XCZ 2

[xcz.kr | Forensics] Prob24 write up

๐Ÿ“Ž http://xcz.kr/START/challenge.php ๐Ÿ‘พ Title Memoryyyyy Dumpppppp ๐Ÿ‘พ Description ๐Ÿ‘พ ์–ด๋Š๋‚  ๋‚˜๋Š” ์ปคํ”ผ์ง‘์—์„œ ๋…ธํŠธ๋ถ์„ ๋†“๊ณ  ์ž ์‹œ ์ž๋ฆฌ๋ฅผ ๋น„์› ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ๋‹ค์‹œ ์™€์„œ ์ž‘์—…์„ ํ•˜๋‹ค๊ฐ€ ์ž‘์—…ํ”„๋กœ๊ทธ๋žจ์ด ๊ฐ‘์ž๊ธฐ ๊บผ์กŒ๊ณ , ์ž‘์—…ํŒŒ์ผ๋“ค์ด ๋ชจ๋‘ ๋‹ค ์‚ญ์ œ๋˜์—ˆ๋‹ค. ์›์ธ์„ ์ฐพ๊ธฐ์œ„ํ•ด ๋‚˜๋Š” ์„œ๋‘˜๋Ÿฌ ๋ฉ”๋ชจ๋ฆฌ ๋คํ”„๋ฅผ ๋งŒ๋“ค์—ˆ๋‹ค. ์ด ๋ฉ”๋ชจ๋ฆฌ ๋คํ”„ํŒŒ์ผ์„ ๋ถ„์„ํ•˜์—ฌ ๋‹ค์Œ ์ •๋ณด๋ฅผ ์•Œ์•„๋‚ด์ž. ํ‚ค ํ˜•์‹ : (Process Name_PID_Port_Process Execute Time(Day of the week-Month-Day-Hour:Min:Sec-Years) ex (explorer.exe_1234_7777_Mon-Jan-01-12:00:00-2012) ๋ฉ”๋ชจ๋ฆฌ ๋คํ”„๋Š” ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ ๋˜๋Š” ์‹œ..

[xcz.kr | Forensics] Prob22 write up

๐Ÿ“Ž http://xcz.kr/START/challenge.php ๐Ÿ‘พ Title Who's Notebook? ๐Ÿ‘พ Description ๋‚ด ์นœ๊ตฌ A๋Š” ์–ด๋Š๋‚  ์ถœ๊ทผ๊ธธ์— ๋ˆ„๊ตฐ๊ฐ€ ์žƒ์–ด๋ฒ„๋ฆฐ ๊ฒƒ ๊ฐ™์€ ๋…ธํŠธ๋ถ์„ ๋ฐœ๊ฒฌํ•œ๋‹ค. A๋Š” ์ด ๋…ธํŠธ๋ถ์„ ์ฃผ์ธ์—๊ฒŒ ์ฐพ์•„์ฃผ๊ณ  ์‹ถ์ง€๋งŒ ์ฐพ์„ ๋ฐฉ๋ฒ•์„ ๋ชฐ๋ผ์„œ ํฌ๋ Œ์„œ์ธ ๋‚˜์—๊ฒŒ ๋…ธํŠธ๋ถ์„ ๋งก๊ธฐ๊ฒŒ๋œ๋‹ค. ์ด ๋…ธํŠธ๋ถ์˜ ์ฃผ์ธ์„ ์ฐพ์•„์ฃผ์ž. ์ธ์ฆํ‚ค ํ˜•์‹ : ์ถœ๋ฐœ์ง€_๊ฑฐ์ณ๊ฐ€๋Š”๊ณณ(1๊ณณ)_์ตœ์ข…๋„์ฐฉ์ง€ ์ธ์ฆํ‚ค๋Š” ๋ชจ๋‘ ๋Œ€๋ฌธ์ž๋กœ, ๋„์–ด์“ฐ๊ธฐ๋ฌด์‹œ ์˜ˆ) PLACE1_PLACE2_PLACE3 ๋จผ์ € ๋ฌธ์ œ์— ์ฒจ๋ถ€๋œ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•œ๋‹ค. ‘notebook’ ์ด๋ผ๋Š” ํŒŒ์ผ์ด ์ƒ์„ฑ๋œ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ํ™•์žฅ์ž๊ฐ€ ๋”ฐ๋กœ ์—†์–ด HxD๋ฅผ ์ด์šฉํ•ด ํŒŒ์ผ ์‹œ๊ทธ๋‹ˆ์ฒ˜๋ฅผ ํ™•์ธํ•œ๋‹ค. HxD๋Š” ์ด์ง„ ํŒŒ์ผ์„ ์ฝ๋Š” ๋ฌด๋ฃŒ ์—๋””ํ„ฐ ํ”„๋กœ๊ทธ๋žจ์œผ๋กœ, ์ฃผ๋กœ ์‚ฌ์šฉ๋˜๋Š” ๊ธฐ๋Šฅ์€..

728x90