Skip to content

Latest commit

 

History

History
44 lines (24 loc) · 795 Bytes

[HDCTF2019]你能发现什么蛛丝马迹吗.md

File metadata and controls

44 lines (24 loc) · 795 Bytes

[HDCTF2019]你能发现什么蛛丝马迹吗

知识点

volatility取证

解题

Volatility分析

查看文件的Profile

image-20231205182619027

profileWin2003SP0x86好像不对

image-20231205182946606

应该是Win2003SP1x86

image-20231205183028537

看一下cmd进程

image-20231205183135612

DumpIt.exe

发现Flag字样,将DumpIt.exe这个程序dump下来

volatility_2.6_lin64_standalone -f memory.img --profile=Win2003SP1x86 memdump -p 1992
--dump-dir=./

image-20231205183521498

foremost分离1992.dmp

image-20231205183608796

image-20231205183715546

image-20231205183656758