 40, 147, 103, 0, 0};
	char result[22]={0};
	for (int i=0;i<22;i++)
	{
		v9=0;
		v6 = str1[i];
		v4 = i+1;
		v8=0;
		while (v8<v4)
		{
			++v8;
			v9 = 1828812941 * v9 + 12345;
		}

		result[i] = str1[i]^v9;
	}
	cout<<result;
	system("pause");
	return 0;
}

你可能感兴趣的:(ida,ctf,reverse)