ones_and_zer0es (50 points)

eps1.1_ones-and-zer0es_c4368e65e1883044f3917485ec928173.mpeg

 

This was a warm-up "challenge". I'm including it as a writeup primarily because I have never posted previously about how to binary translate things like this. The file you download ends in .mpeg, but it's not an mpeg. In fact, the first thing I do with any challenge is to run the Linux "file" command on it.

 

$ file eps1.1_ones-and-zer0es_c4368e65e1883044f3917485ec928173.mpeg 
eps1.1_ones-and-zer0es_c4368e65e1883044f3917485ec928173.mpeg: ASCII text, with very long lines

 

I find it a little silly that they're trying to mislead people that way, but it's certainly fair game for a CTF and anyone playing should know better (or learn quickly). In any case, if you cat the file you see a binary string:

 

$ cat eps1.1_ones-and-zer0es_c4368e65e1883044f3917485ec928173.mpeg 


 

The obvious thing to do first is to see what it translates into. We'll use python (as usual), and first translate it into a large integer. Then change it to hex, which will be the stepping stone into decoding it as text. Note, this challenge could have been made more difficult by changing the encoding. We will use a python module called "binascii" to change the string hex into ASCII.

 

In [1]: from binascii import unhexlify
In [2]: i = open("eps1.1_ones-and-zer0es_c4368e65e1883044f3917485ec928173.mpeg","r").read()
In [3]: unhexlify(hex(int(i,2))[2:])
Out[3]: b"flat{People always make the best exploits.} I've never found it hard to hack most people. If you listen to them, watch them, their vulnerabilities are like a neon sign screwed into their heads."

 

Yeah, they had a typo in the flag. It's actually supposed to be "flag{" in the beginning. From the top down: import binascii, read the string into a variable, translate that string into an integer (explicitly telling python it's binary), convert the integer into hex and strip off the "0x" (this could be done a couple ways, I just chose to use the hex function call), then run unhexlify against it to convert the string hex representation into it's corresponding ASCII.

 

Flag: flag{People always make the best exploits.}