# HCMUS CTF 2023 ## Misc ### japanese có lyrics: ![](https://hackmd.io/_uploads/SycwMVBNn.png) Search google: ![](https://hackmd.io/_uploads/S1AKMEBE3.png) ![](https://hackmd.io/_uploads/H1x6fVBE3.png) flag: ```HCMUS-CTF{ifuudoudou-gumi_hatsunemiku_ia_kagaminerin_megurineluka}``` ### grind Thêm 3 file db vào DB Browser ![](https://hackmd.io/_uploads/rJcH74H42.png) Đề có ghi rằng tài khoản tạo gần trước 2019, có một bài post trên reddit chỉ ra uid và thời gian tham gia game: https://www.reddit.com/r/Granblue_en/comments/eyhg1m/help_with_making_a_gbf_id_timeline/ ![](https://hackmd.io/_uploads/Sy5nQ4rN2.png) => uid khoảng 23k->25k5 points day 3 khoảng 900M => points day3 - points day2 ~ 900M query: ```sql select * from "data-64-final".ranking as df where df.uid in (select uid from "data-64-final".ranking where(rank >5000) INTERSECT select d3.uid from "data-64-day3".ranking as d3, ranking as d2 where d3.uid = d2.uid and (d3.points - d2.points between 900000000 and 1000000000)) and uid BETWEEN 23000000 and 25500000 order by rank ASC ``` query khoảng 30 user có user tên ζ(2) ![](https://hackmd.io/_uploads/HyLq84S42.png) liên quan đến hàm zeta riemann ![](https://hackmd.io/_uploads/H1O9SVrV2.png) tính hàm đó ta được ![](https://hackmd.io/_uploads/Hyg2HNHN3.png) ```HCMUS-CTF{23983477-1.6449340668-2391789368-9614}``` ## Forensics Ta thấy dump lsass, dùng mimikatz để lấy credentials: ![](https://hackmd.io/_uploads/H1FMLNHNh.png)