flag 验证器
IDA + F5 反汇编得到代码:
int __cdecl main(int argc, const char **argv, const char **envp)
{
char v4[17]; // [esp+1Bh] [ebp-15h]
int i; // [esp+2Ch] [ebp-4h]
__main();
printf("Input your flag:");
scanf("%16s", v4);
for ( i = 0; i <= 15; ++i )
v4[i] ^= i;
if ( !strcmp(v4, aFmcd) )
printf("congratulations!");
else
printf("wrong flag!");
return 0;
}
找到 aFmcd 的地址:
.rdata:0040303A aFmcd db 'fmcd' ; DATA XREF: _main+65↑o
.rdata:0040303E db 7Fh ;
.rdata:0040303F db 57h ; W
.rdata:00403040 db 63h ; c
.rdata:00403041 db 71h ; q
.rdata:00403042 db 41h ; A
.rdata:00403043 db 7Ah ; z
.rdata:00403044 db 4Fh ; O
.rdata:00403045 db 6Ah ; j
.rdata:00403046 db 7Fh ;
.rdata:00403047 db 74h ; t
.rdata:00403048 db 70h ; p
.rdata:00403049 db 72h ; r
.rdata:0040304A db 0
故比较的字符串数据为(前四个就是 fmcd
):
66 6D 63 64 7F 57 63 71 41 7A 4F 6A 7F 74 70 72
进行一个简单的异或解密(异或下标)即可得到 flag