Writeup 4 CSS CTF Semester 2 2026 - Dead Faction Servers

Writeup 4 CSS CTF Semester 2 2026 - Dead Faction Servers

题目信息

  • 题目名称:Dead Faction Servers
  • 分值:10
  • 难度:Beginner
  • 类型:OSINT
  • 题目描述:

The old faction that ran Sector 9 didn't leave one trail --- they left several, and most of them are decoys. Whoever built this infrastructure knew someone would come looking eventually, and buried the real access key across two separate locations, split in half, one piece scrambled beyond plain sight.

Your recon has already surfaced their handle and at least one archived project. Don't trust the first thing you find --- Sector 9's engineers were paranoid, and paranoid engineers plant false leads.

Starting trace: bobdev508

Flag Format: CSSCTF{...}


解题思路概述

这是一道 OSINT + Git 历史分析 题目。核心思路是:

  1. 起点 :bobdev508 是一个 GitHub 用户名。
  2. 目标:flag 被拆成两半,分别藏在两个不同的地方。
  3. 陷阱 :大部分线索是诱饵(decoy),真正的 flag 藏在隐藏分支 和被删除的文件里。
  4. 关键技巧 :
    • 使用 git clone 拉取仓库(比网页更快、更完整)
    • 使用 git log --all 发现隐藏分支
    • 使用 git show <commit> 查看被删除的文件
    • 使用 Base64 解码

详细解题步骤

第一步:确认起点

题目给出的起点是 bobdev508。在 GitHub 上搜索这个用户名:

复制代码
https://github.com/bobdev508

可以看到该用户有 2 个仓库:

仓库名 描述 语言
dashboard-app Internal analytics dashboard. WIP. Python
decoy-project (名字直接叫"诱饵项目") -

注意 :decoy-project 名字就是"诱饵",说明它是干扰项。


第二步:克隆仓库

📌 git clone 命令详解
bash 复制代码
git clone https://github.com/bobdev508/dashboard-app.git
git clone https://github.com/bobdev508/decoy-project.git

git clone 的作用:

  • 把远程仓库完整复制到本地
  • 包括所有分支 、所有 commit 历史 、所有文件版本
  • 比在网页上浏览更完整(网页只显示当前分支的文件,不显示历史)

为什么用 git clone 而不是网页:

  1. 速度更快(尤其是 GitHub 网页加载慢时)
  2. 能看到完整历史(网页只能看到当前状态)
  3. 能用命令行搜索 (git log、grep 等)
  4. 能切换分支(网页切换分支不如命令行方便)

国内加速方案(如果 GitHub 太慢):

bash 复制代码
# 用镜像站
git clone https://ghproxy.com/https://github.com/bobdev508/dashboard-app.git
git clone https://gitclone.com/github.com/bobdev508/dashboard-app.git

第三步:检查仓库的 commit 历史

📌 git log 命令详解
bash 复制代码
cd dashboard-app
git log --all --oneline

git log 的常用参数:

参数 作用
git log 显示当前分支的 commit 历史
git log --all 显示所有分支的 commit 历史(包括远程分支)
git log --oneline 每个 commit 只显示一行(简洁模式)
git log --graph 用 ASCII 图形显示分支合并情况
git log --all --graph --oneline 组合使用,最直观
git log -p 显示每个 commit 的完整 diff(改动内容)
git log --stat 显示每个 commit 改动的文件列表
git log --author="Bob" 按作者过滤
git log --since="2025-01-01" 按时间过滤
git log --diff-filter=D --name-only 显示被删除的文件

本题输出:

复制代码
5b3845b (HEAD -> main, origin/main, origin/HEAD) Add setup instructions to README
b72b7ff (origin/experimental/auth-rework) WIP: auth rework notes
99291d3 Remove committed secrets, oops
be82c69 Add local env file
457762d Add date helper
2421118 Add app entrypoint
56e1984 Initial commit

关键发现:

  1. b72b7ff 在一个叫 origin/experimental/auth-rework 的分支上 ------ 这是一个隐藏分支!
  2. 99291d3 的 commit message 是 "Remove committed secrets, oops" ------ 删除了提交的密码,说明被删除的内容里有秘密!

第四步:检查分支

📌 git branch 命令详解
bash 复制代码
git branch -a

git branch 的常用参数:

参数 作用
git branch 显示本地分支
git branch -a 显示所有分支(本地 + 远程)
git branch -r 只显示远程分支
git branch -v 显示每个分支的最后一个 commit
git branch -vv 显示每个分支的跟踪关系

本题输出:

复制代码
* main
  remotes/origin/HEAD -> origin/main
  remotes/origin/experimental/auth-rework
  remotes/origin/main

关键发现 :有一个隐藏分支 experimental/auth-rework(实验性认证重构)。


第五步:查看被删除的文件

📌 git show 命令详解
bash 复制代码
git show 99291d3

git show 的作用:

  • 显示某个 commit 的完整信息 ,包括:
    • commit hash
    • 作者
    • 日期
    • commit message
    • 完整的 diff(改动内容)

本题输出:

diff 复制代码
commit 99291d3882022272baa82680d6ae72f2074c4ab7
Author: Bob Martinez <bobdev508@gmail.com>
Date:   Wed Jan 15 08:40:00 2025 +1100

    Remove committed secrets, oops

diff --git a/.env.local b/.env.local
deleted file mode 100644
index 516ae74..0000000
--- a/.env.local
+++ /dev/null
@@ -1,2 +0,0 @@
-# local dev secrets, do not commit (oops)
-SECRET_PART=Q1NTQ1RGe3VfZzA=

关键发现:

  • 删除了 .env.local 文件
  • 文件内容:SECRET_PART=Q1NTQ1RGe3VfZzA=
  • Q1NTQ1RGe3VfZzA= 是 Base64 编码

第六步:解码第一半

bash 复制代码
echo "Q1NTQ1RGe3VfZzA=" | base64 -d

输出:

复制代码
CSSCTF{u_g0

这是 flag 的前半部分。


第七步:切换到隐藏分支

📌 git checkout 命令详解
bash 复制代码
git checkout experimental/auth-rework

git checkout 的作用:

  • 切换到指定分支
  • 把工作目录的文件更新为该分支的状态

本题输出:

复制代码
branch 'experimental/auth-rework' set up to track 'origin/experimental/auth-rework'.
Switched to a new branch 'experimental/auth-rework'

切换后 ,文件列表多了 auth_notes.md:

bash 复制代码
find . -type f | sort

输出:

复制代码
./README.md
./app.py
./auth_notes.md    ← 新增文件
./utils.py

第八步:查看 auth_notes.md

bash 复制代码
cat auth_notes.md

输出:

markdown 复制代码
# Auth rework notes (WIP, don't merge yet)

Reminder to self --- temp bypass code for local testing only,
remove before merging:

bypass_suffix = "t_130d_508}"

这是 flag 的后半部分。


第九步:拼接两半

第一半 (Base64 解码后):CSSCTF{u_g0

第二半 :t_130d_508}

拼接:

复制代码
CSSCTF{u_g0t_130d_508}

最终 Flag

复制代码
CSSCTF{u_g0t_130d_508}

关键 Git 命令总结

1. 克隆仓库

bash 复制代码
git clone <url>
  • 完整复制远程仓库到本地
  • 包括所有分支、commit 历史、文件版本

2. 查看 commit 历史

bash 复制代码
git log --all --oneline --graph
  • --all:所有分支
  • --oneline:简洁模式
  • --graph:图形显示分支

3. 查看分支

bash 复制代码
git branch -a
  • 显示所有分支(本地 + 远程)

4. 查看某个 commit 的完整内容

bash 复制代码
git show <commit-hash>
  • 显示 commit 的完整 diff

5. 切换到某个分支

bash 复制代码
git checkout <branch-name>
  • 切换分支,更新工作目录

6. 在所有历史中搜索

bash 复制代码
git log --all -p | grep -i "CTF{"
git log --all -p | grep -i -E "flag|token|key|secret"
  • -p:显示完整 diff
  • grep:在 diff 中搜索关键词

7. 查看被删除的文件

bash 复制代码
git log --all --diff-filter=D --name-only
  • --diff-filter=D:只显示被删除(Deleted)的文件

这类题目的通常解题思路

🎯 OSINT + Git 历史类题目

核心思想 :flag 藏在公开信息 里,但需要深入挖掘(而不是只看表面)。

常见藏 flag 的位置:

位置 命令 说明
当前分支的文件 grep -ri "CTF{" . 最明显,但通常是诱饵
隐藏分支 git branch -a + git checkout 题目说"split in half",一半可能在这里
被删除的文件 git show <commit> commit message 常提示"remove secrets"
commit message git log --all 有时 flag 直接写在 message 里
Git stash git stash list 被暂存的改动
Git notes git notes list 附加的注释
Git reflog git reflog 所有 HEAD 移动记录
二进制 blob git rev-list --all --objects 所有对象,包括未被引用的
Gists https://gist.github.com/<user> 用户的其他代码片段
其他平台 Google/GitLab/Pastebin 同一用户名的其他痕迹

🎯 通用解题流程

  1. 确认起点:题目给的 handle(用户名)是什么?
  2. 搜索该 handle:GitHub、GitLab、Twitter、个人网站等
  3. 克隆仓库 :git clone 所有相关仓库
  4. 检查所有分支 :git branch -a 找隐藏分支
  5. 检查所有 commit :git log --all --oneline 找可疑 commit
  6. 检查被删除的文件 :git show <commit> 看删除的内容
  7. 搜索关键词 :git log --all -p | grep -i "flag\|CTF\|key\|secret"
  8. 解码:Base64、Hex、ROT13 等
  9. 拼接:如果是"split in half",把两半拼起来

🎯 本题的关键技巧

  1. 不要相信第一个发现的东西 :utils.py、app.py、old_config.txt 里的 flag 全是假的
  2. 检查隐藏分支 :experimental/auth-rework 分支藏着 flag 的一半
  3. 检查被删除的文件 :commit 99291d3 删除了 .env.local,里面藏着另一半
  4. 注意 commit message :"Remove committed secrets, oops" 直接提示了秘密的存在
  5. Base64 解码 :Q1NTQ1RGe3VfZzA= → CSSCTF{u_g0

附录:完整命令序列

bash 复制代码
# 1. 克隆仓库
git clone https://github.com/bobdev508/dashboard-app.git
git clone https://github.com/bobdev508/decoy-project.git

# 2. 检查 commit 历史
cd dashboard-app
git log --all --oneline --graph

# 3. 检查所有分支
git branch -a

# 4. 查看被删除的文件(commit 99291d3)
git show 99291d3

# 5. Base64 解码第一半
echo "Q1NTQ1RGe3VfZzA=" | base64 -d
# 输出: CSSCTF{u_g0

# 6. 切换到隐藏分支
git checkout experimental/auth-rework

# 7. 查看 auth_notes.md
cat auth_notes.md
# 输出: bypass_suffix = "t_130d_508}"

# 8. 拼接两半
# CSSCTF{u_g0 + t_130d_508} = CSSCTF{u_g0t_130d_508}

最终答案

复制代码
CSSCTF{u_g0t_130d_508}

Rambo

2026年国庆节

🎉🎉🎉

相关推荐
hengdonghui1 天前
Writeup 4 2020 - 之江杯 - 工控现场的恶意扫描
wireshark·ctf·流量分析
hengdonghui2 天前
Writeup 4 2020 - 之江杯 - 异常的工程文件
ctf·工控
hengdonghui2 天前
Writeup 4 2020 - 之江杯 - 注册表分析
注册表·ctf
kali-Myon12 天前
分享一个网络安全 AI 工具导航项目 SecSkills
安全·ai·github·ctf
蒲公英eric13 天前
从旧接口泄露到 OAuth 保护:DVWA API 模块完整漏洞分析教程
web安全·ai·ctf·dvwa·ai安全·api模块
白猫不黑14 天前
CTF是什么?从零理解一场攻防竞赛
网络·web安全·计算机·网络安全·信息安全·ctf·红蓝对抗
玫幽倩15 天前
2026第二届湾区杯网络安全大赛决赛(AI专项赛道静态题wp)
pytorch·python·ai·agent·ctf·rag·湾区杯
落寞的魚丶17 天前
2026年浙江省信息通信业职业技能竞赛(信息安全测试员竞赛) 初赛Wireup
ctf·鱼影安全·2026网络安全通信行业·信息安全测试员竞赛·通信职业技能大赛
合天网安实验室22 天前
Modbus协议及其取证的学习笔记
ctf·modbus·通信协议·取证