<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cryptography Arsip - Bhineka blog</title>
	<atom:link href="https://blog.bhineka-tech.org/category/cryptography/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.bhineka-tech.org/category/cryptography/</link>
	<description></description>
	<lastBuildDate>Fri, 15 Nov 2024 20:33:01 +0000</lastBuildDate>
	<language>id</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.7.1</generator>

<image>
	<url>https://blog.bhineka-tech.org/wp-content/uploads/2024/10/logo-bintek-min.jpg</url>
	<title>cryptography Arsip - Bhineka blog</title>
	<link>https://blog.bhineka-tech.org/category/cryptography/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Logfrenzy WriteUp bhitech &#8211; challenge</title>
		<link>https://blog.bhineka-tech.org/2024/11/15/logfrenzy-writeup-bhitech-challenge/</link>
					<comments>https://blog.bhineka-tech.org/2024/11/15/logfrenzy-writeup-bhitech-challenge/#respond</comments>
		
		<dc:creator><![CDATA[xpl0dec]]></dc:creator>
		<pubDate>Fri, 15 Nov 2024 20:30:20 +0000</pubDate>
				<category><![CDATA[Capture The Flag]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[CTF]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[web exploitation]]></category>
		<category><![CDATA[web pentesting]]></category>
		<guid isPermaLink="false">https://blog.bhineka-tech.org/?p=352</guid>

					<description><![CDATA[<p>Sebenarnya challenge ini dibuat dari ide teman saya yang kebetulan juga saya ikut membantu dalam proses development dan deployment dimana challenge ini terkait dengan Web Exploitation dan Cryptography jadi langsung saja Bisa dibaca pada deskripsi untuk lebih jelas dan intinya pada deskripsi diberikan suatu clue yaitu regex dan analysis. Jika kita masuk pada halaman login [&#8230;]</p>
<p>Artikel <a href="https://blog.bhineka-tech.org/2024/11/15/logfrenzy-writeup-bhitech-challenge/">Logfrenzy WriteUp bhitech &#8211; challenge</a> pertama kali tampil pada <a href="https://blog.bhineka-tech.org">Bhineka blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Sebenarnya challenge ini dibuat dari ide teman saya yang kebetulan juga saya ikut membantu dalam proses development dan deployment dimana challenge ini terkait dengan Web Exploitation dan Cryptography jadi langsung saja</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="402" src="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015140-1024x402.png" alt="" class="wp-image-353" srcset="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015140-1024x402.png 1024w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015140-300x118.png 300w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015140-768x302.png 768w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015140-1536x603.png 1536w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015140.png 1825w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<pre class="wp-block-code has-vivid-green-cyan-color has-black-background-color has-text-color has-background has-link-color wp-elements-62309e10b1e9dcd51baa510e1739b84d"><code>LogFrenzy &#x1f575;&#x200d;&#x2642;&#x1f4bb;

Selamat datang di LogFrenzy, tantangan seru untuk menguji kemampuan analisis log dan regex! &#x1f50d; Di sini, peserta akan dihadapkan pada log penuh petunjuk tersembunyi. Tugasnya? Teliti, bongkar pola, pecahkan regex, dan temukan flag yang tersembunyi! &#x1f3c6;

Kecepatan dan ketelitian adalah kunci, tapi kreativitas dalam memecahkan masalah juga sangat diperlukan. Siap untuk tantangan ini di LogFrenzy? &#x1f4a5;

Level: Medium
Kategori: Web Exploitation &amp; Cryptography
Hadiah (First Solved): Rp 30.000 &#x1f3c5;

URL Challenge: 
https:&#47;&#47;logfrenzy.siber-tech.web.id
Flag: bhitech{...}

#ChallengeAccepted #LogLife #CTF #Bhitech</code></pre>



<p>Bisa dibaca pada deskripsi untuk lebih jelas dan intinya pada deskripsi diberikan suatu clue yaitu regex dan analysis.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="506" src="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015348-1024x506.png" alt="" class="wp-image-354" srcset="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015348-1024x506.png 1024w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015348-300x148.png 300w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015348-768x380.png 768w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015348-1536x760.png 1536w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015348.png 1854w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>Jika kita masuk pada halaman login terdapat 2 form input yaitu username dan password </p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="270" src="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015426-1024x270.png" alt="" class="wp-image-355" srcset="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015426-1024x270.png 1024w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015426-300x79.png 300w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015426-768x202.png 768w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015426-1536x405.png 1536w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-015426.png 1636w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>Dimana jika view source pada HTML code terdapat regex dari username dan password jadi kita diminta untuk melakukan bypass dan memecahkan validasi regex tersebut.</p>



<pre class="wp-block-code"><code>username regex:
^(?=.*&#91;A-Z])(?=.*&#91;a-z])(?=.*&#91;0-9])(?=.*&#91;!@#$%^&amp;*])&#91;A-Za-z0-9!@#$%^&amp;*]{12,20}$  

password regex: 
^(?=.*&#91;A-Z])(?=.*&#91;a-z])(?=.*&#91;0-9])(?=.*&#91;!@#$%^&amp;*])(?!.*(\d)\1{2,})(?!.*(&#91;A-Za-z0-9])\2{2,})&#91;A-Za-z0-9!@#$%^&amp;*]{20,30}$</code></pre>



<p>Jika kita memahami regex sangat mudah untuk memecahkan pattern dari validasi tersebut, pada regex username terdapat pola dimana kita harus menginputkan character mulai dari huruf besar, kecil, angka dan special character hingga 12 sampai 20 dan pada password meminta hingga 20 sampai 30 character.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="392" src="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020100-1024x392.png" alt="" class="wp-image-356" srcset="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020100-1024x392.png 1024w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020100-300x115.png 300w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020100-768x294.png 768w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020100-1536x589.png 1536w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020100.png 1811w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>Mulai analysis manual menggunakan webtools <a href="https://regex101.com/">https://regex101.com/</a> dan lakukan matching pada pattern regex disini kita inputkan dengan <strong><em>Bhitech!@123</em></strong> dan terlihat matching ya selanjutnya kita analysis pada bagian password</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="498" src="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020356-1024x498.png" alt="" class="wp-image-357" srcset="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020356-1024x498.png 1024w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020356-300x146.png 300w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020356-768x373.png 768w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020356-1536x747.png 1536w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020356.png 1862w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>pada password kita juga memiliki pattern yang cocok menggunakan string <em><strong>Bhitech123!A@testing</strong></em> jadi kita sudah menemukan username dan password</p>



<p>user: <strong><em>Bhitech!@123</em></strong></p>



<p>pass: <em><strong>Bhitech123!A@testing</strong></em></p>



<p>Jadi kita bisa lanjut untuk login..</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="493" src="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020730-1024x493.png" alt="" class="wp-image-359" srcset="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020730-1024x493.png 1024w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020730-300x144.png 300w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020730-768x370.png 768w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020730-1536x739.png 1536w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-020730.png 1762w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>Dan kita berhasil masuk dashboard, dan pada tampilan dashboard terdapat 3 list menu dan kita diminta untuk mendownload file log</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="868" height="463" src="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021018.png" alt="" class="wp-image-360" srcset="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021018.png 868w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021018-300x160.png 300w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021018-768x410.png 768w" sizes="auto, (max-width: 868px) 100vw, 868px" /></figure>



<p> Pada access log di file pertama tidak ada yang menarik hanya akses log dan menampilkan request path dari client jadi kita lanjut yang kedua</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="269" src="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021201-1024x269.png" alt="" class="wp-image-361" srcset="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021201-1024x269.png 1024w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021201-300x79.png 300w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021201-768x202.png 768w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021201.png 1324w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>pada file error log kedua juga tidak ada hint atau clue jadi kita skip dan lanjut pada file user action yang ketiga </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="308" src="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021312-1024x308.png" alt="" class="wp-image-362" srcset="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021312-1024x308.png 1024w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021312-300x90.png 300w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021312-768x231.png 768w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021312.png 1202w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>Dan disini menarik jadi pada file ketiga ini berisi log action user yang sudah login dan terdapat name cookie dari object User Action dimana berisi key session_id dan value semacam unique number. </p>



<p>Kemungkinan ini merupakan suatu valid session dari user sebelumnya karena dari key objectnya menunjukkan cookie jadi kita masukkan cookie dengan name session_id dan memilih acak salah satu value</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="450" src="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021942-1024x450.png" alt="" class="wp-image-363" srcset="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021942-1024x450.png 1024w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021942-300x132.png 300w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021942-768x337.png 768w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021942-1536x675.png 1536w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-021942.png 1707w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>Benar saja setelah input cookies, pada header website menampilkan suatu pesan yang dimana disana kita menemukan suatu cipher text </p>



<pre class="wp-block-code"><code>Kode rahasia:

3a273b1f001a3034070509163b24610f3a29183c211c550b3c101d0d3a2d692261342649363e2758175836282f

Petunjuk XOR:

Ingat, jika A ^ B = C, maka C ^ A = B! 
Semoga ini membantu!

Format flag: bhitech{...}</code></pre>



<p>Dan kita juga disuguhkan suatu petunjuk terkait dengan XOR. jadi XOR itu merupakan operasi cryptography ya dimana jika 1 ^ 1 = 0 maka 1 ^ 0 =1 atau gampangnya jika bilangan yang di XOR itu sama contoh 1 ^ 1 = 0 atau 0 ^ 0 = 0 dan sebaliknya jika bilangan berbeda maka hasilnya 1</p>



<p>Bisa asumsikan disini kita mempunyai ciphertext tapi tidak mempunyai key jadi rumusnya:</p>



<pre class="wp-block-code"><code>flag ^ key = ciphertext(kita punya)

jika

cipher ^ key = flag(kita belum punya)

disini kita membutuhkan key dimana kita sudah tau sebagian dari format flag yaitu bhitech{} jadi jika 

cipher ^ flag(sebagian) = key 

jadi kita perlu lakukan XOR dengan sebagian flag untuk mendapatkan key sehingga kita bisa melakukan decrypting pada ciphertext </code></pre>



<p>ada 2 cara ya kita bisa menggunakan webtools maupun membuat suatu program sendiri menggunakan python. Simplenya kita bisa menggunakan webtools dari cyberchef <a href="https://gchq.github.io/CyberChef/">https://gchq.github.io/CyberChef/</a></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="442" src="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-023654-1024x442.png" alt="" class="wp-image-364" srcset="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-023654-1024x442.png 1024w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-023654-300x130.png 300w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-023654-768x332.png 768w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-023654-1536x663.png 1536w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-023654.png 1880w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>Pertama kita convert dulu dari hex karena ciphertext disana di encode menggunakan hexadecimal lalu kedua kita pilih XOR</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="461" src="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-023844-1024x461.png" alt="" class="wp-image-366" srcset="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-023844-1024x461.png 1024w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-023844-300x135.png 300w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-023844-768x346.png 768w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-023844-1536x692.png 1536w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-023844.png 1894w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>Terlihat ya saat kita input bhitech(6 character) sebagian output menampilkan <em><strong>XORkey</strong></em>(6 character) karena kita menginput 6 character jadi hasil yang diambil juga 6 character yang dimana kita berhasil mendapatkan suatu key yaitu <em><strong>XORkey</strong></em> dan jika masukkan key yang valid</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="472" src="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-024119-1024x472.png" alt="" class="wp-image-367" srcset="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-024119-1024x472.png 1024w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-024119-300x138.png 300w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-024119-768x354.png 768w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-024119-1536x708.png 1536w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-024119.png 1888w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>Maka outputnya akan menampilkan flag yang benar atau bisa juga kita membuat simple program menggunakan python</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="281" src="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-032741-1024x281.png" alt="" class="wp-image-368" srcset="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-032741-1024x281.png 1024w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-032741-300x82.png 300w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-032741-768x210.png 768w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-032741.png 1230w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>dan jika kita run</p>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="601" height="148" src="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-032820.png" alt="" class="wp-image-371" style="width:837px;height:auto" srcset="https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-032820.png 601w, https://blog.bhineka-tech.org/wp-content/uploads/2024/11/Screenshot-2024-11-16-032820-300x74.png 300w" sizes="auto, (max-width: 601px) 100vw, 601px" /></figure>



<p>Flag: bhitech{Unlock3d_P@ssw0rd_Of_T1m3_C0nqu3r!ng}</p>



<p>Cukup sekian semoga bermanfaat, keep learning and exploring </p>



<p></p>
<p>Artikel <a href="https://blog.bhineka-tech.org/2024/11/15/logfrenzy-writeup-bhitech-challenge/">Logfrenzy WriteUp bhitech &#8211; challenge</a> pertama kali tampil pada <a href="https://blog.bhineka-tech.org">Bhineka blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.bhineka-tech.org/2024/11/15/logfrenzy-writeup-bhitech-challenge/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
