{"id":5293,"date":"2015-05-19T14:44:21","date_gmt":"2015-05-19T05:44:21","guid":{"rendered":"https:\/\/mimumimu.net\/blog\/?p=5293"},"modified":"2015-05-19T14:51:11","modified_gmt":"2015-05-19T05:51:11","slug":"defcon-ctf-23-quals-catwestern","status":"publish","type":"post","link":"https:\/\/mimumimu.net\/blog\/2015\/05\/19\/defcon-ctf-23-quals-catwestern\/","title":{"rendered":"DEFCON CTF 23 Quals &ndash; catwestern Writeup"},"content":{"rendered":"<p>\u3054\u7121\u6c99\u6c70\u3057\u3066\u307e\u3059\u3002\u307f\u3080\u3089\u3067\u3059\u3002    <br \/>\u4eca\u5e74\u306f\u3001\u67d0\u300c\u307f\u304b\u304b\u300d\u306a\u5834\u6240\u3067 Team Enu \u306e\u307f\u306a\u3055\u3093\u3068\u4e00\u7dd2\u306b\u53c2\u52a0\u3057\u3066\u304d\u307e\u3057\u305f\u3002<\/p>\n<p>\u3084\u306f\u308a\u5408\u5bbf\u5f62\u5f0f\u3067\u3084\u308b\u3068\u3044\u3046\u306e\u306f\u9762\u767d\u3044\u3067\u3059\u3057\u3001    <br \/>\u51fa\u6765\u308b\u4eba\u304c\u5468\u308a\u306b\u5c45\u307e\u3059\u3068\u3001\u305d\u308c\u3060\u3051\u3067\u304b\u306a\u308a\u6210\u9577\u3067\u304d\u308b\u306a\u3068\u3044\u3046\u3053\u3068\u3092\u5f37\u304f\u601d\u3044\u307e\u3057\u305f\u3002     <br \/>\u30fb\u30fb\u30fb\u6765\u5e74\u3082\u3053\u3046\u3044\u3046\u611f\u3058\u3067\u51fa\u6765\u305f\u3089\u3044\u3044\u306a\u3041\u30fb\u30fb\u3068\u601d\u3046\u305d\u3093\u306a\u4eca\u65e5\u3053\u306e\u9803\u3067\u3059\u3002<\/p>\n<p>\u3068\u3044\u3046\u308f\u3051\u3067\u3001\u3061\u3083\u3093\u3068\u6700\u5f8c\u307e\u3067\u81ea\u5206\u3067\u3084\u308a\u304d\u3063\u305f\u5185\u5bb9\u306e Write-up \u3068\u3044\u3046\u3053\u3068\u3067    <br \/>catwestern \u306eWrite-up \u3092\u3002<\/p>\n<p>&#160;<\/p>\n<h3>catwestern<\/h3>\n<hr \/>\n<p>\u6307\u5b9a\u3055\u308c\u305f\u30b5\u30fc\u30d0\u306b\u63a5\u7d9a\u3059\u308b\u3068\u6b21\u306e\u3088\u3046\u306a\u30d0\u30a4\u30ca\u30ea\u30c7\u30fc\u30bf\u304c\u9001\u4fe1\u3055\u308c\u3066\u304d\u307e\u3059\u3002<\/p>\n<p><a href=\"http:\/\/mimumimu.net\/blog\/wp-content\/uploads\/2015\/05\/image.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/mimumimu.net\/blog\/wp-content\/uploads\/2015\/05\/image_thumb.png\" width=\"619\" height=\"524\" \/><\/a><\/p>\n<p>&#160;<\/p>\n<p>\u4e0a\u306e\u65b9\u306f\u300c\u30ec\u30b8\u30b9\u30bf\u300d\u306e\u60c5\u5831\u3067\u3001    <br \/>\u201dAbout to send ** bytes:\u201d \u306e\u5148\u306b x86_64 \u3063\u307d\u3044\u30d0\u30a4\u30ca\u30ea\u304c     <br \/>\u9001\u3089\u308c\u3066\u304d\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308b\u304b\u3068\u601d\u3044\u307e\u3059\u3002     <\/p>\n<p>&#160;<\/p>\n<p>\u3053\u3053\u3067 mzyy94 \uff08\u307f\u3063\u304d\u30fc\uff09\u3055\u3093\u304c    <br \/>\u300crax=\u2026 \u3092\u305d\u306e\u307e\u307e\u8fd4\u3059\u3068\u3001\u5fdc\u7b54\u304c\u5909\u308f\u308b\uff01\u300d\u3068\u6559\u3048\u3066\u304f\u308c\u307e\u3057\u3066     <br \/>\u5b9f\u884c\u3057\u3066\u305d\u306e\u7d50\u679c\u3092\u8fd4\u305b\u3070\u3044\u3044\u306e\u304b\u306a\u3001\u3068\u3044\u3046\u3053\u3068\u3067\u3084\u3063\u3066\u307f\u307e\u3057\u305f\u3002<\/p>\n<p>&#160;<\/p>\n<p>Code:<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:da27e859-5e68-4fd6-bc15-90756f318a99\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: c++;\">#include &lt;stdio.h&gt;\n#include &lt;stdlib.h&gt;\n#include &lt;unistd.h&gt;\n#include &lt;arpa\/inet.h&gt;\n#include &lt;string.h&gt;\n#include &lt;sys\/mman.h&gt;\n \nstatic char* code;\nstatic unsigned long reg[15];\n \nvoid main(void)\n{\n    int sock;\n    struct sockaddr_in server;\n \n    memset((void*)&amp;server,0,sizeof(server));\n    server.sin_addr.s_addr = inet_addr(&quot;52.74.101.145&quot;);\n    server.sin_family = AF_INET;\n    server.sin_port = htons(9999);\n \n    sock = socket(AF_INET,SOCK_STREAM,0);\n    if(sock == -1) return;\n \n    if(connect(sock, (struct sockaddr*)&amp;server, sizeof(server)) &lt; 0)\n        return;\n \n    while(1)\n    {\n        char buf[4192];\n        int i,codesize,pagesize;\n \n        memset(buf,0,sizeof(buf));\n        read(sock,buf,sizeof(buf));\n \n        printf(&quot;INPUT : \\n%s\\n&quot;,buf);\n \n        {\n            char *tp;\n         \n            tp = strtok(buf,&quot;\\n&quot;);\n            for(i = -1; tp != NULL; i++)\n            {\n                if(strstr(tp,&quot;=&quot;) != 0)\n                    reg[i] = strtouq(strstr(tp,&quot;=&quot;)+1,NULL,0);\n                tp = strtok(NULL,&quot;\\n&quot;);\n            }\n        }\n\n        read(sock,buf,sizeof(buf));\n        codesize = atoi(buf+0x37);\n \n        if(codesize == 0)\n            break;\n \n        pagesize = sysconf(_SC_PAGE_SIZE);\n        code = memalign(pagesize,pagesize);\n \n        memset(code,0xC3,pagesize);\n        memcpy(code,buf+0x42,codesize);\n        printf(&quot;CODESIZE : %d bytes.\\n&quot;,codesize);\n \n        if(mprotect(code,pagesize,PROT_READ | PROT_EXEC) &lt; 0)\n        {\n            free(code);\n            return;\n        }\n \n        printf(&quot;EXECUTE..&quot;);\n \n        asm volatile (&quot;movq (reg),%rax&quot;);\n        asm volatile (&quot;movq (reg+8),%rbx&quot;);\n        asm volatile (&quot;movq (reg+16),%rcx&quot;);\n        asm volatile (&quot;movq (reg+24),%rdx&quot;);\n        asm volatile (&quot;movq (reg+32),%rsi&quot;);\n        asm volatile (&quot;movq (reg+40),%rdi&quot;);\n        asm volatile (&quot;movq (reg+48),%r8&quot;);\n        asm volatile (&quot;movq (reg+56),%r9&quot;);\n        asm volatile (&quot;movq (reg+64),%r10&quot;);\n        asm volatile (&quot;movq (reg+72),%r11&quot;);\n        asm volatile (&quot;movq (reg+80),%r12&quot;);\n        asm volatile (&quot;movq (reg+88),%r13&quot;);\n        asm volatile (&quot;movq (reg+96),%r14&quot;);\n        asm volatile (&quot;movq (reg+104),%r15&quot;);\n         \n        asm volatile (&quot;call *code&quot;);\n \n        asm volatile (&quot;movq %rax,(reg)&quot;);\n        asm volatile (&quot;movq %rbx,(reg+8)&quot;);\n        asm volatile (&quot;movq %rcx,(reg+16)&quot;);\n        asm volatile (&quot;movq %rdx,(reg+24)&quot;);\n        asm volatile (&quot;movq %rsi,(reg+32)&quot;);\n        asm volatile (&quot;movq %rdi,(reg+40)&quot;);\n        asm volatile (&quot;movq %r8,(reg+48)&quot;);\n        asm volatile (&quot;movq %r9,(reg+56)&quot;);\n        asm volatile (&quot;movq %r10,(reg+64)&quot;);\n        asm volatile (&quot;movq %r11,(reg+72)&quot;);\n        asm volatile (&quot;movq %r12,(reg+80)&quot;);\n        asm volatile (&quot;movq %r13,(reg+88)&quot;);\n        asm volatile (&quot;movq %r14,(reg+96)&quot;);\n        asm volatile (&quot;movq %r15,(reg+104)&quot;);\n         \n        printf(&quot;DONE.\\n&quot;);\n        free(code);\n \n        memset(buf,0,sizeof(buf));\n        sprintf(buf,&quot;rax=0x%llx\\nrbx=0x%llx\\nrcx=0x%llx\\nrdx=0x%llx\\nrsi=0x%llx\\nrdi=0x%llx\\nr8=0x%llx\\nr9=0x%llx\\nr10=0x%llx\\nr11=0x%llx\\nr12=0x%llx\\nr13=0x%llx\\nr14=0x%llx\\nr15=0x%llx\\n&quot;,reg[0],reg[1],reg[2],reg[3],reg[4],reg[5],reg[6],reg[7],reg[8],reg[9],reg[10],reg[11],reg[12],reg[13]);\n \n        printf(&quot;OUTPUT :\\n%s\\n&quot;,buf);\n        write(sock,buf,strlen(buf));\n    }\n}<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\u5185\u5bb9\u3068\u3057\u3066\u306f\u3001\u30ec\u30b8\u30b9\u30bf\u306e\u521d\u671f\u5024\u3092\u6301\u3063\u3066\u304d\u3066\u3001<br \/>\n  <br \/>\u81ea\u5206\u81ea\u8eab\u306b\u5bfe\u3057\u3066\u305d\u306e\u5024\u3092\u8a2d\u5b9a \u2192 \u5b9f\u884c \u2192 \u30ec\u30b8\u30b9\u30bf\u306e\u5024\u3092\u53d6\u5f97\u3057\u3066\u9001\u308a\u8fd4\u3059\u3002 <\/p>\n<p>\u3068\u3044\u3046\u6d41\u308c\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p>..\u305d\u3093\u306a\u611f\u3058\u3067\u5b9f\u884c\u3057\u307e\u3059\u3068\u3001 <\/p>\n<p>FLAG IS : Cats with frickin lazer beamz on top of their heads! <\/p>\n<p>\u3068\u3044\u3046\u3053\u3068\u3067\u8fd4\u7b54\u304c\u5e30\u3063\u3066\u304d\u307e\u3059\u3093\u3067\u3001\u3053\u308c\u3092\u9001\u308b\u3068\u5f97\u70b9\u304c\u3048\u3089\u308c\u307e\u3057\u305f\u3002<\/p>\n<p>&#160;<\/p>\n<hr \/>\n<p>\u4f59\u8ac7\uff1a<\/p>\n<p>\u3053\u306e\u3042\u305f\u308a\u306b\u5f8c\u308d\u59ff\u304c..<br \/>\n  <br \/><a title=\"https:\/\/www.ntt.com\/wideangle_security\/data\/sec_repo.html\" href=\"https:\/\/www.ntt.com\/wideangle_security\/data\/sec_repo.html\">https:\/\/www.ntt.com\/wideangle_security\/data\/sec_repo.html<\/a><\/p>\n<p>\u307e\u305f\u3001\u4eca\u56de\u3053\u305d\u306f \u201cPython \u30b3\u30fc\u30c9\u66f8\u304f\u305e\uff01\uff01\u201d \u3068\u601d\u3063\u3066\u3044\u305f\u3093\u3067\u3059\u304c\u3001<br \/>\n  <br \/>\u6c17\u3065\u3044\u305f\u3089 C \u3068 C# \u3057\u304b\u66f8\u3044\u3066\u3044\u307e\u305b\u3093\u3067\u3057\u305f\u3002 <\/p>\n<p>\uff08\u7279\u306b\u3001\u300c\u30b3\u30fc\u30c9\u8cbc\u3063\u3066\u3088\u300d\u2192\u300cC# \u3067\u3059\u304c\u3044\u3044\u3067\u3059\u304b\u300d\u2192\u300cC#\u2026 orz\u300d \u306e\u6d41\u308c\u306f\u8f9b\u304b\u3063\u305f\u3067\u3059\uff09<\/p>\n<p>\u6b21\u56de\u3053\u305d\u306f\u30fb\u30fb\u6b21\u56de\u3053\u305d\u306f\u30fb\u30fb\uff01<br \/>\n  <br \/>(Babyecho \u3082 Pwn \u3082 C# \u3067\u53d6\u308a\u7d44\u3093\u3067\u307e\u3057\u305f.&#160; BitConverter.GetBytes() \u306f\u5049\u5927\u3067\u3059.<\/p>\n<p>\u2026\u3053\u306e\u554f\u984c\u306e Write-up \u3082\u3001\u4ed6\u306e\u4eba\u306f\u307f\u3093\u306a\u901a\u4fe1\u90e8\u5206\u306f Python \u3067\u3084\u3063\u3066\u308b\u3093\u3067\u3059\u3088\u306d\u3002<br \/>\n  <br \/>\u3046\u30fc\u3093\u3084\u3063\u3071\u308a\u3084\u3089\u306a\u3044\u3068\u306a\u3041\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u3054\u7121\u6c99\u6c70\u3057\u3066\u307e\u3059\u3002\u307f\u3080\u3089\u3067\u3059\u3002 \u4eca\u5e74\u306f\u3001\u67d0\u300c\u307f\u304b\u304b\u300d\u306a\u5834\u6240\u3067 Team Enu \u306e\u307f\u306a\u3055\u3093\u3068\u4e00\u7dd2\u306b\u53c2\u52a0\u3057\u3066\u304d\u307e\u3057\u305f\u3002 \u3084\u306f\u308a\u5408\u5bbf\u5f62\u5f0f\u3067\u3084\u308b\u3068\u3044\u3046\u306e\u306f\u9762\u767d\u3044\u3067\u3059\u3057\u3001 \u51fa\u6765\u308b\u4eba\u304c\u5468\u308a\u306b\u5c45\u307e\u3059\u3068\u3001\u305d\u308c\u3060\u3051\u3067\u304b\u306a\u308a\u6210\u9577\u3067\u304d\u308b\u306a\u3068 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[581,579],"class_list":["post-5293","post","type-post","status-publish","format-standard","hentry","category-other","tag-catwestern-writeup","tag-defcon-ctf-23-quals"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"\u307f\u3080\u3089\"\/>\n\t<meta name=\"keywords\" content=\"catwestern writeup,defcon ctf 23 quals\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/mimumimu.net\/blog\/2015\/05\/19\/defcon-ctf-23-quals-catwestern\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"ja_JP\" \/>\n\t\t<meta property=\"og:site_name\" content=\"\u307f\u3080\u3089\u306e\u624b\u8a18\u624b\u5e33\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"DEFCON CTF 23 Quals \u2013 catwestern Writeup | \u307f\u3080\u3089\u306e\u624b\u8a18\u624b\u5e33\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/mimumimu.net\/blog\/2015\/05\/19\/defcon-ctf-23-quals-catwestern\/\" \/>\n\t\t<meta property=\"fb:admins\" content=\"100001278294483\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/mimumimu.net\/blog\/wp-content\/uploads\/2015\/05\/image_thumb.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/mimumimu.net\/blog\/wp-content\/uploads\/2015\/05\/image_thumb.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"619\" \/>\n\t\t<meta property=\"og:image:height\" content=\"524\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2015-05-19T05:44:21+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2015-05-19T05:51:11+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@mimura1133\" \/>\n\t\t<meta name=\"twitter:title\" content=\"DEFCON CTF 23 Quals \u2013 catwestern Writeup | \u307f\u3080\u3089\u306e\u624b\u8a18\u624b\u5e33\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/mimumimu.net\/blog\/wp-content\/uploads\/2015\/05\/image_thumb.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/2015\\\/05\\\/19\\\/defcon-ctf-23-quals-catwestern\\\/#article\",\"name\":\"DEFCON CTF 23 Quals \\u2013 catwestern Writeup | \\u307f\\u3080\\u3089\\u306e\\u624b\\u8a18\\u624b\\u5e33\",\"headline\":\"DEFCON CTF 23 Quals &ndash; catwestern Writeup\",\"author\":{\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/author\\\/mimura1133\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/#person\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/05\\\/image_thumb.png\",\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/2015\\\/05\\\/19\\\/defcon-ctf-23-quals-catwestern\\\/#articleImage\",\"width\":619,\"height\":524},\"datePublished\":\"2015-05-19T14:44:21+09:00\",\"dateModified\":\"2015-05-19T14:51:11+09:00\",\"inLanguage\":\"ja\",\"commentCount\":1,\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/2015\\\/05\\\/19\\\/defcon-ctf-23-quals-catwestern\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/2015\\\/05\\\/19\\\/defcon-ctf-23-quals-catwestern\\\/#webpage\"},\"articleSection\":\"\\u96d1\\u8a18, catwestern Writeup, DEFCON CTF 23 Quals\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/2015\\\/05\\\/19\\\/defcon-ctf-23-quals-catwestern\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog#listItem\",\"position\":1,\"name\":\"\\u30db\\u30fc\\u30e0\",\"item\":\"https:\\\/\\\/mimumimu.net\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/category\\\/other\\\/#listItem\",\"name\":\"\\u96d1\\u8a18\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/category\\\/other\\\/#listItem\",\"position\":2,\"name\":\"\\u96d1\\u8a18\",\"item\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/category\\\/other\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/2015\\\/05\\\/19\\\/defcon-ctf-23-quals-catwestern\\\/#listItem\",\"name\":\"DEFCON CTF 23 Quals &ndash; catwestern Writeup\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog#listItem\",\"name\":\"\\u30db\\u30fc\\u30e0\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/2015\\\/05\\\/19\\\/defcon-ctf-23-quals-catwestern\\\/#listItem\",\"position\":3,\"name\":\"DEFCON CTF 23 Quals &ndash; catwestern Writeup\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/category\\\/other\\\/#listItem\",\"name\":\"\\u96d1\\u8a18\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/#person\",\"name\":\"\\u307f\\u3080\\u3089\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/author\\\/mimura1133\\\/#author\",\"url\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/author\\\/mimura1133\\\/\",\"name\":\"\\u307f\\u3080\\u3089\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/2015\\\/05\\\/19\\\/defcon-ctf-23-quals-catwestern\\\/#webpage\",\"url\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/2015\\\/05\\\/19\\\/defcon-ctf-23-quals-catwestern\\\/\",\"name\":\"DEFCON CTF 23 Quals \\u2013 catwestern Writeup | \\u307f\\u3080\\u3089\\u306e\\u624b\\u8a18\\u624b\\u5e33\",\"inLanguage\":\"ja\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/2015\\\/05\\\/19\\\/defcon-ctf-23-quals-catwestern\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/author\\\/mimura1133\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/author\\\/mimura1133\\\/#author\"},\"datePublished\":\"2015-05-19T14:44:21+09:00\",\"dateModified\":\"2015-05-19T14:51:11+09:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/\",\"name\":\"\\u307f\\u3080\\u3089\\u306e\\u624b\\u8a18\\u624b\\u5e33\",\"description\":\"\\u3068\\u304d\\u3069\\u304d Developer \\u3068\\u304d\\u3069\\u304d Researcher \\u305d\\u3093\\u306a\\u793e\\u4f1a\\u4eba\\u306e\\u3044\\u3061\\u306b\\u3061\\u3002\",\"inLanguage\":\"ja\",\"publisher\":{\"@id\":\"https:\\\/\\\/mimumimu.net\\\/blog\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"DEFCON CTF 23 Quals \u2013 catwestern Writeup | \u307f\u3080\u3089\u306e\u624b\u8a18\u624b\u5e33","description":"","canonical_url":"https:\/\/mimumimu.net\/blog\/2015\/05\/19\/defcon-ctf-23-quals-catwestern\/","robots":"max-image-preview:large","keywords":"catwestern writeup,defcon ctf 23 quals","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/mimumimu.net\/blog\/2015\/05\/19\/defcon-ctf-23-quals-catwestern\/#article","name":"DEFCON CTF 23 Quals \u2013 catwestern Writeup | \u307f\u3080\u3089\u306e\u624b\u8a18\u624b\u5e33","headline":"DEFCON CTF 23 Quals &ndash; catwestern Writeup","author":{"@id":"https:\/\/mimumimu.net\/blog\/author\/mimura1133\/#author"},"publisher":{"@id":"https:\/\/mimumimu.net\/blog\/#person"},"image":{"@type":"ImageObject","url":"https:\/\/mimumimu.net\/blog\/wp-content\/uploads\/2015\/05\/image_thumb.png","@id":"https:\/\/mimumimu.net\/blog\/2015\/05\/19\/defcon-ctf-23-quals-catwestern\/#articleImage","width":619,"height":524},"datePublished":"2015-05-19T14:44:21+09:00","dateModified":"2015-05-19T14:51:11+09:00","inLanguage":"ja","commentCount":1,"mainEntityOfPage":{"@id":"https:\/\/mimumimu.net\/blog\/2015\/05\/19\/defcon-ctf-23-quals-catwestern\/#webpage"},"isPartOf":{"@id":"https:\/\/mimumimu.net\/blog\/2015\/05\/19\/defcon-ctf-23-quals-catwestern\/#webpage"},"articleSection":"\u96d1\u8a18, catwestern Writeup, DEFCON CTF 23 Quals"},{"@type":"BreadcrumbList","@id":"https:\/\/mimumimu.net\/blog\/2015\/05\/19\/defcon-ctf-23-quals-catwestern\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/mimumimu.net\/blog#listItem","position":1,"name":"\u30db\u30fc\u30e0","item":"https:\/\/mimumimu.net\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/mimumimu.net\/blog\/category\/other\/#listItem","name":"\u96d1\u8a18"}},{"@type":"ListItem","@id":"https:\/\/mimumimu.net\/blog\/category\/other\/#listItem","position":2,"name":"\u96d1\u8a18","item":"https:\/\/mimumimu.net\/blog\/category\/other\/","nextItem":{"@type":"ListItem","@id":"https:\/\/mimumimu.net\/blog\/2015\/05\/19\/defcon-ctf-23-quals-catwestern\/#listItem","name":"DEFCON CTF 23 Quals &ndash; catwestern Writeup"},"previousItem":{"@type":"ListItem","@id":"https:\/\/mimumimu.net\/blog#listItem","name":"\u30db\u30fc\u30e0"}},{"@type":"ListItem","@id":"https:\/\/mimumimu.net\/blog\/2015\/05\/19\/defcon-ctf-23-quals-catwestern\/#listItem","position":3,"name":"DEFCON CTF 23 Quals &ndash; catwestern Writeup","previousItem":{"@type":"ListItem","@id":"https:\/\/mimumimu.net\/blog\/category\/other\/#listItem","name":"\u96d1\u8a18"}}]},{"@type":"Person","@id":"https:\/\/mimumimu.net\/blog\/#person","name":"\u307f\u3080\u3089"},{"@type":"Person","@id":"https:\/\/mimumimu.net\/blog\/author\/mimura1133\/#author","url":"https:\/\/mimumimu.net\/blog\/author\/mimura1133\/","name":"\u307f\u3080\u3089"},{"@type":"WebPage","@id":"https:\/\/mimumimu.net\/blog\/2015\/05\/19\/defcon-ctf-23-quals-catwestern\/#webpage","url":"https:\/\/mimumimu.net\/blog\/2015\/05\/19\/defcon-ctf-23-quals-catwestern\/","name":"DEFCON CTF 23 Quals \u2013 catwestern Writeup | \u307f\u3080\u3089\u306e\u624b\u8a18\u624b\u5e33","inLanguage":"ja","isPartOf":{"@id":"https:\/\/mimumimu.net\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/mimumimu.net\/blog\/2015\/05\/19\/defcon-ctf-23-quals-catwestern\/#breadcrumblist"},"author":{"@id":"https:\/\/mimumimu.net\/blog\/author\/mimura1133\/#author"},"creator":{"@id":"https:\/\/mimumimu.net\/blog\/author\/mimura1133\/#author"},"datePublished":"2015-05-19T14:44:21+09:00","dateModified":"2015-05-19T14:51:11+09:00"},{"@type":"WebSite","@id":"https:\/\/mimumimu.net\/blog\/#website","url":"https:\/\/mimumimu.net\/blog\/","name":"\u307f\u3080\u3089\u306e\u624b\u8a18\u624b\u5e33","description":"\u3068\u304d\u3069\u304d Developer \u3068\u304d\u3069\u304d Researcher \u305d\u3093\u306a\u793e\u4f1a\u4eba\u306e\u3044\u3061\u306b\u3061\u3002","inLanguage":"ja","publisher":{"@id":"https:\/\/mimumimu.net\/blog\/#person"}}]},"og:locale":"ja_JP","og:site_name":"\u307f\u3080\u3089\u306e\u624b\u8a18\u624b\u5e33","og:type":"article","og:title":"DEFCON CTF 23 Quals \u2013 catwestern Writeup | \u307f\u3080\u3089\u306e\u624b\u8a18\u624b\u5e33","og:url":"https:\/\/mimumimu.net\/blog\/2015\/05\/19\/defcon-ctf-23-quals-catwestern\/","fb:admins":"100001278294483","og:image":"https:\/\/mimumimu.net\/blog\/wp-content\/uploads\/2015\/05\/image_thumb.png","og:image:secure_url":"https:\/\/mimumimu.net\/blog\/wp-content\/uploads\/2015\/05\/image_thumb.png","og:image:width":619,"og:image:height":524,"article:published_time":"2015-05-19T05:44:21+00:00","article:modified_time":"2015-05-19T05:51:11+00:00","twitter:card":"summary_large_image","twitter:site":"@mimura1133","twitter:title":"DEFCON CTF 23 Quals \u2013 catwestern Writeup | \u307f\u3080\u3089\u306e\u624b\u8a18\u624b\u5e33","twitter:image":"https:\/\/mimumimu.net\/blog\/wp-content\/uploads\/2015\/05\/image_thumb.png"},"aioseo_meta_data":{"post_id":"5293","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2020-12-24 18:44:53","updated":"2026-06-05 11:30:04","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/mimumimu.net\/blog\" title=\"\u30db\u30fc\u30e0\">\u30db\u30fc\u30e0<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/mimumimu.net\/blog\/category\/other\/\" title=\"\u96d1\u8a18\">\u96d1\u8a18<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tDEFCON CTF 23 Quals \u2013 catwestern Writeup\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"\u30db\u30fc\u30e0","link":"https:\/\/mimumimu.net\/blog"},{"label":"\u96d1\u8a18","link":"https:\/\/mimumimu.net\/blog\/category\/other\/"},{"label":"DEFCON CTF 23 Quals &ndash; catwestern Writeup","link":"https:\/\/mimumimu.net\/blog\/2015\/05\/19\/defcon-ctf-23-quals-catwestern\/"}],"_links":{"self":[{"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/posts\/5293","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/comments?post=5293"}],"version-history":[{"count":0,"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/posts\/5293\/revisions"}],"wp:attachment":[{"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/media?parent=5293"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/categories?post=5293"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/tags?post=5293"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}