flag format: bushbash{....} Unfortunately, it has ...

생성일: 2026년 7월 31일

답변에 사용된 모델 GPT-5.5 by Chat01

질문

bliss_2.png

flag format: bushbash{....}
Unfortunately, it has started snowing in the land of Windows XP. But there is a QR code in the image... somewhere. Uncovering it is all a matter of timing. Author: Cameron
solevd challenge rồi viết write up chi tiết

Python

python
from PIL import Image img=Image.open('/mnt/data/bliss_2.png') img.mode, img.size, img.info ('L', (300, 200), {'xmp': b'<?xpacket begin="\xef\xbb\xbf" id="W5M0MpCehiHzreSzNTczkc9d"?>\n<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">\n <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">\n <rdf:Description rdf:about=""\n xmlns:tiff="http://ns.adobe.com/tiff/1.0/"\n xmlns:dc="http://purl.org/dc/elements/1.1/"\n xmlns:exif="http://ns.adobe.com/exif/1.0/"\n xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/"\n xmlns:xmp="http://ns.adobe.com/xap/1.0/"\n xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/"\n xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#"\n tiff:ImageLength="200"\n tiff:ImageWidth="300"\n tiff:ResolutionUnit="2"\n tiff:XResolution="368014/3833"\n tiff:YResolution="368014/3833"\n exif:PixelXDimension="300"\n exif:PixelYDimension="200"\n exif:ColorSpace="65535"\n photoshop:ColorMode="1"\n photoshop:ICCProfile="Greyscale D50"\n xmp:ModifyDate="2026-07-23T19:04:31+10:00"\n xmp:MetadataDate="2026-07-23T19:04:31+10:00">\n <dc:title>\n <rdf:Alt>\n <rdf:li xml:lang="x-default">bliss_2</rdf:li>\n </rdf:Alt>\n </dc:title>\n <xmpMM:History>\n <rdf:Seq>\n <rdf:li\n stEvt:action="produced"\n stEvt:softwareAgent="Affinity 3.2.3"\n stEvt:when="2026-07-23T19:04:31+10:00"/>\n </rdf:Seq>\n </xmpMM:History>\n </rdf:Description>\n </rdf:RDF>\n</x:xmpmeta>\n<?xpacket end="r"?>', 'XML:com.adobe.xmp': '<?xpacket begin="\ufeff" id="W5M0MpCehiHzreSzNTczkc9d"?>\n<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">\n <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">\n <rdf:Description rdf:about=""\n xmlns:tiff="http://ns.adobe.com/tiff/1.0/"\n xmlns:dc="http://purl.org/dc/elements/1.1/"\n xmlns:exif="http://ns.adobe.com/exif/1.0/"\n xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/"\n xmlns:xmp="http://ns.adobe.com/xap/1.0/"\n xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/"\n xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#"\n tiff:ImageLength="200"\n tiff:ImageWidth="300"\n tiff:ResolutionUnit="2"\n tiff:XResolution="368014/3833"\n tiff:YResolution="368014/3833"\n exif:PixelXDimension="300"\n exif:PixelYDimension="200"\n exif:ColorSpace="65535"\n photoshop:ColorMode="1"\n photoshop:ICCProfile="Greyscale D50"\n xmp:ModifyDate="2026-07-23T19:04:31+10:00"\n xmp:MetadataDate="2026-07-23T19:04:31+10:00">\n <dc:title>\n <rdf:Alt>\n <rdf:li xml:lang="x-default">bliss_2</rdf:li>\n </rdf:Alt>\n </dc:title>\n <xmpMM:History>\n <rdf:Seq>\n <rdf:li\n stEvt:action="produced"\n stEvt:softwareAgent="Affinity 3.2.3"\n stEvt:when="2026-07-23T19:04:31+10:00"/>\n </rdf:Seq>\n </xmpMM:History>\n </rdf:Description>\n </rdf:RDF>\n</x:xmpmeta>\n<?xpacket end="r"?>', 'icc_profile': b'\x00\x00\x01\\lcms\x040\x00\x00mntrGRAYXYZ \x07\xea\x00\x07\x00\x13\x00\x07\x00\x0e\x00,acspAPPL\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xf6\xd6\x00\x01\x00\x00\x00\x00\xd3-lcms\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x04desc\x00\x00\x00\xb4\x00\x00\x006cprt\x00\x00\x00\xec\x00\x00\x00Lwtpt\x00\x00\x018\x00\x00\x00\x14kTRC\x00\x00\x01L\x00\x00\x00\x10mluc\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x0cenUS\x00\x00\x00\x1a\x00\x00\x00\x1c\x00G\x00r\x00e\x00y\x00s\x00c\x00a\x00l\x00e\x00 \x00D\x005\x000\x00\x00mluc\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x0cenUS\x00\x00\x000\x00\x00\x00\x1c\x00N\x00o\x00 \x00c\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00,\x00 \x00u\x00s\x00e\x00 \x00f\x00r\x00e\x00e\x00l\x00yXYZ \x00\x00\x00\x00\x00\x00\xf6\xd6\x00\x01\x00\x00\x00\x00\xd3-para\x00\x00\x00\x00\x00\x00\x00\x00\x00\x0233', 'dpi': (96.012, 96.012)})

Python

python
import random, numpy as np, cv2, datetime, time seeds=[ts, ts+36000, int(str(20260723190431)), 20260723, 190431, 2026, 723190431] def check(bits,name): for inv in [0,1]: im=((obs^bits^inv).reshape(a.shape)*255).astype(np.uint8) v,p,_=det.detectAndDecode(im) if v or p is not None: print("HIT",name,inv,v,p) for seed in seeds: r=random.Random(seed) check(np.fromiter((r.getrandbits(1) for _ in range(len(obs))),np.uint8,len(obs)),f'pybit {seed}') r=random.Random(seed) check(np.fromiter((r.randrange(2) for _ in range(len(obs))),np.uint8,len(obs)),f'pyrange {seed}') rs=np.random.RandomState(seed & 0xffffffff)

Python

python
import ctypes, os libc=ctypes.CDLL(None) def glibc_bits(seed,n,kind='lsb'): libc.srand(ctypes.c_uint(seed)) arr=np.empty(n,np.uint8) for i in range(n): r=libc.rand() arr[i]=(r&1) if kind=='lsb' else (r>1073741823) return arr for seed in seeds: for k in ['lsb','high']: bits=glibc_bits(seed,len(obs),k) out=obs^bits arr=out.reshape(a.shape) score=((arr[:,:-1]==arr[:,1:]).mean()+(arr[:-1,:]==arr[1:,:]).mean())/2 print(seed,k,out.mean(),score)

Python

python
bits=(a>0).astype(int) rowmeans=bits.mean(1); colmeans=bits.mean(0) rowmeans.min(),rowmeans.max(),colmeans.min(),colmeans.max(), np.argsort(rowmeans)[:5],np.argsort(rowmeans)[-5:] (np.float64(0.45666666666666667), np.float64(0.6), np.float64(0.425), np.float64(0.625), array([ 15, 41, 72, 125, 2]), array([131, 78, 68, 107, 76]))

Python

python
# autocorrelation equality for shifts scores=[] for dy in range(0,101): for dx in range(-100,101): if dy==0 and dx<=0: continue y1=max(0,dy); y2=min(200,200+dy) x1=max(0,dx); x2=min(300,300+dx) aa=bits[y1:y2,x1:x2]; bb=bits[y1-dy:y2-dy,x1-dx:x2-dx] scores.append(((aa==bb).mean(),dx,dy)) sorted(scores,reverse=True)[:10], sorted(scores)[:5] ([(np.float64(0.5163451776649746), 0, 3), (np.float64(0.5161538461538462), 0, 5), (np.float64(0.5157407407407407), 3, 0), (np.float64(0.5128730048577377), 80, 69), (np.float64(0.512728813559322), 5, 0), (np.float64(0.5118290598290598), -50, 83), (np.float64(0.5116053511705686), 1, 0), (np.float64(0.5115969930326366), 84, 99), (np.float64(0.511145851427248), -98, 29), (np.float64(0.5111185870479394), 95, 55)], [(np.float64(0.4876936026936027), 0, 2), (np.float64(0.48771201107649703), -86, 92), (np.float64(0.487972972972973), 4, 0), (np.float64(0.4888095238095238), 0, 4), (np.float64(0.4891207729468599), 75, 85)])

Python

python
# Windows FILETIME for timestamp filetime=(ts+11644473600)*10_000_000 vals=[filetime&0xffffffff,filetime>>32, int(filetime), ts*1000, ts*1_000_000] vals [1170946432, 31267458, 134292710710000000, 1784797471000, 1784797471000000]

Python

python
pat=np.ones((7,7),dtype=np.uint8) pat[1:6,1:6]=0; pat[2:5,2:5]=1 # Hamming distance every pos from numpy.lib.stride_tricks import sliding_window_view win=sliding_window_view(bits,(7,7)) dist=np.sum(win!=pat,axis=(-1,-2)) np.unravel_index(np.argsort(dist.ravel())[:20],dist.shape), np.sort(dist.ravel())[:20] ((array([187, 155, 60, 28, 55, 60, 170, 65, 170, 21, 104, 70, 153, 69, 149, 87, 154, 184, 40, 175]), array([ 95, 126, 151, 34, 12, 117, 72, 146, 157, 14, 39, 30, 138, 23, 70, 231, 41, 168, 119, 179])), array([11, 12, 12, 12, 12, 12, 12, 12, 12, 12, 12, 12, 12, 12, 12, 13, 13, 13, 13, 13]))

Python

python
candidates={ 'topbottom':bits[:100]^bits[100:], 'leftright':bits[:,:150]^bits[:,150:], 'odd_even_rows':bits[::2]^bits[1::2], 'odd_even_cols':bits[:,::2]^bits[:,1::2], } for n,H in candidates.items(): im=(H*255).astype(np.uint8) v,p,_=det.detectAndDecode(im) print(n,H.shape,H.mean(),v,p is not None) Image.fromarray(im).save('/mnt/data/'+n+'.png')

사고

Tested image frequency, variance, and denoising methods to decode noisy QR code

Worked for 5m 46s

답변

Mình chưa thể xác định flag một cách đáng tin cậy chỉ từ file bliss_2.png hiện tại, nên không muốn bịa flag/write-up.

Các dấu hiệu đã kiểm tra:

  • Ảnh PNG grayscale 300×200, chỉ có hai giá trị pixel 0255, trông như nhiễu nhị phân.
  • Không có APNG/GIF frame ẩn, dữ liệu nối thêm sau IEND, hay bit-plane phụ.
  • Metadata cho thấy ảnh được xuất bằng Affinity và có timestamp 2026-07-23 19:04:31 +10:00.
  • Đã thử giải QR trực tiếp, đảo màu, blur/median filter, XOR các hàng/cột, ghép chẵn–lẻ, chia ảnh thành nhiều frame, cùng một số PRNG phổ biến được seed bằng timestamp; chưa thu được QR hợp lệ.
  • Tên file bliss_2.png khá mạnh cho thấy challenge có thể còn bliss_1.png, một file tạo nhiễu, source/script, hoặc dữ kiện nằm trong tên/category của challenge. Hai ảnh rất có thể cần XOR hoặc so sánh theo thời gian.

Hãy gửi thêm tên đầy đủ + category của challenge và toàn bộ attachment trên trang challenge, đặc biệt nếu có bliss_1.png. Khi có đủ dữ liệu mình sẽ giải tiếp và viết write-up chi tiết bằng tiếng Việt, gồm script tái hiện và flag cuối cùng.

이 Q&A 공유하기