Writeup 4 CSS CTF Semester 2 2026 - Dead Faction Servers
题目信息
- 题目名称:Dead Faction Servers
- 分值:10
- 难度:Beginner
- 类型:OSINT
- 题目描述:
The old faction that ran Sector 9 didn't leave one trail --- they left several, and most of them are decoys. Whoever built this infrastructure knew someone would come looking eventually, and buried the real access key across two separate locations, split in half, one piece scrambled beyond plain sight.
Your recon has already surfaced their handle and at least one archived project. Don't trust the first thing you find --- Sector 9's engineers were paranoid, and paranoid engineers plant false leads.
Starting trace:
bobdev508Flag Format:
CSSCTF{...}
解题思路概述
这是一道 OSINT + Git 历史分析 题目。核心思路是:
- 起点 :
bobdev508是一个 GitHub 用户名。 - 目标:flag 被拆成两半,分别藏在两个不同的地方。
- 陷阱 :大部分线索是诱饵(decoy),真正的 flag 藏在隐藏分支 和被删除的文件里。
- 关键技巧 :
- 使用
git clone拉取仓库(比网页更快、更完整) - 使用
git log --all发现隐藏分支 - 使用
git show <commit>查看被删除的文件 - 使用 Base64 解码
- 使用
详细解题步骤
第一步:确认起点
题目给出的起点是 bobdev508。在 GitHub 上搜索这个用户名:
https://github.com/bobdev508
可以看到该用户有 2 个仓库:
| 仓库名 | 描述 | 语言 |
|---|---|---|
dashboard-app |
Internal analytics dashboard. WIP. | Python |
decoy-project |
(名字直接叫"诱饵项目") | - |
注意 :decoy-project 名字就是"诱饵",说明它是干扰项。
第二步:克隆仓库
📌 git clone 命令详解
bash
git clone https://github.com/bobdev508/dashboard-app.git
git clone https://github.com/bobdev508/decoy-project.git
git clone 的作用:
- 把远程仓库完整复制到本地
- 包括所有分支 、所有 commit 历史 、所有文件版本
- 比在网页上浏览更完整(网页只显示当前分支的文件,不显示历史)
为什么用 git clone 而不是网页:
- 速度更快(尤其是 GitHub 网页加载慢时)
- 能看到完整历史(网页只能看到当前状态)
- 能用命令行搜索 (
git log、grep等) - 能切换分支(网页切换分支不如命令行方便)
国内加速方案(如果 GitHub 太慢):
bash
# 用镜像站
git clone https://ghproxy.com/https://github.com/bobdev508/dashboard-app.git
git clone https://gitclone.com/github.com/bobdev508/dashboard-app.git
第三步:检查仓库的 commit 历史
📌 git log 命令详解
bash
cd dashboard-app
git log --all --oneline
git log 的常用参数:
| 参数 | 作用 |
|---|---|
git log |
显示当前分支的 commit 历史 |
git log --all |
显示所有分支的 commit 历史(包括远程分支) |
git log --oneline |
每个 commit 只显示一行(简洁模式) |
git log --graph |
用 ASCII 图形显示分支合并情况 |
git log --all --graph --oneline |
组合使用,最直观 |
git log -p |
显示每个 commit 的完整 diff(改动内容) |
git log --stat |
显示每个 commit 改动的文件列表 |
git log --author="Bob" |
按作者过滤 |
git log --since="2025-01-01" |
按时间过滤 |
git log --diff-filter=D --name-only |
显示被删除的文件 |
本题输出:
5b3845b (HEAD -> main, origin/main, origin/HEAD) Add setup instructions to README
b72b7ff (origin/experimental/auth-rework) WIP: auth rework notes
99291d3 Remove committed secrets, oops
be82c69 Add local env file
457762d Add date helper
2421118 Add app entrypoint
56e1984 Initial commit
关键发现:
b72b7ff在一个叫origin/experimental/auth-rework的分支上 ------ 这是一个隐藏分支!99291d3的 commit message 是 "Remove committed secrets, oops" ------ 删除了提交的密码,说明被删除的内容里有秘密!
第四步:检查分支
📌 git branch 命令详解
bash
git branch -a
git branch 的常用参数:
| 参数 | 作用 |
|---|---|
git branch |
显示本地分支 |
git branch -a |
显示所有分支(本地 + 远程) |
git branch -r |
只显示远程分支 |
git branch -v |
显示每个分支的最后一个 commit |
git branch -vv |
显示每个分支的跟踪关系 |
本题输出:
* main
remotes/origin/HEAD -> origin/main
remotes/origin/experimental/auth-rework
remotes/origin/main
关键发现 :有一个隐藏分支 experimental/auth-rework(实验性认证重构)。
第五步:查看被删除的文件
📌 git show 命令详解
bash
git show 99291d3
git show 的作用:
- 显示某个 commit 的完整信息 ,包括:
- commit hash
- 作者
- 日期
- commit message
- 完整的 diff(改动内容)
本题输出:
diff
commit 99291d3882022272baa82680d6ae72f2074c4ab7
Author: Bob Martinez <bobdev508@gmail.com>
Date: Wed Jan 15 08:40:00 2025 +1100
Remove committed secrets, oops
diff --git a/.env.local b/.env.local
deleted file mode 100644
index 516ae74..0000000
--- a/.env.local
+++ /dev/null
@@ -1,2 +0,0 @@
-# local dev secrets, do not commit (oops)
-SECRET_PART=Q1NTQ1RGe3VfZzA=
关键发现:
- 删除了
.env.local文件 - 文件内容:
SECRET_PART=Q1NTQ1RGe3VfZzA= Q1NTQ1RGe3VfZzA=是 Base64 编码
第六步:解码第一半
bash
echo "Q1NTQ1RGe3VfZzA=" | base64 -d
输出:
CSSCTF{u_g0
这是 flag 的前半部分。
第七步:切换到隐藏分支
📌 git checkout 命令详解
bash
git checkout experimental/auth-rework
git checkout 的作用:
- 切换到指定分支
- 把工作目录的文件更新为该分支的状态
本题输出:
branch 'experimental/auth-rework' set up to track 'origin/experimental/auth-rework'.
Switched to a new branch 'experimental/auth-rework'
切换后 ,文件列表多了 auth_notes.md:
bash
find . -type f | sort
输出:
./README.md
./app.py
./auth_notes.md ← 新增文件
./utils.py
第八步:查看 auth_notes.md
bash
cat auth_notes.md
输出:
markdown
# Auth rework notes (WIP, don't merge yet)
Reminder to self --- temp bypass code for local testing only,
remove before merging:
bypass_suffix = "t_130d_508}"
这是 flag 的后半部分。
第九步:拼接两半
第一半 (Base64 解码后):CSSCTF{u_g0
第二半 :t_130d_508}
拼接:
CSSCTF{u_g0t_130d_508}
最终 Flag
CSSCTF{u_g0t_130d_508}
关键 Git 命令总结
1. 克隆仓库
bash
git clone <url>
- 完整复制远程仓库到本地
- 包括所有分支、commit 历史、文件版本
2. 查看 commit 历史
bash
git log --all --oneline --graph
--all:所有分支--oneline:简洁模式--graph:图形显示分支
3. 查看分支
bash
git branch -a
- 显示所有分支(本地 + 远程)
4. 查看某个 commit 的完整内容
bash
git show <commit-hash>
- 显示 commit 的完整 diff
5. 切换到某个分支
bash
git checkout <branch-name>
- 切换分支,更新工作目录
6. 在所有历史中搜索
bash
git log --all -p | grep -i "CTF{"
git log --all -p | grep -i -E "flag|token|key|secret"
-p:显示完整 diffgrep:在 diff 中搜索关键词
7. 查看被删除的文件
bash
git log --all --diff-filter=D --name-only
--diff-filter=D:只显示被删除(Deleted)的文件
这类题目的通常解题思路
🎯 OSINT + Git 历史类题目
核心思想 :flag 藏在公开信息 里,但需要深入挖掘(而不是只看表面)。
常见藏 flag 的位置:
| 位置 | 命令 | 说明 |
|---|---|---|
| 当前分支的文件 | grep -ri "CTF{" . |
最明显,但通常是诱饵 |
| 隐藏分支 | git branch -a + git checkout |
题目说"split in half",一半可能在这里 |
| 被删除的文件 | git show <commit> |
commit message 常提示"remove secrets" |
| commit message | git log --all |
有时 flag 直接写在 message 里 |
| Git stash | git stash list |
被暂存的改动 |
| Git notes | git notes list |
附加的注释 |
| Git reflog | git reflog |
所有 HEAD 移动记录 |
| 二进制 blob | git rev-list --all --objects |
所有对象,包括未被引用的 |
| Gists | https://gist.github.com/<user> |
用户的其他代码片段 |
| 其他平台 | Google/GitLab/Pastebin | 同一用户名的其他痕迹 |
🎯 通用解题流程
- 确认起点:题目给的 handle(用户名)是什么?
- 搜索该 handle:GitHub、GitLab、Twitter、个人网站等
- 克隆仓库 :
git clone所有相关仓库 - 检查所有分支 :
git branch -a找隐藏分支 - 检查所有 commit :
git log --all --oneline找可疑 commit - 检查被删除的文件 :
git show <commit>看删除的内容 - 搜索关键词 :
git log --all -p | grep -i "flag\|CTF\|key\|secret" - 解码:Base64、Hex、ROT13 等
- 拼接:如果是"split in half",把两半拼起来
🎯 本题的关键技巧
- 不要相信第一个发现的东西 :
utils.py、app.py、old_config.txt里的 flag 全是假的 - 检查隐藏分支 :
experimental/auth-rework分支藏着 flag 的一半 - 检查被删除的文件 :commit
99291d3删除了.env.local,里面藏着另一半 - 注意 commit message :
"Remove committed secrets, oops"直接提示了秘密的存在 - Base64 解码 :
Q1NTQ1RGe3VfZzA=→CSSCTF{u_g0
附录:完整命令序列
bash
# 1. 克隆仓库
git clone https://github.com/bobdev508/dashboard-app.git
git clone https://github.com/bobdev508/decoy-project.git
# 2. 检查 commit 历史
cd dashboard-app
git log --all --oneline --graph
# 3. 检查所有分支
git branch -a
# 4. 查看被删除的文件(commit 99291d3)
git show 99291d3
# 5. Base64 解码第一半
echo "Q1NTQ1RGe3VfZzA=" | base64 -d
# 输出: CSSCTF{u_g0
# 6. 切换到隐藏分支
git checkout experimental/auth-rework
# 7. 查看 auth_notes.md
cat auth_notes.md
# 输出: bypass_suffix = "t_130d_508}"
# 8. 拼接两半
# CSSCTF{u_g0 + t_130d_508} = CSSCTF{u_g0t_130d_508}
最终答案
CSSCTF{u_g0t_130d_508}
Rambo
2026年国庆节
🎉🎉🎉