Writeup 4 CSS CTF Semester 2 2026 - Lamp Drill

Writeup 4 CSS CTF Semester 2 2026 - Lamp Drill

题目信息

  • 题目名称:Lamp Drill
  • 分值:15
  • 难度:Beginner
  • 类型:Hardware / Reverse Engineering
  • 题目描述:

Warm-up. No spaces.

Flag Format: CSSCTF{...}

These artists may help (Cost: 5 points)

  1. Offonoff
  2. Logical (Cost: 15 points)
    A black filled lamp is 1. An empty circle is 0.
  • 附件 :lampDrill.svg

解题思路

1. 分析提示

题目给了两个提示:

提示 1(5 分):Offonoff

Offonoff 是一个韩国音乐组合,但在这里它是个双关:

  • Off = 关 = 逻辑 0
  • On = 开 = 逻辑 1
  • "Off on off" = 0 1 0

这暗示我们要关注逻辑电平(0 和 1)。

提示 2(15 分):Logical

A black filled lamp is 1. An empty circle is 0.

这直接告诉我们编码方式:

  • 黑色实心圆 = 1
  • 白色空心圆 = 0

2. 分析 SVG 电路图

打开 lampDrill.svg,可以看到一张逻辑电路图:

顶部:逻辑门真值表

输入 A 输入 B 输出
1 (黑) 1 (黑) 1 (黑)
1 (黑) 0 (白) 0 (白)
0 (白) 1 (黑) 0 (白)
0 (白) 0 (白) 0 (白)

这完全符合 AND 门的真值表:只有两个输入都为 1 时,输出才为 1。

下方:3 行电路

每行有 8 个盒子 ,每个盒子里有 2 个圆(输入),盒子之间用箭头连接。

每个盒子是一个独立的 AND 门。

3. 提取数据

用脚本从 SVG 中提取所有圆形节点的坐标和填充色:

python 复制代码
import re
from collections import defaultdict

with open('lampDrill.svg', 'r') as f:
    content = f.read()

circles = []
pattern = r'<path d="M ([\d.]+) ([\d.]+)\s*C[^"]*"\s*clip-path="[^"]*"\s*style="fill: (#[0-9a-f]+); stroke: #[0-9a-f]+; stroke-width: 1.6'
for m in re.finditer(pattern, content):
    x = float(m.group(1))
    y = float(m.group(2))
    fill = m.group(3)
    val = 1 if fill == '#1c1915' else 0
    circles.append((x, y, val))

rows = defaultdict(list)
for x, y, val in circles:
    rows[round(y)].append((x, val))

for row_key in sorted(rows.keys()):
    if row_key < 200:
        continue
    row = sorted(rows[row_key], key=lambda t: t[0])
    values = [v for x, v in row]
    print(f"y={row_key}: {values}")

输出:

复制代码
y=281: [1, 0, 1, 1, 1, 1, 0, 1, 0, 0, 1, 0, 1, 1, 1, 1]
y=385: [0, 1, 1, 1, 1, 1, 1, 1, 1, 0, 0, 1, 1, 1, 1, 1]
y=489: [0, 0, 1, 1, 1, 1, 1, 1, 1, 0, 0, 1, 1, 1, 1, 1]

4. 计算 AND 输出

每行 16 个输入,每 2 个一组送入 AND 门,得到 8 位输出。

第 1 行(y=281):

输入对 AND 输出
1, 0 0
1, 1 1
1, 1 1
0, 1 0
0, 0 0
1, 0 0
1, 1 1
1, 1 1

输出:0 1 1 0 0 0 1 1 = 01100011 = 0x63 = 'c'

第 2 行(y=385):

输入对 AND 输出
0, 1 0
1, 1 1
1, 1 1
1, 1 1
1, 0 0
0, 1 0
1, 1 1
1, 1 1

输出:0 1 1 1 0 0 1 1 = 01110011 = 0x73 = 's'

第 3 行(y=489):

输入对 AND 输出
0, 0 0
1, 1 1
1, 1 1
1, 1 1
1, 0 0
0, 1 0
1, 1 1
1, 1 1

输出:0 1 1 1 0 0 1 1 = 01110011 = 0x73 = 's'

5. 拼接结果

三行输出对应的 ASCII 字符:

复制代码
c + s + s = css

6. 最终 Flag

复制代码
CSSCTF{css}

解题脚本

python 复制代码
import re
from collections import defaultdict

with open('lampDrill.svg', 'r') as f:
    content = f.read()

circles = []
pattern = r'<path d="M ([\d.]+) ([\d.]+)\s*C[^"]*"\s*clip-path="[^"]*"\s*style="fill: (#[0-9a-f]+); stroke: #[0-9a-f]+; stroke-width: 1.6'
for m in re.finditer(pattern, content):
    x = float(m.group(1))
    y = float(m.group(2))
    fill = m.group(3)
    val = 1 if fill == '#1c1915' else 0
    circles.append((x, y, val))

rows = defaultdict(list)
for x, y, val in circles:
    rows[round(y)].append((x, val))

result = ""
for row_key in sorted(rows.keys()):
    if row_key < 200:
        continue
    row = sorted(rows[row_key], key=lambda t: t[0])
    values = [v for x, v in row]
    outputs = []
    for i in range(0, len(values), 2):
        if i+1 < len(values):
            outputs.append(values[i] & values[i+1])
    if len(outputs) == 8:
        byte = int(''.join(map(str, outputs)), 2)
        result += chr(byte)
        print(f"y={row_key}: {outputs} -> {chr(byte)}")

print(f"Flag: CSSCTF{{{result}}}")

输出:

复制代码
C:\Users\Administrator\AppData\Local\Programs\Python\Python314\python.exe exp.py 
y=281: [0, 1, 1, 0, 0, 0, 1, 1] -> c
y=385: [0, 1, 1, 1, 0, 0, 1, 1] -> s
y=489: [0, 1, 1, 1, 0, 0, 1, 1] -> s
Flag: CSSCTF{css}

进程已结束,退出代码为 0

关键点总结

  1. 编码:黑圆 = 1,白圆 = 0(提示 2)
  2. 逻辑门 :顶部示例确认是 AND 门(只有 1,1 输出 1)
  3. 数据提取:从 SVG 中按 y 坐标分组提取圆形节点
  4. 计算:每行 16 个输入 → 8 个 AND 输出 → 1 字节 ASCII
  5. 结果 :3 行得到 c、s、s → css

最终 Flag:

复制代码
CSSCTF{css}

Rambo

2026年国庆节

🎉🎉🎉

相关推荐
hengdonghui6 小时前
Writeup 4 CSS CTF Semester 2 2026 Cryptography Chrono I
ctf·维吉尼亚密码·crypto
hengdonghui16 小时前
Writeup 4 CSS CTF Semester 2 2026 - Dead Faction Servers
ctf·osint
hengdonghui2 天前
Writeup 4 2020 - 之江杯 - 工控现场的恶意扫描
wireshark·ctf·流量分析
hengdonghui2 天前
Writeup 4 2020 - 之江杯 - 异常的工程文件
ctf·工控
hengdonghui2 天前
Writeup 4 2020 - 之江杯 - 注册表分析
注册表·ctf
kali-Myon13 天前
分享一个网络安全 AI 工具导航项目 SecSkills
安全·ai·github·ctf
蒲公英eric14 天前
从旧接口泄露到 OAuth 保护:DVWA API 模块完整漏洞分析教程
web安全·ai·ctf·dvwa·ai安全·api模块
白猫不黑15 天前
CTF是什么?从零理解一场攻防竞赛
网络·web安全·计算机·网络安全·信息安全·ctf·红蓝对抗
玫幽倩16 天前
2026第二届湾区杯网络安全大赛决赛(AI专项赛道静态题wp)
pytorch·python·ai·agent·ctf·rag·湾区杯