flag format: bushbash{....} Unfortunately, it has ...
Creado el: 31 de julio de 2026
Creado el: 31 de julio de 2026
flag format: bushbash{....}
Unfortunately, it has started snowing in the land of Windows XP. But there is a QR code in the image... somewhere. Uncovering it is all a matter of timing. Author: Cameron
solevd challenge rồi viết write up chi tiết
pythonfrom PIL import Image img=Image.open('/mnt/data/bliss_2.png') img.mode, img.size, img.info ('L', (300, 200), {'xmp': b'<?xpacket begin="\xef\xbb\xbf" id="W5M0MpCehiHzreSzNTczkc9d"?>\n<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">\n <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">\n <rdf:Description rdf:about=""\n xmlns:tiff="http://ns.adobe.com/tiff/1.0/"\n xmlns:dc="http://purl.org/dc/elements/1.1/"\n xmlns:exif="http://ns.adobe.com/exif/1.0/"\n xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/"\n xmlns:xmp="http://ns.adobe.com/xap/1.0/"\n xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/"\n xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#"\n tiff:ImageLength="200"\n tiff:ImageWidth="300"\n tiff:ResolutionUnit="2"\n tiff:XResolution="368014/3833"\n tiff:YResolution="368014/3833"\n exif:PixelXDimension="300"\n exif:PixelYDimension="200"\n exif:ColorSpace="65535"\n photoshop:ColorMode="1"\n photoshop:ICCProfile="Greyscale D50"\n xmp:ModifyDate="2026-07-23T19:04:31+10:00"\n xmp:MetadataDate="2026-07-23T19:04:31+10:00">\n <dc:title>\n <rdf:Alt>\n <rdf:li xml:lang="x-default">bliss_2</rdf:li>\n </rdf:Alt>\n </dc:title>\n <xmpMM:History>\n <rdf:Seq>\n <rdf:li\n stEvt:action="produced"\n stEvt:softwareAgent="Affinity 3.2.3"\n stEvt:when="2026-07-23T19:04:31+10:00"/>\n </rdf:Seq>\n </xmpMM:History>\n </rdf:Description>\n </rdf:RDF>\n</x:xmpmeta>\n<?xpacket end="r"?>', 'XML:com.adobe.xmp': '<?xpacket begin="\ufeff" id="W5M0MpCehiHzreSzNTczkc9d"?>\n<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">\n <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">\n <rdf:Description rdf:about=""\n xmlns:tiff="http://ns.adobe.com/tiff/1.0/"\n xmlns:dc="http://purl.org/dc/elements/1.1/"\n xmlns:exif="http://ns.adobe.com/exif/1.0/"\n xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/"\n xmlns:xmp="http://ns.adobe.com/xap/1.0/"\n xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/"\n xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#"\n tiff:ImageLength="200"\n tiff:ImageWidth="300"\n tiff:ResolutionUnit="2"\n tiff:XResolution="368014/3833"\n tiff:YResolution="368014/3833"\n exif:PixelXDimension="300"\n exif:PixelYDimension="200"\n exif:ColorSpace="65535"\n photoshop:ColorMode="1"\n photoshop:ICCProfile="Greyscale D50"\n xmp:ModifyDate="2026-07-23T19:04:31+10:00"\n xmp:MetadataDate="2026-07-23T19:04:31+10:00">\n <dc:title>\n <rdf:Alt>\n <rdf:li xml:lang="x-default">bliss_2</rdf:li>\n </rdf:Alt>\n </dc:title>\n <xmpMM:History>\n <rdf:Seq>\n <rdf:li\n stEvt:action="produced"\n stEvt:softwareAgent="Affinity 3.2.3"\n stEvt:when="2026-07-23T19:04:31+10:00"/>\n </rdf:Seq>\n </xmpMM:History>\n </rdf:Description>\n </rdf:RDF>\n</x:xmpmeta>\n<?xpacket end="r"?>', 'icc_profile': b'\x00\x00\x01\\lcms\x040\x00\x00mntrGRAYXYZ \x07\xea\x00\x07\x00\x13\x00\x07\x00\x0e\x00,acspAPPL\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xf6\xd6\x00\x01\x00\x00\x00\x00\xd3-lcms\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x04desc\x00\x00\x00\xb4\x00\x00\x006cprt\x00\x00\x00\xec\x00\x00\x00Lwtpt\x00\x00\x018\x00\x00\x00\x14kTRC\x00\x00\x01L\x00\x00\x00\x10mluc\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x0cenUS\x00\x00\x00\x1a\x00\x00\x00\x1c\x00G\x00r\x00e\x00y\x00s\x00c\x00a\x00l\x00e\x00 \x00D\x005\x000\x00\x00mluc\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x0cenUS\x00\x00\x000\x00\x00\x00\x1c\x00N\x00o\x00 \x00c\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00,\x00 \x00u\x00s\x00e\x00 \x00f\x00r\x00e\x00e\x00l\x00yXYZ \x00\x00\x00\x00\x00\x00\xf6\xd6\x00\x01\x00\x00\x00\x00\xd3-para\x00\x00\x00\x00\x00\x00\x00\x00\x00\x0233', 'dpi': (96.012, 96.012)})
pythonimport random, numpy as np, cv2, datetime, time seeds=[ts, ts+36000, int(str(20260723190431)), 20260723, 190431, 2026, 723190431] def check(bits,name): for inv in [0,1]: im=((obs^bits^inv).reshape(a.shape)*255).astype(np.uint8) v,p,_=det.detectAndDecode(im) if v or p is not None: print("HIT",name,inv,v,p) for seed in seeds: r=random.Random(seed) check(np.fromiter((r.getrandbits(1) for _ in range(len(obs))),np.uint8,len(obs)),f'pybit {seed}') r=random.Random(seed) check(np.fromiter((r.randrange(2) for _ in range(len(obs))),np.uint8,len(obs)),f'pyrange {seed}') rs=np.random.RandomState(seed & 0xffffffff)
pythonimport ctypes, os libc=ctypes.CDLL(None) def glibc_bits(seed,n,kind='lsb'): libc.srand(ctypes.c_uint(seed)) arr=np.empty(n,np.uint8) for i in range(n): r=libc.rand() arr[i]=(r&1) if kind=='lsb' else (r>1073741823) return arr for seed in seeds: for k in ['lsb','high']: bits=glibc_bits(seed,len(obs),k) out=obs^bits arr=out.reshape(a.shape) score=((arr[:,:-1]==arr[:,1:]).mean()+(arr[:-1,:]==arr[1:,:]).mean())/2 print(seed,k,out.mean(),score)
pythonbits=(a>0).astype(int) rowmeans=bits.mean(1); colmeans=bits.mean(0) rowmeans.min(),rowmeans.max(),colmeans.min(),colmeans.max(), np.argsort(rowmeans)[:5],np.argsort(rowmeans)[-5:] (np.float64(0.45666666666666667), np.float64(0.6), np.float64(0.425), np.float64(0.625), array([ 15, 41, 72, 125, 2]), array([131, 78, 68, 107, 76]))
python# autocorrelation equality for shifts scores=[] for dy in range(0,101): for dx in range(-100,101): if dy==0 and dx<=0: continue y1=max(0,dy); y2=min(200,200+dy) x1=max(0,dx); x2=min(300,300+dx) aa=bits[y1:y2,x1:x2]; bb=bits[y1-dy:y2-dy,x1-dx:x2-dx] scores.append(((aa==bb).mean(),dx,dy)) sorted(scores,reverse=True)[:10], sorted(scores)[:5] ([(np.float64(0.5163451776649746), 0, 3), (np.float64(0.5161538461538462), 0, 5), (np.float64(0.5157407407407407), 3, 0), (np.float64(0.5128730048577377), 80, 69), (np.float64(0.512728813559322), 5, 0), (np.float64(0.5118290598290598), -50, 83), (np.float64(0.5116053511705686), 1, 0), (np.float64(0.5115969930326366), 84, 99), (np.float64(0.511145851427248), -98, 29), (np.float64(0.5111185870479394), 95, 55)], [(np.float64(0.4876936026936027), 0, 2), (np.float64(0.48771201107649703), -86, 92), (np.float64(0.487972972972973), 4, 0), (np.float64(0.4888095238095238), 0, 4), (np.float64(0.4891207729468599), 75, 85)])
python# Windows FILETIME for timestamp filetime=(ts+11644473600)*10_000_000 vals=[filetime&0xffffffff,filetime>>32, int(filetime), ts*1000, ts*1_000_000] vals [1170946432, 31267458, 134292710710000000, 1784797471000, 1784797471000000]
pythonpat=np.ones((7,7),dtype=np.uint8) pat[1:6,1:6]=0; pat[2:5,2:5]=1 # Hamming distance every pos from numpy.lib.stride_tricks import sliding_window_view win=sliding_window_view(bits,(7,7)) dist=np.sum(win!=pat,axis=(-1,-2)) np.unravel_index(np.argsort(dist.ravel())[:20],dist.shape), np.sort(dist.ravel())[:20] ((array([187, 155, 60, 28, 55, 60, 170, 65, 170, 21, 104, 70, 153, 69, 149, 87, 154, 184, 40, 175]), array([ 95, 126, 151, 34, 12, 117, 72, 146, 157, 14, 39, 30, 138, 23, 70, 231, 41, 168, 119, 179])), array([11, 12, 12, 12, 12, 12, 12, 12, 12, 12, 12, 12, 12, 12, 12, 13, 13, 13, 13, 13]))
pythoncandidates={ 'topbottom':bits[:100]^bits[100:], 'leftright':bits[:,:150]^bits[:,150:], 'odd_even_rows':bits[::2]^bits[1::2], 'odd_even_cols':bits[:,::2]^bits[:,1::2], } for n,H in candidates.items(): im=(H*255).astype(np.uint8) v,p,_=det.detectAndDecode(im) print(n,H.shape,H.mean(),v,p is not None) Image.fromarray(im).save('/mnt/data/'+n+'.png')
Mình chưa thể xác định flag một cách đáng tin cậy chỉ từ file bliss_2.png hiện tại, nên không muốn bịa flag/write-up.
Các dấu hiệu đã kiểm tra:
0 và 255, trông như nhiễu nhị phân.IEND, hay bit-plane phụ.2026-07-23 19:04:31 +10:00.bliss_2.png khá mạnh cho thấy challenge có thể còn bliss_1.png, một file tạo nhiễu, source/script, hoặc dữ kiện nằm trong tên/category của challenge. Hai ảnh rất có thể cần XOR hoặc so sánh theo thời gian.Hãy gửi thêm tên đầy đủ + category của challenge và toàn bộ attachment trên trang challenge, đặc biệt nếu có bliss_1.png. Khi có đủ dữ liệu mình sẽ giải tiếp và viết write-up chi tiết bằng tiếng Việt, gồm script tái hiện và flag cuối cùng.