Skip to content
Back to skills

Kctf2026 题7 暗能潜流

ASecurity

KCTF 2026 第七题 HexMaze 确定性加密逆向:6 字节固定骨架、nibble 周期变换、3 字节分块位置重排,通过已知明文恢复完整算法。

  • 271 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 23, 2026
tools

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 23, 2026

npx -y skills add manyuegong33/r0crawl_skills --skill 'kctf2026-题7-暗能潜流' --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Kctf2026 题7 暗能潜流?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Kctf2026 题7 暗能潜流
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/manyuegong33-kctf2026-7/badge)](https://www.skillsdirectory.com/skills/manyuegong33-kctf2026-7)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: kctf2026-题7-暗能潜流
description: KCTF 2026 第七题 HexMaze 确定性加密逆向:6 字节固定骨架、nibble 周期变换、3 字节分块位置重排,通过已知明文恢复完整算法。
---

# 题目摘要

目标为确定性加密程序 HexMaze。明文按 ASCII 字节处理,算法包含字节编码、十六进制位运算、模 16 循环偏移、固定位置重排和固定摘要扰动。所有样例和 FLAG 均使用密钥 `121`。

## 可验证常量

- 密钥:`121`
- 已知样例:
  - `TLU` → `94AA48550495`
  - `Hello` → `34BB405504B5223594B94C53`
  - `2026` → `A48844556485223322356483`
  - `abcd!` → `547B475584B5223564BB4553`
- FLAG 密文:`14CC4655547594BC475584C5848A43551495448C445584C5D4C9475564C534A84B55A4B574BA4355F495A48844556485648C495534A5548C4F5584A5B4BB405554B522332235A4B3`
- 最终 FLAG:`flag{T1u_2026_Kc7f_Crypt0_M4ster!}`

## 标准解法流程

1. **观察密文结构**
   - 密文按 6 字节一组输出
   - 3 字节明文对应 1 个 6-byte 块
   - 不足 3 字节的尾部仍补成完整 6 字节输出块
   - 完整块结构:`[a,4] [b,c] [4,d] [5,5] [e,4] [f,5]`,有效数据半字节为 `a b c d e f`

2. **确定 FLAG 长度**
   - FLAG 密文 144 hex chars = 72 bytes = 12 blocks
   - 最后一块结构 `22 33 22 35 ?4 ?3` 与余 1 字节尾块一致
   - 因此 `len(flag) mod 3 = 1`,总长度 `11 * 3 + 1 = 34` 字节

3. **提取有效数据**
   - 从每个 6-byte 块中提取有效半字节:`byte0.high, byte1.high, byte1.low, byte2.low, byte4.high, byte5.high`
   - 尾块根据 `len(plaintext) mod 3` 提取不同位置

4. **恢复密钥变换**
   - 密钥 `121` 表示周期操作:`1, 2, 1, 1, 2, 1, ...`
   - key=1:`(H,L) -> (L+4, H+5) mod 16`(交换 + 偏移)
   - key=2:`(H,L) -> (H+5, L+4) mod 16`(不交换 + 偏移)
   - 逆变换:key=1 时 `L=(a-4)%16, H=(b-5)%16`;key=2 时 `H=(a-5)%16, L=(b-4)%16`

5. **恢复位置重排**
   - 加密时从字符串右侧每 3 字节分块
   - 完整块:`ABC -> CAB`(右循环 1 位)
   - 两字节块:`AB -> BA`
   - 单字节:`A -> A`
   - 块顺序从右向左输出
   - 解密时执行左循环 1 位并反转块顺序

6. **解密 FLAG**
   - 按固定骨架提取有效半字节
   - 按密钥周期执行逆半字节变换
   - 逆位置重排得到最终 FLAG

## 可复用检查清单

- [ ] 观察密文固定块结构和固定半字节模式
- [ ] 通过已知明文恢复密钥对应的周期变换
- [ ] 识别分块位置重排模式(右循环、块反转)
- [ ] 处理尾块特殊情况(与长度模 3 相关)
- [ ] 逐层逆向:骨架提取 → 密钥逆变换 → 位置逆重排

## 通用方法论(重点)

> 本题只是"自定义分块编码/加密"的一个实例。**遇到同类型新题不要抄本题常量**,
> 照 [`METHODLOGY.md`](METHODLOGY.md) 的五步推导法 + [`derive_solver.py`](derive_solver.py)
> 自动推导器,喂几组已知样例即可重新推出全部参数(块结构/密钥周期/重排/尾块位置)。
> 方法论文档含:题型识别特征、五步推导法、验证清单、常见坑对照表。

Files in this skill

  • METHODLOGY.md5.4 KB
  • SKILL.md3.1 KB
  • derive_solver.py5.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…