Init. Commit

This commit is contained in:
Caplag
2026-09-17 00:50:07 +03:00
commit 880d8698d6
115 changed files with 7611 additions and 0 deletions
@@ -0,0 +1,49 @@
<h1 align="center">Wheelhouse Beacon</h1>
<p align="center">
<img src="https://img.shields.io/badge/category-Reverse-blueviolet" alt="Reverse"/>
<img src="https://img.shields.io/badge/difficulty-hard-critical" alt="hard"/>
</p>
В раздатке есть пакет `wheelhouse_beacon-0.4.2-py3-none-any.whl` из внутреннего ML/CI-зеркала. Один из этапов загрузки реализован в байткоде без исходного Python-модуля. Начинаем с содержимого архива и списка файлов в `*.dist-info/RECORD`.
## Решение
Среди обычных Python-модулей выделяется `wheelhouse_beacon/data/stage_gate.dat`. Содержимое файла распознаётся как LZMA. Извлекаем и распаковываем:
```python
import lzma
import marshal
import types
import zipfile
wheel_path = "public/wheelhouse_beacon-0.4.2-py3-none-any.whl"
with zipfile.ZipFile(wheel_path) as wheel:
packed = wheel.read("wheelhouse_beacon/data/stage_gate.dat")
stage = lzma.decompress(packed)
```
Внутри находится pyc с 16-байтным заголовком и marshal-объектом кода. Пропускаем заголовок и разбираем код, используя **Python 3.13**, под который собран артефакт.
Флаг может находиться в константах вложенной функции, поэтому одного `code.co_consts` недостаточно. Обходим объекты рекурсивно:
```python
code = marshal.loads(stage[16:])
def strings(code):
for value in code.co_consts:
if isinstance(value, str):
yield value
elif isinstance(value, types.CodeType):
yield from strings(value)
print(next(value for value in strings(code) if value.startswith("caplag{")))
```
Среди собранных строк находим значение, начинающееся с `caplag{`. При желании `dis.dis(code)` показывает, как стадия его использует, но для чтения флага исполнения пакета не требуется.
[Солвер](solve/solve.py).
## Флаг
`caplag{wheel_record_led_to_the_lzma_stage}`
@@ -0,0 +1,26 @@
#!/usr/bin/env python3
from pathlib import Path
import argparse, base64, hashlib, json, lzma, marshal, os, plistlib, re, struct, subprocess, sys, zipfile, zlib
def xor(data, key):
return bytes(b ^ key[i % len(key)] for i, b in enumerate(data))
def find_after(data, marker):
off = data.index(marker) + len(marker)
ln = struct.unpack_from('<I', data, off)[0]
off += 4
return data[off:off+ln]
def walk_consts(co):
out=[]
for c in co.co_consts:
if isinstance(c, str): out.append(c)
elif hasattr(c, 'co_consts'): out += walk_consts(c)
return out
def main():
ap=argparse.ArgumentParser(); ap.add_argument('wheel', nargs='?', default='../public/wheelhouse_beacon-0.4.2-py3-none-any.whl'); args=ap.parse_args()
with zipfile.ZipFile(args.wheel) as z:
stage=lzma.decompress(z.read('wheelhouse_beacon/data/stage_gate.dat'))
co=marshal.loads(stage[16:])
print(next(v for v in walk_consts(co) if v.startswith('caplag{')))
if __name__=='__main__': main()