{"id":81,"date":"2021-05-23T16:47:07","date_gmt":"2021-05-23T08:47:07","guid":{"rendered":"http:\/\/121.5.220.128\/wordpress\/?p=6"},"modified":"2021-08-20T01:35:08","modified_gmt":"2021-08-19T17:35:08","slug":"lsb%e9%9a%90%e5%86%99","status":"publish","type":"post","link":"http:\/\/101.34.19.194\/?p=81","title":{"rendered":"LSB\u9690\u5199"},"content":{"rendered":"<pre class=\"md-fences md-end-block ty-contain-cm modeLoaded\" lang=\"\" spellcheck=\"false\"><span role=\"presentation\">\u7531\u4e8eLSB\u9690\u5199\u662f\u5728\u6700\u4f4e\u4f4d\u9690\u85cf\u6570\u636e\uff0c\u4e5f\u5c31\u662f\u5728\u6bd4\u8f83\u65e0\u5173\u7d27\u8981\u7684\u5730\u65b9\u9690\u85cf\uff0c\u56e0\u6b64\u53ea\u6709\u5728\u65e0\u635f\u538b\u7f29\uff08png\uff09\u6216\u65e0\u538b\u7f29(bmp)\u56fe\u7247\u4e0a\u5b9e\u73b0<\/span>\n<span role=\"presentation\">\u200b<\/span>\n<span role=\"presentation\"> jpg \u5c5e\u4e8e\u6709\u635f\u538b\u7f29\u683c\u5f0f\uff0c\u6211\u4eec\u4fee\u6539\u7684\u4fe1\u606f\u53ef\u80fd\u4f1a\u5728\u538b\u7f29\u7684\u8fc7\u7a0b\u4e2d\u88ab\u7834\u574f\uff1b\u800c png \u867d\u7136\u4e5f\u6709\u538b\u7f29\uff0c\u4f46\u5374\u662f\u65e0\u635f\u538b\u7f29\uff0c\u6211\u4eec\u4fee\u6539\u7684\u4fe1\u606f\u4e0d\u4f1a\u4e22\u5931<\/span>\n<span role=\"presentation\">\u200b<\/span>\n<span role=\"presentation\"> bmp \u56fe\u7247\u628a\u6240\u6709\u7684\u50cf\u7d20\u90fd\u6309\u539f\u6837\u50a8\u5b58\uff0c\u6ca1\u6709\u8fdb\u884c\u538b\u7f29\uff0c\u56e0\u6b64\u4e00\u822c\u4f1a\u7279\u522b\u7684\u5927 <\/span><\/pre>\n<h3 class=\"md-end-block md-heading\"><span class=\"md-pair-s \"><strong><span class=\"md-plain\">\u5de5\u5177\uff1astegsolve.jar<\/span><\/strong><\/span><\/h3>\n<h4 class=\"md-end-block md-heading\"><span class=\"md-pair-s \"><strong><span class=\"md-plain\">\u6b63\u5e38 &lt; &gt;<\/span><\/strong><\/span><\/h4>\n<h5 class=\"md-end-block md-heading\"><span class=\"md-pair-s \"><strong><span class=\"md-plain\">Colour Inversion (Xor)<\/span><\/strong><\/span><\/h5>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u989c\u8272\u53cd\u8f6c\uff0c\u5c06RGB\u6240\u8868\u793a\u7684\u4e8c\u8fdb\u5236 0 1\u4e92\u6362<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u5728CTF\u89e3\u9898\u8fc7\u7a0b\u4e2d\uff0c\u67d0\u4e00\u6b65\u53ef\u80fd\u5f97\u5230\u4e00\u5f20\u4e8c\u7ef4\u7801\uff0c\u4f46\u4e8c\u7ef4\u7801\u7684\u9ed1\u767d\u662f\u76f8\u53cd\u7684\uff0c\u8981\u60f3\u626b\u7801\u5f97\u5230\u4fe1\u606f\uff0c\u5c31\u9700\u8981\u8fdb\u884c\u989c\u8272\u53cd\u8f6c\uff08\u4e8c\u7ef4\u7801\u901a\u5e38\u7531\u9ed1\u767d\u7ec4\u6210\uff0c\u53cd\u8f6c\u5bf9\u7acb\uff09<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-image md-img-loaded\" data-src=\"https:\/\/gitee.com\/hermitaria\/blogimagee\/raw\/master\/20210820013136.png\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/gitee.com\/hermitaria\/blogimagee\/raw\/master\/20210820013136.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/gitee.com\/hermitaria\/blogimagee\/raw\/master\/20210820013136.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20210601231635135\" \/><\/div><\/span><\/p>\n<h5 class=\"md-end-block md-heading\"><span class=\"md-pair-s \"><strong><span class=\"md-plain\">4\u901a\u9053<\/span><\/strong><\/span><\/h5>\n<p class=\"md-end-block md-p\"><span class=\"md-pair-s \"><strong><span class=\"md-plain\">Alpha plane\u3001Red plane<\/span><\/strong><\/span><span class=\"md-plain\">\u3001<\/span><span class=\"md-pair-s \"><strong><span class=\"md-plain\">Green plane<\/span><\/strong><\/span><span class=\"md-plain\">\u3001Blue plane<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">4\u4e2a\u901a\u9053\uff0c\u6bcf\u4e2a\u901a\u9053\u5404\u9700\u89818bit\uff0cStegSolve\u5c06 4 \u00d7 8 = 32 \u4e2abit\u4f4d\u7f6e\u7684\u6570\u636e\u90fd\u63d0\u53d6\u51fa\u6765\uff0c\u5355\u72ec\u5f62\u6210\u56fe\u7247\u663e\u793a\u51fa\u6765\u3002\u8fd9\u6070\u597d\u5bf9\u5e94\u4e86\u4e0a\u9762\u7684LSB\u9690\u5199<\/span><\/p>\n<h4 class=\"md-end-block md-heading\"><span class=\"md-pair-s \"><strong><span class=\"md-plain\">Analyse<\/span><\/strong><\/span><\/h4>\n<h5 class=\"md-end-block md-heading\"><span class=\"md-pair-s \"><strong><span class=\"md-plain\">File Format \u2014\u2014 \u6587\u4ef6\u683c\u5f0f<\/span><\/strong><\/span><\/h5>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u67e5\u770b\u56fe\u7247\u7684\u5177\u4f53\u4fe1\u606f\uff0c\u6709\u65f6\u5019flag\u4f1a\u9690\u85cf\u5728\u8fd9\u91cc\u9762<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u5b83\u4e0e\u76f4\u63a5\u70b9\u51fb\u56fe\u7247\u53f3\u952e&#8221;\u5c5e\u6027&#8221;\uff0c\u67e5\u770b&#8221;\u8be6\u7ec6\u4fe1\u606f&#8221;\u76f8\u8f85\u76f8\u6210\uff0c\u4e24\u8005\u63d0\u4f9b\u7684\u4fe1\u606f\u6709\u91cd\u53e0\u3001\u4e5f\u6709\u4e92\u4e0d\u76f8\u540c<\/span><\/p>\n<h5 class=\"md-end-block md-heading\"><span class=\"md-pair-s \"><strong><span class=\"md-plain\">Stereogram Solver \u2014\u2014 \u7acb\u4f53\u8bd5\u56fe<\/span><\/strong><\/span><\/h5>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u56fe\u7247\u4e0e\u56fe\u7247\u81ea\u8eab\u8fdb\u884c\u5f02\u6216\u8fd0\u7b97\uff0c\u56e0\u6b64\u521d\u59cb\u7684 offet: 0 \u65f6\u7684\u56fe\u50cf\u6c38\u8fdc\u662f\u9ed1\u5c4f\uff08\u5bf9\u4e8e\u4efb\u610f a\uff0c\u90fd\u6709a ^ a = 0\uff09<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u53ef\u4ee5\u63a7\u5236offset(\u504f\u79fb\u91cf)\u5bf9\u5176\u4e2d\u4e00\u5f20\u8fdb\u884c\u79fb\u52a8\uff0c\u8fdb\u884c\u7684\u4ecd\u7136\u662f\u5f02\u6216\u8fd0\u7b97\uff1boffset\u7684\u53d6\u503c\u8303\u56f4\u662f [0, \u56fe\u7247\u7684\u5bbd\u5ea6-1]<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u7528\u4e00\u5f20\u56fe\u7247\u8bd5\u8bd5\u5c31\u77e5\u9053\u600e\u4e48\u56de\u4e8b\u4e86<\/span><\/p>\n<h5 class=\"md-end-block md-heading\"><span class=\"md-pair-s \"><strong><span class=\"md-plain\">Frame Browser \u2014\u2014 \u5e27\u6d4f\u89c8\u5668<\/span><\/strong><\/span><\/h5>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u8be5\u529f\u80fd\u53ea\u9488\u5bf9 gif \u52a8\u56fe<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u6709\u65f6\u5019CTF\u4f1a\u5c06flag\u9690\u85cf\u5728 gif \u52a8\u56fe\u4e2d\uff0c\u4f1a\u5728 gif \u4e2d\u6025\u901f\u95ea\u8fc7\uff0c\u8fd9\u65f6\u5c31\u9700\u8981\u628a\u52a8\u56fe\u4e00\u5e27\u4e00\u5e27\u5730\u653e\uff1b\u6709\u65f6\u5019\u53c8\u4f1a\u628a gif \u653e\u6620\u5f97\u975e\u5e38\u6162\uff0c\u9700\u8981\u624b\u52a8\u67e5\u770b\u4e0b\u4e00\u5e27<\/span><\/p>\n<h5 class=\"md-end-block md-heading\"><span class=\"md-pair-s \"><strong><span class=\"md-plain\">Image Combiner \u2014\u2014 \u56fe\u50cf\u5408\u5e76<\/span><\/strong><\/span><\/h5>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u4f7f\u7528StegSolve\u6253\u5f00 1.png\uff0c\u518d\u5728Image Combiner\u4e2d\u6253\u5f00 2.png\uff0c\u80fd\u591f\u67e5\u770b\u4e24\u5f20\u56fe\u7247\u7684\u6570\u636e\u8fdb\u884c\u591a\u79cd\u8fd0\u7b97\u5448\u73b0\u51fa\u6765\u7684\u7ed3\u679c<\/span><\/p>\n<p class=\"md-end-block md-p\">\n<blockquote>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u4f8b\u9898\uff1a<\/span> <span class=\"md-plain\">\u4e0b\u8f7d \u7537\u795e.zip\uff0c\u89e3\u538b\u5f97\u5230\u4e24\u5f20\u56fe\u7247 first.png \u548c second.png\uff0c\u4e24\u5f20\u56fe\u7247\u770b\u4e0a\u53bb\u4e00\u6a21\u4e00\u6837\uff0c\u660e\u663e\u7684\u53cc\u56fe\u95ee\u9898<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u5c06 first.png \u653e\u5165StegSolve\u4e2d\uff0c\u5728Image Combiner\u4e2d\u6253\u5f00 second.png\uff0c\u53d1\u73b0\u5728 SUB (R,G,B separate) \u7684\u56fe\u50cf\u5448\u73b0\u4e8c\u7ef4\u7801\u7684\u5f62\u72b6\uff1a<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-image md-img-loaded\" data-src=\"https:\/\/gitee.com\/hermitaria\/blogimagee\/raw\/master\/20210820013216.png\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/gitee.com\/hermitaria\/blogimagee\/raw\/master\/20210820013216.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/gitee.com\/hermitaria\/blogimagee\/raw\/master\/20210820013216.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20210820013216866\" \/><\/div><\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u7136\u800c\u5b83\u5e76\u4e0d\u80fd\u76f4\u63a5\u88ab\u626b\u7801<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u5c06\u4e0a\u56fe\u53e6\u5b58\u4e3a colorfulQR.bmp\uff0c\u518d\u5728StegSolve\u4e2d\u6253\u5f00\uff0c\u5de6\u53f3\u67e5\u770b\uff0c\u53d1\u73b0\u8fd9\u540c\u65f6\u4e5f\u662f\u4e00\u9053LSB\u9690\u5199\u9898\uff0c\u5728RGB\u4e09\u8272\u901a\u9053\u7684\u6700\u4f4e\u4f4d\uff0c\u5206\u522b\u5b58\u50a8\u4e86\u4e00\u5f20\u4e8c\u7ef4\u7801<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u5c06Red plane 0\u3001Green plane 0\u3001Blue plane 0\u5bf9\u5e94\u7684\u56fe\u50cf\u5206\u522b\u5bfc\u51fa\uff0c\u5f97\u5230\uff1a<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-image md-img-loaded\" data-src=\"C:\\Users\\Administrator\\AppData\\Roaming\\Typora\\typora-user-images\\image-20210820013228642.png\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='file:\/\/C:\/Users\/Administrator\/AppData\/Roaming\/Typora\/typora-user-images\/image-20210820013228642.png?lastModify=1629345807'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"file:\/\/C:\/Users\/Administrator\/AppData\/Roaming\/Typora\/typora-user-images\/image-20210820013228642.png?lastModify=1629345807\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20210820013228642\" \/><\/div><\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u89c2\u5bdf\u53d1\u73b0\uff0c\u8fd9\u4e09\u5f20\u4e8c\u7ef4\u7801\u90fd\u662f\u53cd\u8272\u7684\uff0c\u9700\u8981\u8fdb\u884c\u989c\u8272\u53cd\u8f6c\u5904\u7406<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u518d\u6b21\u5c06\u4e09\u5f20\u56fe\u7247\u5bfc\u5165StegSolve\uff0c\u8fdb\u884cColour Inversion\u5904\u7406\uff1b\u628a\u4e09\u5f20\u5904\u7406\u540e\u7684\u4e8c\u7ef4\u7801\u4fdd\u5b58\uff0c\u6254\u5230\u5728\u7ebf\u4e8c\u7ef4\u7801\u89e3\u7801\u4e2d\uff0c\u4f1a\u5206\u522b\u5f97\u5230 DES\u30016XaMMbM7 \u548c \u4e00\u957f\u4e32\u88ab\u52a0\u5bc6\u7684\u5b57\u7b26\u4e32<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u6309\u7167\u63d0\u793a\u662fDES\u52a0\u5bc6\uff0c\u5bc6\u94a5\u4e3a 6XaMMbM7\uff0c\u968f\u4fbf\u627e\u4e2a\u5728\u7ebf\u7684DES\u89e3\u5bc6\u7f51\u7ad9\uff0c\u89e3\u7801\u5b57\u7b26\u4e32\u5f97\u5230flag <\/span><\/p>\n<\/blockquote>\n<p class=\"md-end-block md-p\">\n<p class=\"md-end-block md-p\">\n<h5 class=\"md-end-block md-heading\"><span class=\"md-pair-s \"><strong><span class=\"md-plain\">Data Extract \u2014\u2014 \u6570\u636e\u63d0\u53d6<\/span><\/strong><\/span><\/h5>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u5728StegSolve\u7684&lt;&gt;\u5207\u6362\u754c\u9762\u4e2d\uff0cStegSolve\u4f1a\u81ea\u52a8\u8bfb\u53d6RGBA\u7684\u5404\u4e2a\u901a\u9053\uff0c\u5c06\u5404\u4e2a\u901a\u9053\u7684\u6570\u636e\u7ed3\u5408\u6253\u5f00\u6587\u4ef6\u7684\u7c7b\u578b\uff08\u731c\u6d4b\u662f\u52a0\u4e0a\u5bf9\u5e94\u6587\u4ef6\u7684\u4e00\u4e9b\u683c\u5f0f\u6570\u636e\uff0c\u5982 jpg \u5c31\u6dfb\u52a0\u6587\u4ef6\u5934\u6807\u8bc6 FF D8\u3001\u6587\u4ef6\u5c3e\u6807\u8bc6 FF D9\uff09\uff0c\u91cd\u65b0\u751f\u6210\u4e00\u5f20\u56fe\u7247\uff0c\u663e\u793a\u5728\u4e0a\u9762<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u4f46\u6709\u65f6\u5019\uff0cflag\u5e76\u4e0d\u4ee5\u56fe\u7247\u7684\u5f62\u5f0f\u5b58\u5728\uff0c\u5b83\u6709\u53ef\u80fd\u5c31\u4ee5\u6570\u636e\u7684\u5f62\u5f0f\u85cf\u533f\u5728\u67d0\u4e2a\u901a\u9053\u7684\u6570\u636e\u4e2d\uff0c\u8fd9\u65f6\u5c31\u8981\u901a\u8fc7Data Extract\u5355\u72ec\u6d4f\u89c8\u6570\u636e\u4e86<\/span><\/p>\n<h6 class=\"md-end-block md-heading\"><span class=\"md-pair-s \"><strong><span class=\"md-plain\">Bit Planes<\/span><\/strong><\/span><span class=\"md-plain\"> \u2014\u2014 <\/span><span class=\"md-pair-s \"><strong><span class=\"md-plain\">\u4f4d\u901a\u9053<\/span><\/strong><\/span><\/h6>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u8fd9\u91cc\u7f57\u5217\u4e86RGBA\u56db\u6761\u901a\u9053\u7684\u54048\u4f4d\uff0c\u5982\u679c\u70b9\u51fbBlue 0\uff0cStegSolve\u5c06\u4f1a\u63d0\u53d6\u6574\u5f20\u56fe\u7247\u5404\u4e2a\u50cf\u7d20\u70b9\u4e2d\uff0c\u4ee3\u8868\u84dd\u8272\u6df1\u5ea6\u76848\u4f4d\u4e8c\u8fdb\u5236\u7684\u6700\u540e\u4e00\u4f4d\uff0c\u63d0\u53d6\u51fa\u6765\u7684 010101&#8230; \u53ef\u4ee5\u901a\u8fc7Preview\u67e5\u770b<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u6ce8\u610f\u8fd9\u91cc\u5f3a\u8c03\u63d0\u53d6\u51fa\u6765\u7684\u662f 010101&#8230; \u7684\u4e8c\u8fdb\u5236\u6570\u636e\uff0c\u56e0\u4e3aBlue\u7684\u53d6\u503c\u670928\u79cd\uff0c\u76f8\u5f53\u4e8e\u4e00\u4e2a8\u4f4d\u4e8c\u8fdb\u5236\u6570\u503c\u3002\u5047\u8bbeBlue\u901a\u9053\u5404\u4f4d\u4e0a\u7684\u6570\u636e\u662f 01010101\uff0c\u521d\u59cb\u65f68\u4e2a\u25a2\u90fd\u672a\u52fe\u4e0a\uff0c\u56e0\u6b64\u8bfb\u53d6\u4e0d\u5230\u6570\u636e\uff1b\u5982\u679c\u52fe\u9009\u4e86\u540e\u4e94\u4e2a\u25a2\uff0c\u5219\u8bfb\u53d6\u4e86\u6570\u636e 10101<\/span><\/p>\n<h6 class=\"md-end-block md-heading\"><span class=\"md-pair-s \"><strong><span class=\"md-plain\">Preview<\/span><\/strong><\/span><span class=\"md-plain\">\u2014\u2014 <\/span><span class=\"md-pair-s \"><strong><span class=\"md-plain\">\u9884\u89c8<\/span><\/strong><\/span><\/h6>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u6b63\u5982\u4e0a\u9762\u4e3e\u4f8b\u6240\u793a\uff0c\u5982\u679c\u70b9\u51fb\u7684\u662fBlue 0\uff0cStegSolve\u81ea\u52a8\u63d0\u53d6\u51fa\u6765\u7684 10101\uff0c\u7531\u4e8e\u4e8c\u8fdb\u5236\u6570\u9700\u8981\u8f6c\u5341\u516d \u8fdb\u5236\u6570\uff0c\u56e0\u6b64\u9700\u8981\u51d1\u9f508\u4f4d\uff1b\u5bf9\u4e8e\u63d0\u53d6\u51fa\u6765\u7684\u6570\u636e\u4e0d\u6ee18\u4f4d\uff0c\u5c06\u4f1a\u5728\u540e\u9762\u81ea\u52a8\u586b\u5145 0<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u56e0\u6b64\u8fd9\u65f6\u5019\u7684\u6570\u636e\u53d8\u6210\u4e86 10101000\uff0c\u5b83\u4f1a\u663e\u793a\u5728\u7a97\u53e3\u7684\u5de6\u7aef<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u6211\u4eec\u4ee5\u67d0\u6b21\u7684\u6570\u636e\u622a\u56fe\u6765\u5206\u6790<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-image md-img-loaded\" data-src=\"https:\/\/gitee.com\/hermitaria\/blogimagee\/raw\/master\/20210820013308.png\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/gitee.com\/hermitaria\/blogimagee\/raw\/master\/20210820013308.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/gitee.com\/hermitaria\/blogimagee\/raw\/master\/20210820013308.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20210820013308710\" \/><\/div><\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u7a97\u53e3\u7684\u6570\u636e\u7531\u4e24\u90e8\u5206\u7ec4\u6210\uff1a\u5de6\u4fa7\u662f\u63d0\u53d6\u51fa\u6765\u7684\u6570\u636e\u8f6c\u5341\u516d\u8fdb\u5236\u7684\u663e\u793a\uff0c\u53f3\u4fa7\u662f\u8fd9\u4e9b\u5341\u516d\u8fdb\u5236\u5bf9\u5e94\u7684Unicode\u5b57\u7b26<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u6bd4\u5982\u7b2c\u4e8c\u884c\u7b2c\u4e00\u4e2a\u7684 C\uff0c\u5b83\u5bf9\u5e94\u7684Unicode\u7801\u662f 67\uff0c\u5341\u8fdb\u5236\u6570 67 \u7684\u5341\u516d\u8fdb\u5236\u6070\u597d\u5c31\u662f 43<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u7a97\u53e3\u53f3\u4fa7\u53ea\u663e\u793aASCII\u5b57\u7b26\uff0c\u975eASCII\u5b57\u7b26\u90fd\u4f1a\u88ab . \u4ee3\u66ff<\/span><\/p>\n<h3 class=\"md-end-block md-heading\"><span class=\"md-pair-s \"><strong><span class=\"md-plain\">kali\u5185\u7684zsteg<\/span><\/strong><\/span><\/h3>\n<pre class=\"md-fences md-end-block ty-contain-cm modeLoaded\" lang=\"\" spellcheck=\"false\"><span role=\"presentation\">zsteg xxx.jpg\/xxx.png<\/span><\/pre>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u8981\u662f\u6709\u5f02\u5e38<\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-image md-expand md-img-loaded\" data-src=\"https:\/\/gitee.com\/hermitaria\/blogimagee\/raw\/master\/20210820013403.png\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/gitee.com\/hermitaria\/blogimagee\/raw\/master\/20210820013403.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/gitee.com\/hermitaria\/blogimagee\/raw\/master\/20210820013403.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\u672a\u547d\u540d\u56fe\u7247\" \/><\/div><\/span><\/p>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u8fd9\u65f6\u53ef\u4ee5\u63d0\u53d6\u5f02\u5e38\u6570\u636e<\/span><\/p>\n<pre class=\"md-fences md-end-block ty-contain-cm modeLoaded\" lang=\"\" spellcheck=\"false\"><span role=\"presentation\">zsteg -E \"extradata:0\" xxx.jpg\/xxx.png &gt; 1.txt<\/span><\/pre>\n<p class=\"md-end-block md-p\"><span class=\"md-plain\">\u63d0\u53d6\u51fa\u6765\u7684\u6570\u636e\u53ef\u4ee5\u7528foremost\u6216binwalk -e\u5206\u79bb<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u7531\u4e8eLSB\u9690\u5199\u662f\u5728\u6700\u4f4e\u4f4d\u9690\u85cf\u6570\u636e\uff0c\u4e5f\u5c31\u662f\u5728\u6bd4\u8f83\u65e0\u5173\u7d27\u8981\u7684\u5730\u65b9\u9690\u85cf\uff0c\u56e0\u6b64\u53ea\u6709\u5728\u65e0\u635f\u538b\u7f29\uff08png\uff09\u6216\u65e0\u538b\u7f29(bmp [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[2,5],"tags":[9],"_links":{"self":[{"href":"http:\/\/101.34.19.194\/index.php?rest_route=\/wp\/v2\/posts\/81"}],"collection":[{"href":"http:\/\/101.34.19.194\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/101.34.19.194\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/101.34.19.194\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/101.34.19.194\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=81"}],"version-history":[{"count":4,"href":"http:\/\/101.34.19.194\/index.php?rest_route=\/wp\/v2\/posts\/81\/revisions"}],"predecessor-version":[{"id":266,"href":"http:\/\/101.34.19.194\/index.php?rest_route=\/wp\/v2\/posts\/81\/revisions\/266"}],"wp:attachment":[{"href":"http:\/\/101.34.19.194\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=81"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/101.34.19.194\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=81"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/101.34.19.194\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=81"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}