usb流量分析
usb流量分析
kunkunusb流量
简介:
USB流量指的是USB设备接口的流量,攻击者能够通过监听usb接口流量获取键盘敲击键、鼠标移动与点击、存储设备的铭文传输通信、USB无线网卡网络传输内容等等。在CTF中,USB流量分析主要以键盘和鼠标流量为主
[NISACTF 2022]破损的flag
键盘流量分析
#!/usr/bin/env python |
ujkonjk,tfvbhyhjipokrdcvgrdcvgpokqwsztfvbhujkowazxdqasewsdrpokxdfviklpnjkwsdrrfgyrdcvguhnmkbhjmyhji
根据键盘上所包围住的找出所对应的字符,例如:ujko所包围的字符是i
im gulf flag is welcome t fjnu
NSSCTF{welcome to fjnu}
[CISCN 2022 初赛]ez_usb
wireshark里分析可以为usb中的键盘流量
搜索8个长度的字节包,可以发现其有2.8.1和2.10.1
usb.data_len == 8 |
使用tshark将其导出
tshark -r 2.pcapng -T fields -e usbhid.data -Y "usb.data_len == 8" -Y 'usb.src =="2.8.1"' > 1.txt |
由于导出数据没有加:所以我们要给其加上:
f=open('3.txt','r') |
键盘流量转化:
normalKeys = {"04":"a", "05":"b", "06":"c", "07":"d", "08":"e", "09":"f", "0a":"g", "0b":"h", "0c":"i", "0d":"j", "0e":"k", "0f":"l", "10":"m", "11":"n", "12":"o", "13":"p", "14":"q", "15":"r", "16":"s", "17":"t", "18":"u", "19":"v", "1a":"w", "1b":"x", "1c":"y", "1d":"z","1e":"1", "1f":"2", "20":"3", "21":"4", "22":"5", "23":"6","24":"7","25":"8","26":"9","27":"0","28":"<RET>","29":"<ESC>","2a":"<DEL>", "2b":"\t","2c":"<SPACE>","2d":"-","2e":"=","2f":"[","30":"]","31":"\\","32":"<NON>","33":";","34":"'","35":"<GA>","36":",","37":".","38":"/","39":"<CAP>","3a":"<F1>","3b":"<F2>", "3c":"<F3>","3d":"<F4>","3e":"<F5>","3f":"<F6>","40":"<F7>","41":"<F8>","42":"<F9>","43":"<F10>","44":"<F11>","45":"<F12>"} |
output1:16进制转化为rar压缩包
output2:rar压缩包密码
flag{20de17cc-d2c1-4b61-bebd-41159ed7172d}
[MoeCTF 2022]usb
找个类似题目练习一下
tshark -r 3.pcapng -T fields -e usbhid.data -Y "usb.data_len == 8" -Y 'usb.src =="2.2.1"' > 3.txt |
加****:
f=open('3.txt','r') |
键盘流量转化
normalKeys = {"04":"a", "05":"b", "06":"c", "07":"d", "08":"e", "09":"f", "0a":"g", "0b":"h", "0c":"i", "0d":"j", "0e":"k", "0f":"l", "10":"m", "11":"n", "12":"o", "13":"p", "14":"q", "15":"r", "16":"s", "17":"t", "18":"u", "19":"v", "1a":"w", "1b":"x", "1c":"y", "1d":"z","1e":"1", "1f":"2", "20":"3", "21":"4", "22":"5", "23":"6","24":"7","25":"8","26":"9","27":"0","28":"<RET>","29":"<ESC>","2a":"<DEL>", "2b":"\t","2c":"<SPACE>","2d":"-","2e":"=","2f":"[","30":"]","31":"\\","32":"<NON>","33":";","34":"'","35":"<GA>","36":",","37":".","38":"/","39":"<CAP>","3a":"<F1>","3b":"<F2>", "3c":"<F3>","3d":"<F4>","3e":"<F5>","3f":"<F6>","40":"<F7>","41":"<F8>","42":"<F9>","43":"<F10>","44":"<F11>","45":"<F12>"} |
moectf{Learned_a6ou7_USB_tr@ffic}
评论
匿名评论隐私政策