1 min read

[CTF GEMA] obf-0

CTF GEMA Groupe 2025

Niveau de Difficulté : Easy

Catégorie du Challenge : Malware

Description :

I hate snakes!

Steps to Solve

Lorsque vous ouvrirez le fichier, vous constaterez qu'il s'agit d'un code python mais qu'il est obfusqué :

= lambda __ : __import__('zlib').decompress(__import__('base64').b64decode(__[::-1]));exec((_)(b'=siEP/yB//77z7frbJsGI4Mf18dcS1vIey8MobtS0cMLcygePavh6KXsm8gc8yB2OfdWlE8O7wvGBXAUBZbpUoSZjkgn0mEaYJSzsSuJ3c5V0JlRWciT0o/z/QpIWmiSGR55zbT1h9MWWsq6wzT8YjxFr9hxT7GJ9OJtfZ9N6gk/YsWtIgaCOH+aFe67V0rDSMMW/fF8zb5OzFQ74vY7nKt7SsRRUy52FEuQAp8MF5pC3x0ryqtTe5fpEF3M4rBvUJifFGx389m+zyjTXl6F+qWi7AlAfB3Itv+Y8csZkuIO/Hs+v8UkQ4OgRyTFtMfhlupu8mauUB2t/Po0AGL+CDpBNRIaEVLtKZH0fB56aw+5odZ0lcoqUtodx9R1lhPwb6fBt7ZAUXzoTNQFNLRoqnFytL/mf73xCd6H4qhPGGMJ569UAVyGEKEcFjCeRKMlPGhxNToRCjwKP7nPfXdyjoFcXjP2UC/3HT5fGTAHcB2nV6G7U0aXut/+dD5IAdcqsjB2wKQNUkPUuItfIL5IQ8cvPiQXJ/PggHbVxOF5TloI9zrbPYMC6AEO1ccbauWkGWcGE2rsG50iXh650QH2EoJSejhbnClg7RYnzDqFqCz8vB4FxepoZuWwnO3KSBS9mTvtdUoGtXd71P4LmM2rcJtzlFmbGOH10q7iKDUesUGAHvyXyZzgFM6RovRnK+r+Cv7TLVlW1HtDvnFz3Xj43TmZYzDHsrIb13xWn3mS37gUnG+eJLRsNkD2Rl+hV7SbRDwlzO8r08xEuL54av/yQdKVlxoMgu25wtvFiv1shLQW2owKXv/Ec9h74KVvGyuQaRVvmeJFioeliN6ZsFOcETX2rNXeIiwpHnlHe/jk4ctngaakA6gjvir8c1a8xkWmadUqKr+UPn1zAuuxj4d6CafBB6rPF8/p3R5sZrAfjySuB5jYeNN+/jTKOp3ZTS76mYKcST1ZCeEDv/LsslwliIYqr+hCkNWGBnGlECZuKkUYMpXsHHO6nVmL8WaBrxF3TZr3XBpp0ajJBSknc5ZUgKvJiackzzbPHoK9CE36cwdjiz7g6pYkB9m9tDzz0V09sVixGM5a4tWcffhU/A2zQlEYIe+4+7NoPkb5LNSOIIOojBcUo5md88eAOjizuBGBBUPtZ4g2JpReBoGzvXxPfSjzUinH+9FtSyMEjoq7fl9J5VVwbywFh+Q0se0EdhP79sHEOO4ItCM9U29vuE7SF2lVQEMbD9OjxuzPRwgr+4+KQOxuqspmmqseEvsoZMxgiprc2nIICKjTGG3ffqxHtpltxhAwVeGKmRVP/lFC5ps8ko+Dd7kIi7FG/Vs5v02gtcfEDzxEnm3+0A1NoCGD6IvLJGOaE0Osh/tJ7LAkWI669fH1A/FdDZwNubhdqLp4bBHb1wpPIrfRPaDEvrq1QYVByLJd4Wd7pRvCsyl0m5hCFq0kSF2fGjhvOIGTxR2Gn9k1lad8tfl9MVvnpdBffWYhZqq86S9Sh4iIO26K87wuk7goIp5O6QdZpR4wMPLZvRdFoOjRarwWQV+qF739zGnCizakdhvVw5/P+gAVRx3PFj44oCqTiscqXXzXIrC2nYLagGHayA2Vxe0AnI1eOKgaS0SqSjshlfcQWegQa4L0Ba++2l6ZAkWfMU/iCuWNBA+kSecea8XCvqJBiJpFJBgt1yKmKHlLXUGmUTonTgAVa0JklYSy9fuzOCl9H3kimN38vbxGhYa8eh+cLIKbIXlEUWDahndrPR1KhhhFpuew4GJqpfCsGUi6zQ6Umc8g5jXSFxg/mhXtUiiX/JH325730oTr3xyvZ0CgC/tRAKDW1QRuHApOuZNKTyKBEN/LTjF4IQSgKkWP7SlYSttAm3C3Zxjg0I9nFRyjeUe6u/h3OO9emDDH8sFRFWm2BQtv4eCb/QeBfzM++1JHHIdtFSA1WkbhfXHxOCb5htzjcrb/gQ1nEr1DNINmDaIqLNNqahMWsah4CsSZ6v+2mIPRXV7vWAzorLDs5xsEVR4+JBXdFdUnsxLspFj5AHOeYF7XABvVpebslVe+5mvYmYoTPTTVUaJkOy7P2iwri6eccIz8E2e2qaEpx9OsZukrQSITlFR5E9rAHhgkJyzPOwVIu8kU0rT0+rDBps7nloNDEuCU2swKj67LeI2JUXNYcwG7OSY805FTbUoBRSBjCENzKKSGcM5w4ko5yQbTsb5PF5MrPN4HtUGeHuFrWAYnbU63T9A4ZBdpXbz2Br/YjZBGXzqy6IySdUGAaUD4Fx9TcNnBtS6+LAyS1vjnv61ssDoLssc1maHsxbQb9SfgjRakS0VcLx7nGLokHjj8sPWfBP70dpXVPkyCCYD3rxUGAX9YOpY7lI83Za+KYcNIkk8ufIbFYGXKC50DlxhyjWvNM5Dh4QcD1myJSmDcn6eDTIybe2/VF7I0pTlLealxCBdujAqF9eUaHDk+sjJZCRV+5v7zffNDWTWBaKPrto8ZO629aGplhakaO/lXzxOgyA/CtKl4IK/kxp70+MFeFt8TnNbwL8YVJtdYALi98r+fLFvIUiI9DwVPSBhIEgxvRKQFTgGPg4Tqegnhc/uvGiOFJgm4wSSIaaVior0LnS+CuTQx6gAQqahWGfXg7n2vzJt3wBuOUt37rw7ar4LxJp/V4gylqVysx6rHbU4gTbvoTlcw0btIWjTV9E3X5xwXClSCLhi/sf1qlglb2olOenV79KpNvkyL9hFhJ0vdSbZJIIADWsV6UD8MpZHwT13N5kkqm/ArIIlQP0i0aK77s1mT/kQm/PiBACrUSeA4hvur9VsKHX1bA0qNfVkax+7GRR83WYgXEWSaqgvb3YPy2Yy8qAKLBj34TRVhCUVKShVHo6UVRqb+YEahn7U3QepxvWfV7xZjuQXRPb7NEcUGQ7UmjQu8XRy4vFxNEkPj3yzJotWW5jVcDSylSe+9c6/lflzW6B6MJYV7w4voLyYlxZVze40+aTvVM8r7ffBAz1MrE1Bzhi5wzq/QrM/9WSdRpP4o/ezW91gXlMhGZ54EhozBELSUW9JgW3V0va5Dgl74blDQFOh4ka88PA2gWmgqprKkYWbZEP1Pf0FCfMk+nUfRJeaV6kvNEAcR4oJF/5VfHa19NPsTg4IJswTDUby8E2fVTgHKBx3EjTTUF39szxjtfF2NeySD1DvBJBGdcQ+2aJZn37CfHp1id3XAckbYLjFH7Zh+5G/bcEkzxuPTd0VtDWzck4vMStk2YpJF1Ie6DeysRsTlsOXpjmZSxCaHkyT/GSdTQhsIB8iwlZU1hfDdvAWLm6CELhvXhy2v+VM7LYmY0Pc9jkava8BTb943cVD8PaDXMVOOcQgbuwRbuoDFVS57ZwzCeivi3ogzMEdxXFC1LeWrMdtfdNYYBs6RYbUjTZRSYkbgibe3cvofhZhZx/DAwoxb0CCJ6+pCI0PW/jpPkbzPFTJtUFu8NEbYAPGvOOYeEp0OnNHp+R6Q0JhO6X3qZpwOmTAjy1aBR/HCQFTgUwgYtSqYbhdX+ZE0hM+87PVqD88ILxO5GRtOWkBOEAc2oDZsD8nQjT+ogptuCr/qofgD6HYVnKv3T8DPoK+WuH07aLqbjUlCIOMeKicSQJoFTxtRqISquHEhw0ifk2q+6XzkKdpOk1qGqFs+ZSyLwCMnjrUykYamnkhsOjNV+6aU64Mwov9w3slSmniA8Ncd+YNg2/6XD7n8DYTxwybDq2ckoKqM9+UW3wP1wD3BXoqp4JKofVsXWn3QdxpBGbCX7pEv0nag+IUOCEPnIT/d46S7II5KU3NjAL9l6g+pIchXAPx8KQvtNCgn3rAqSugdhfNGGfeZGMXjLS5mBWYfiCnuKsiQp/w62DIWcKLcWAn8eQGoHAXGeUB4j3EICW8NTsUv/e+/T6///de++ryprynOuL4vvbVmJuuEiblZidgAYGoSn5YXVgcxyWzVNwJe'))

Si nous changeons le code de .txt en .py nous pouvons l'exécuter :

$ python3 chall.py      
FLAG{SO_SO_EAZY_LOL}

Flag

FLAG{SO_SO_EAZY_LOL}