<!DOCTYPE html>
<html lang="">

<head>
    <meta charset="utf-8">
    <meta name="viewport" content="width=device-width,initial-scale=1">    <meta name="renderer" content="webkit"/>
    <meta name="force-rendering" content="webkit"/>
    <meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1"/>
    <meta name="format-detection" content="telephone=no"/>
            <link rel="shortcut icon" type="image/x-icon" href="/uploads/2023/07/5b969fa44d65fe71a1f97c7e9e8c6395.png" />	
            <title>内存取证-Otter CTF（ 取证专项赛） - 北京卓识网安技术股份有限公司</title>        <script id="_CONFIG_">
        window["_CONFIG_"]={"theme":"#E95A30","centerWidth":"1400px","paths":{"static":"\/dist\/"},"sidebar":"no-sidebar","staticVer":"1773309051236-9930","syncload":[],"asyncload":["theme\/static\/lib\/aos\/aos","theme\/static\/js\/register"],"dev":0,"responsive":1,"contextmenu":1,"selectstart":1,"lazyload":1,"current":{"module":"post","type":"post","id":221},"views":"no","show_footer":"no","footer_style":"","footer_slot_style":"","Small_screen":"1180px","login_url":"https:\/\/www.enst.org.cn\/account\/login","agent":"15dfysa4dzzyix"}    </script>
    <link rel="stylesheet" href="/dist/theme/static/css/core.css?ver=1773309051236-9930">
    <link rel="stylesheet" href="/dist/theme/static/css/main.css?ver=1773309051236-9930">
        <link rel="stylesheet" href="/dist/theme/static/css/main.media.css?ver=1773309051236-9930">
        <script src="/dist/theme/static/js/core.js?ver=1773309051236-9930"></script>
    <script src="/dist/theme/static/js/main.js?ver=1773309051236-9930"></script>
    <link rel="stylesheet" class="reload-css" href="/dist/visual/sites/1/style.cssx?lang=&ver=1773309051236-9930">
    <link rel='dns-prefetch' href='//www.enst.org.cn' />
<link rel='canonical' href='https://www.enst.org.cn/221.html' />


    <style class="custom-css-code">
        </style>
</head>
<body class="layout-full-width no-sidebar header-type-immersion header-type-mobile-default responsive">
<div class="App loading">
    <div class="Page ">

        <div class="Page-header">
            <div class="Page-header--main default">
    
<div class="Page-header--main__in container">
    <div class="Page-header--default">
        <div class="Page-header--logo">
<h1>
    <a href="/">
        <img class="all-logo" src="/uploads/2023/09/ed3d09c4c80a2d66b7f125a93175eae9.png" alt="logo">
        <img class="mobile-logo" src="/uploads/2023/09/5c1449e456337eea77bba818371c0612.png" alt="logo-mobile">
    </a>
</h1></div><div class="Page-header--menu"><div class="cc-element--wrapper menu-69b3f8de93264--wrapper" >
<style style-id="menu-69b3f8de93264">
[node-id="menu-69b3f8de93264"].cc-menu.cc-menu--vertical  .cc-menu--nav  .cc-menu--item{box-sizing:border-box;} 
[node-id="menu-69b3f8de93264"].cc-menu--style__line .line_box{background:rgba(255, 255, 255, 0);} 
[node-id="menu-69b3f8de93264"].cc-menu--style__line .cc-menu--item.current > .line_box{width:100%;} 
[node-id="menu-69b3f8de93264"] li.menu{color:#000000;} 
[node-id="menu-69b3f8de93264"] .icon-active{color:#3c3c3c!important;} 
[node-id="menu-69b3f8de93264"] .item-icon-active{color:#3c3c3c!important;} 
[node-id="menu-69b3f8de93264"] .cc-menu--item  a{font-size:16px;} 
[node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--nav > .cc-menu--item a{font-size:15px;} 
[node-id="menu-69b3f8de93264"].cc-menu--horizontal{text-align:right;} 
[node-id="menu-69b3f8de93264"].cc-menu--horizontal > .cc-menu--nav > .cc-menu--item{height:80px;line-height:80px;padding:0 16px;margin:0 0;} 
[node-id="menu-69b3f8de93264"].cc-menu--vertical > .cc-menu--nav > .cc-menu--item{margin:0 0;} 
[node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item .cc-menu--item__link{height:43px;line-height:43px;margin:0 0;} 
[node-id="menu-69b3f8de93264"].cc-menu--vertical .cc-menu--item{line-height:80px;} 
[node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item,
                    [node-id="menu-69b3f8de93264"].cc-menu--style__line > .cc-menu--nav >.cc-menu--item{background-color:rgba(255, 255, 255, 0);} 
[node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item.block,
                    [node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item.current,
                    [node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item:hover{background-color:rgba(255, 255, 255, 0);} 
[node-id="menu-69b3f8de93264"]{font-size:16px;} 
[node-id="menu-69b3f8de93264"].cc-menu--style__line .cc-menu--item.block,
                    [node-id="menu-69b3f8de93264"].cc-menu--style__line .cc-menu--item.current,
                    [node-id="menu-69b3f8de93264"].cc-menu--style__line .cc-menu--item:hover{border-bottom-color:rgba(255, 255, 255, 0);} 
[node-id="menu-69b3f8de93264"] .cc-menu--item__link{color:#333333;} 
[node-id="menu-69b3f8de93264"] .cc-menu--item.block > .cc-menu--item__link,
                    [node-id="menu-69b3f8de93264"] .cc-menu--item.current > .cc-menu--item__link,
                    [node-id="menu-69b3f8de93264"] .cc-menu--item:hover > .cc-menu--item__link{color:var(--theme-color);} 
[node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item{background-color:rgba(255, 255, 255, 1);} 
[node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item.block,
    [node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item.current,
    [node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item:hover,
    [node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item .cc-menu--item.block,
    [node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item .cc-menu--item.current,
    [node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item .cc-menu--item:hover,
    [node-id="menu-69b3f8de93264"].cc-menu--line-main .cc-menu--item .cc-menu--item.block,
    [node-id="menu-69b3f8de93264"].cc-menu--line-main .cc-menu--item .cc-menu--item.current,
    [node-id="menu-69b3f8de93264"].cc-menu--line-main .cc-menu--item .cc-menu--item:hover{background-color:rgba(233, 90, 48, 1);} 
[node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item .cc-menu--item__link{color:#333333;text-align:left;} 
[node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item.current > .cc-menu--item__link{color:#FFFFFF;text-align:left;} 
[node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item .cc-menu--item.block > .cc-menu--item__link,
                [node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item .cc-menu--item.current > .cc-menu--item__link,
                [node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item .cc-menu--item:hover > .cc-menu--item__link,
                [node-id="menu-69b3f8de93264"].cc-menu--line-main .cc-menu--item .cc-menu--item.block > .cc-menu--item__link,
                [node-id="menu-69b3f8de93264"].cc-menu--line-main .cc-menu--item .cc-menu--item.current > .cc-menu--item__link,
                [node-id="menu-69b3f8de93264"].cc-menu--line-main .cc-menu--item .cc-menu--item:hover > .cc-menu--item__link{color:#FFFFFF;} 
[node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item__link{justify-content:flex-start;text-align:left;} 
[node-id="menu-69b3f8de93264"].cc-menu--auto > .cc-menu--nav{font-size:16px;} 
[node-id="menu-69b3f8de93264"].cc-menu--style__line .cc-menu--nav .cc-menu--item .cc-menu--item:hover > .cc-menu--item__link{color:#FFFFFF;} 
[node-id="menu-69b3f8de93264"].cc-menu.cc-menu--auto__mini .item-icon-active{color:#3c3c3c!important;} 
@media screen and (min-width: 1180px){[node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item .cc-menu--item__link,
                    [node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item.current .cc-menu--item__link{text-align:center;} 
} 
@media only screen and (max-width:1180px){[node-id="menu-69b3f8de93264"].cc-menu--auto .cc-menu--expand__header{display:block;} 
[node-id="menu-69b3f8de93264"].cc-menu--auto > .cc-menu--nav{display: none;
        opacity: 0;
        /*position: fixed;*/
        position: relative;
        z-index: 25;
        width: 100%;
        left: 0;
        top: 50px;
        height: calc(100% - 50px);
        padding: 0 10px;
        box-sizing: border-box;
        overflow: hidden;
        overflow-y: auto;} 
} 
@media only screen and (max-width: 1180px){[node-id="menu-69b3f8de93264"] .cc-menu--item a{font-size:16px;} 
[node-id="menu-69b3f8de93264"]  .cc-menu--item .cc-menu--nav > .cc-menu--item a{font-size:16px;} 
[node-id="menu-69b3f8de93264"].cc-menu--horizontal > .cc-menu--nav > .cc-menu--item{height:60px;line-height:60px;padding:0 20px;} 
[node-id="menu-69b3f8de93264"].cc-menu--vertical > .cc-menu--nav > .cc-menu--item{margin:20px 0;} 
[node-id="menu-69b3f8de93264"].cc-menu--vertical .cc-menu--item{line-height:60px;} 
[node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item{background-color:#fff;} 
[node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item.block,
                    [node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item.current,
                    [node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item:hover{background-color:#fff;} 
[node-id="menu-69b3f8de93264"].cc-menu--style__line .cc-menu--item.block,
                    [node-id="menu-69b3f8de93264"].cc-menu--style__line .cc-menu--item.current,
                    [node-id="menu-69b3f8de93264"].cc-menu--style__line .cc-menu--item:hover{border-bottom-color:#fff;} 
[node-id="menu-69b3f8de93264"] .cc-menu--item__link{color:#3c3c3c;} 
[node-id="menu-69b3f8de93264"] .cc-menu--item.block > .cc-menu--item__link,
    [node-id="menu-69b3f8de93264"] .cc-menu--item.current > .cc-menu--item__link,
    [node-id="menu-69b3f8de93264"] .cc-menu--item:hover > .cc-menu--item__link{color:#00b5ae;} 
[node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item{background-color:#00b5ae;} 
[node-id="menu-69b3f8de93264"] .cc-menu--item.block > .cc-menu--item__link,
                    [node-id="menu-69b3f8de93264"] .cc-menu--item.current > .cc-menu--item__link,
                    [node-id="menu-69b3f8de93264"] .cc-menu--item:hover > .cc-menu--item__link{color:#00b5ae;} 
[node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item{background-color:#00b5ae;} 
[node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item.block,
                    [node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item.current,
                    [node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item:hover,
                    [node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item .cc-menu--item.block,
                    [node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item .cc-menu--item.current,
                    [node-id="menu-69b3f8de93264"].cc-menu--style__default .cc-menu--item .cc-menu--item:hover,
                    [node-id="menu-69b3f8de93264"].cc-menu--line-main .cc-menu--item .cc-menu--item.block,
                    [node-id="menu-69b3f8de93264"].cc-menu--line-main .cc-menu--item .cc-menu--item.current,
                    [node-id="menu-69b3f8de93264"].cc-menu--line-main .cc-menu--item .cc-menu--item:hover{background-color:#009892;} 
[node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item .cc-menu--item__link{color:#fff;} 
[node-id="menu-69b3f8de93264"] .cc-menu--trigger i{color:#000000;} 
[node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item.block > .cc-menu--item__link,
                    [node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item.current > .cc-menu--item__link,
                    [node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item:hover > .cc-menu--item__link{color:#fff;} 
[node-id="menu-69b3f8de93264"].cc-menu.cc-menu--auto__mini .cc-menu--trigger i{color:#000000;} 
[node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item .cc-menu--item__link{height:43px;line-height:43px;margin:0 0;} 
} 
@media only screen and (min-width: 1180px){[node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item .cc-menu--item__link > a{width:100%;} 
[node-id="menu-69b3f8de93264"] .cc-menu--item .cc-menu--item .cc-menu--item__link > a{width:100%;} 
}
</style>
<div node-id="menu-69b3f8de93264" node-type="menu" class="cc-menu cc-menu--style__default cc-menu--horizontal cc-menu--sub-cen cc-menu--line-main" >
            <ul class="cc-menu--nav">
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn" >
                            <span class="cc-menu--item__title">
                                首页
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/%e5%85%ac%e5%8f%b8%e7%ae%80%e4%bb%8b" >
                            <span class="cc-menu--item__title">
                                关于我们
                            </span>
                            
                        </a>
                <i class="fas fa-caret-down down-icon"></i>
            </div>
            <ul class="cc-menu--nav">
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/%e5%85%ac%e5%8f%b8%e7%ae%80%e4%bb%8b" >
                            <span class="cc-menu--item__title">
                                公司简介
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/%e5%8f%91%e5%b1%95%e5%8e%86%e7%a8%8b" >
                            <span class="cc-menu--item__title">
                                发展历程
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/%e4%bc%81%e4%b8%9a%e6%96%87%e5%8c%96" >
                            <span class="cc-menu--item__title">
                                企业文化
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/%e8%8d%a3%e8%aa%89%e8%b5%84%e8%b4%a8" >
                            <span class="cc-menu--item__title">
                                荣誉资质
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    </ul>
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%ae%89%e5%85%a8%e6%9c%8d%e5%8a%a1/%e5%ae%89%e5%85%a8%e8%af%84%e6%b5%8b" >
                            <span class="cc-menu--item__title">
                                安全服务
                            </span>
                            
                        </a>
                <i class="fas fa-caret-down down-icon"></i>
            </div>
            <ul class="cc-menu--nav">
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%ae%89%e5%85%a8%e6%9c%8d%e5%8a%a1/%e5%ae%89%e5%85%a8%e8%af%84%e6%b5%8b" >
                            <span class="cc-menu--item__title">
                                安全评测
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%ae%89%e5%85%a8%e6%9c%8d%e5%8a%a1/%e5%ae%89%e5%85%a8%e6%a3%80%e6%b5%8b" >
                            <span class="cc-menu--item__title">
                                安全检测
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%ae%89%e5%85%a8%e6%9c%8d%e5%8a%a1/%e5%ae%89%e5%85%a8%e7%ae%a1%e5%ae%b6" >
                            <span class="cc-menu--item__title">
                                安全管家
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%ae%89%e5%85%a8%e6%9c%8d%e5%8a%a1/%e5%ae%89%e5%85%a8%e8%ae%be%e8%ae%a1" >
                            <span class="cc-menu--item__title">
                                安全设计
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%ae%89%e5%85%a8%e6%9c%8d%e5%8a%a1/%e5%ae%89%e5%85%a8%e5%92%a8%e8%af%a2" >
                            <span class="cc-menu--item__title">
                                安全咨询
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%ae%89%e5%85%a8%e6%9c%8d%e5%8a%a1/%e5%ae%89%e5%85%a8%e6%95%99%e8%82%b2" >
                            <span class="cc-menu--item__title">
                                安全教育
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    </ul>
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/%e6%8a%80%e6%9c%af%e5%ae%9e%e5%8a%9b" >
                            <span class="cc-menu--item__title">
                                技术实力
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%85%9a%e5%bb%ba%e5%9b%ad%e5%9c%b0" >
                            <span class="cc-menu--item__title">
                                党建园地
                            </span>
                            
                        </a>
                <i class="fas fa-caret-down down-icon"></i>
            </div>
            <ul class="cc-menu--nav">
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%85%9a%e5%bb%ba%e5%9b%ad%e5%9c%b0/%e5%85%9a%e5%bb%ba%e6%96%b0%e9%97%bb" >
                            <span class="cc-menu--item__title">
                                党建新闻
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%85%9a%e5%bb%ba%e5%9b%ad%e5%9c%b0/%e5%ad%a6%e4%b9%a0%e5%9b%ad%e5%9c%b0" >
                            <span class="cc-menu--item__title">
                                学习园地
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    </ul>
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e6%96%b0%e9%97%bb%e4%b8%ad%e5%bf%83/%e8%a1%8c%e4%b8%9a%e6%96%b0%e9%97%bb" >
                            <span class="cc-menu--item__title">
                                新闻中心
                            </span>
                            
                        </a>
                <i class="fas fa-caret-down down-icon"></i>
            </div>
            <ul class="cc-menu--nav">
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e6%96%b0%e9%97%bb%e4%b8%ad%e5%bf%83/%e8%a1%8c%e4%b8%9a%e6%96%b0%e9%97%bb" >
                            <span class="cc-menu--item__title">
                                行业新闻
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e6%96%b0%e9%97%bb%e4%b8%ad%e5%bf%83/%e5%85%ac%e5%8f%b8%e5%8a%a8%e6%80%81" >
                            <span class="cc-menu--item__title">
                                公司动态
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    </ul>
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/%e6%94%bf%e7%ad%96%e6%b3%95%e8%a7%84" >
                            <span class="cc-menu--item__title">
                                政策法规
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/%e8%81%94%e7%b3%bb%e6%88%91%e4%bb%ac" >
                            <span class="cc-menu--item__title">
                                联系我们
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e6%8b%9b%e8%b4%a4%e7%ba%b3%e5%a3%ab" >
                            <span class="cc-menu--item__title">
                                招贤纳士
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    </ul></div>

<script>(function() {
    useComponent('menu').default({"id":"menu-69b3f8de93264","options":{"hover_show":"no","show_cur_sub":"no","retain_hover":"none","line-style-obj":"main_menu","line-style":"left","mode":"horizontal","style":"default","menu-item-repulsion":"no"}})
})()</script></div></div>
        <div class="Page-header--widgets">
            
<div class="Page-header--search search-style-icon2"><div tabindex="-1" class="search-wrapper">
    
    
            <div class="search-icon2">
            <i style="color:#333333" class="fas fa-search"></i>
        </div>
        <form action="https://www.enst.org.cn" target="_blank">
            <div class="search-input-text">
                <input class="cc-form--input2" type="text" name="search" placeholder="搜索">
                <button class="cc-icon">
                    <i style="color:#000000" class="fa fa-search"></i> 
                </button>
            </div>
        </form>
    
</div>
</div>        </div>

        <div class="Page-slot--template-header_in" template_type="global" template_position="template-header_in" template_id="2"><div node-id="id-70-iluql29gls" node-type="row" class="cc-row cc-slot--wrapper cc-row--flex cc-row--justify__start cc-row--align__top cc-row--width__default"><script>(function() {
    useComponent('row').default({"id":"id-70-iluql29gls","options":{"full-width":"default","adaption-height":"no","background-video":"","noheader-full-height":"no","auto-flex":[],"auto-flex-enable":"no"}})
})()</script><div node-id="id-52-r54sxtxxs5" node-type="column" class="cc-col cc-slot--wrapper cc-col--align__top cc-col--justify__start cc-col-24 cc-col-xl-24 cc-col-lg3-24 cc-col-lg2-24 cc-col-lg-24 cc-col-md-24 cc-col-sm-24 cc-col-xs-24"><script>(function() {
    useComponent('column').default({"id":"id-52-r54sxtxxs5","options":[]})
})()</script><div class="cc-element--wrapper id-78-xdjz6840h0--wrapper" >
<style style-id="id-78-xdjz6840h0">
[node-id="id-78-xdjz6840h0"]{border-right-width:1px;border-right-color:rgba(229, 229, 229, 1);border-style:solid;} 
[node-id="id-78-xdjz6840h0"] .cc-textblock__body{padding: 0px;}
</style>
<div node-id="id-78-xdjz6840h0" node-type="textblock" class="cc-textblock" >
    <div class="cc-textblock__body richtext">
        <p style="line-height: 1;">&nbsp;&nbsp;</p>    </div>
</div>

<script>(function() {
    useComponent('textblock').default({"id":"id-78-xdjz6840h0","options":[]})
})()</script></div></div></div></div>    </div>
</div>
</div>
<div class="Page-header--main__placeholder"></div>


<div class="Page-header--mobile default">
            
<div class="Page-header--right-drawer">
    
    <div class="Page-header--icons Page-header--menu">
        <ul>
            <li class="menu">
                <i class="fas fa-align-justify"></i>
            </li>

                    </ul>
    </div>

    <div class="Page-header--logo">
<h1>
    <a href="/">
        <img class="all-logo" src="/uploads/2023/09/ed3d09c4c80a2d66b7f125a93175eae9.png" alt="logo">
        <img class="mobile-logo" src="/uploads/2023/09/5c1449e456337eea77bba818371c0612.png" alt="logo-mobile">
    </a>
</h1></div>
</div>

<div class="Page-header--shade shade-main">

    <div class="Page-header--shade__menu">
        <div class="cc-element--wrapper menu-69b3f8deb02de--wrapper" >
<style style-id="menu-69b3f8deb02de">
[node-id="menu-69b3f8deb02de"].cc-menu.cc-menu--vertical  .cc-menu--nav  .cc-menu--item{box-sizing:border-box;} 
[node-id="menu-69b3f8deb02de"].cc-menu--style__line .line_box{background:rgba(255, 255, 255, 0);} 
[node-id="menu-69b3f8deb02de"].cc-menu--style__line .cc-menu--item.current > .line_box{width:100%;} 
[node-id="menu-69b3f8deb02de"] li.menu{color:#000000;} 
[node-id="menu-69b3f8deb02de"] .icon-active{color:#3c3c3c!important;} 
[node-id="menu-69b3f8deb02de"] .item-icon-active{color:#3c3c3c!important;} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item  a{font-size:16px;} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--nav > .cc-menu--item a{font-size:15px;} 
[node-id="menu-69b3f8deb02de"].cc-menu--horizontal{text-align:right;} 
[node-id="menu-69b3f8deb02de"].cc-menu--horizontal > .cc-menu--nav > .cc-menu--item{height:80px;line-height:80px;padding:0 16px;margin:0 0;} 
[node-id="menu-69b3f8deb02de"].cc-menu--vertical > .cc-menu--nav > .cc-menu--item{margin:0 0;} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item .cc-menu--item__link{height:43px;line-height:43px;margin:0 0;} 
[node-id="menu-69b3f8deb02de"].cc-menu--vertical .cc-menu--item{line-height:80px;} 
[node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item,
                    [node-id="menu-69b3f8deb02de"].cc-menu--style__line > .cc-menu--nav >.cc-menu--item{background-color:rgba(255, 255, 255, 0);} 
[node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item.block,
                    [node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item.current,
                    [node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item:hover{background-color:rgba(255, 255, 255, 0);} 
[node-id="menu-69b3f8deb02de"]{font-size:16px;} 
[node-id="menu-69b3f8deb02de"].cc-menu--style__line .cc-menu--item.block,
                    [node-id="menu-69b3f8deb02de"].cc-menu--style__line .cc-menu--item.current,
                    [node-id="menu-69b3f8deb02de"].cc-menu--style__line .cc-menu--item:hover{border-bottom-color:rgba(255, 255, 255, 0);} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item__link{color:#333333;} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item.block > .cc-menu--item__link,
                    [node-id="menu-69b3f8deb02de"] .cc-menu--item.current > .cc-menu--item__link,
                    [node-id="menu-69b3f8deb02de"] .cc-menu--item:hover > .cc-menu--item__link{color:var(--theme-color);} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item{background-color:rgba(255, 255, 255, 1);} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item.block,
    [node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item.current,
    [node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item:hover,
    [node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item .cc-menu--item.block,
    [node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item .cc-menu--item.current,
    [node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item .cc-menu--item:hover,
    [node-id="menu-69b3f8deb02de"].cc-menu--line-main .cc-menu--item .cc-menu--item.block,
    [node-id="menu-69b3f8deb02de"].cc-menu--line-main .cc-menu--item .cc-menu--item.current,
    [node-id="menu-69b3f8deb02de"].cc-menu--line-main .cc-menu--item .cc-menu--item:hover{background-color:rgba(233, 90, 48, 1);} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item .cc-menu--item__link{color:#333333;text-align:left;} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item.current > .cc-menu--item__link{color:#FFFFFF;text-align:left;} 
[node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item .cc-menu--item.block > .cc-menu--item__link,
                [node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item .cc-menu--item.current > .cc-menu--item__link,
                [node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item .cc-menu--item:hover > .cc-menu--item__link,
                [node-id="menu-69b3f8deb02de"].cc-menu--line-main .cc-menu--item .cc-menu--item.block > .cc-menu--item__link,
                [node-id="menu-69b3f8deb02de"].cc-menu--line-main .cc-menu--item .cc-menu--item.current > .cc-menu--item__link,
                [node-id="menu-69b3f8deb02de"].cc-menu--line-main .cc-menu--item .cc-menu--item:hover > .cc-menu--item__link{color:#FFFFFF;} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item__link{justify-content:flex-start;text-align:left;} 
[node-id="menu-69b3f8deb02de"].cc-menu--auto > .cc-menu--nav{font-size:16px;} 
[node-id="menu-69b3f8deb02de"].cc-menu--style__line .cc-menu--nav .cc-menu--item .cc-menu--item:hover > .cc-menu--item__link{color:#FFFFFF;} 
[node-id="menu-69b3f8deb02de"].cc-menu.cc-menu--auto__mini .item-icon-active{color:#3c3c3c!important;} 
@media screen and (min-width: 1180px){[node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item .cc-menu--item__link,
                    [node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item.current .cc-menu--item__link{text-align:center;} 
} 
@media only screen and (max-width:1180px){[node-id="menu-69b3f8deb02de"].cc-menu--auto .cc-menu--expand__header{display:block;} 
[node-id="menu-69b3f8deb02de"].cc-menu--auto > .cc-menu--nav{display: none;
        opacity: 0;
        /*position: fixed;*/
        position: relative;
        z-index: 25;
        width: 100%;
        left: 0;
        top: 50px;
        height: calc(100% - 50px);
        padding: 0 10px;
        box-sizing: border-box;
        overflow: hidden;
        overflow-y: auto;} 
} 
@media only screen and (max-width: 1180px){[node-id="menu-69b3f8deb02de"] .cc-menu--item a{font-size:16px;} 
[node-id="menu-69b3f8deb02de"]  .cc-menu--item .cc-menu--nav > .cc-menu--item a{font-size:15px;} 
[node-id="menu-69b3f8deb02de"].cc-menu--horizontal > .cc-menu--nav > .cc-menu--item{height:42px;line-height:42px;padding:0 1px;} 
[node-id="menu-69b3f8deb02de"].cc-menu--vertical > .cc-menu--nav > .cc-menu--item{margin:1px 0;} 
[node-id="menu-69b3f8deb02de"].cc-menu--vertical .cc-menu--item{line-height:42px;} 
[node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item{background-color:rgba(255, 255, 255, 0);} 
[node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item.block,
                    [node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item.current,
                    [node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item:hover{background-color:rgba(233, 90, 48, 1);} 
[node-id="menu-69b3f8deb02de"].cc-menu--style__line .cc-menu--item.block,
                    [node-id="menu-69b3f8deb02de"].cc-menu--style__line .cc-menu--item.current,
                    [node-id="menu-69b3f8deb02de"].cc-menu--style__line .cc-menu--item:hover{border-bottom-color:rgba(233, 90, 48, 1);} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item__link{color:#FFFFFF;} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item.block > .cc-menu--item__link,
    [node-id="menu-69b3f8deb02de"] .cc-menu--item.current > .cc-menu--item__link,
    [node-id="menu-69b3f8deb02de"] .cc-menu--item:hover > .cc-menu--item__link{color:#FFFFFF;} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item{background-color:rgba(247, 113, 74, 1);} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item.block > .cc-menu--item__link,
                    [node-id="menu-69b3f8deb02de"] .cc-menu--item.current > .cc-menu--item__link,
                    [node-id="menu-69b3f8deb02de"] .cc-menu--item:hover > .cc-menu--item__link{color:#FFFFFF;} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item{background-color:rgba(247, 113, 74, 1);} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item.block,
                    [node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item.current,
                    [node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item:hover,
                    [node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item .cc-menu--item.block,
                    [node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item .cc-menu--item.current,
                    [node-id="menu-69b3f8deb02de"].cc-menu--style__default .cc-menu--item .cc-menu--item:hover,
                    [node-id="menu-69b3f8deb02de"].cc-menu--line-main .cc-menu--item .cc-menu--item.block,
                    [node-id="menu-69b3f8deb02de"].cc-menu--line-main .cc-menu--item .cc-menu--item.current,
                    [node-id="menu-69b3f8deb02de"].cc-menu--line-main .cc-menu--item .cc-menu--item:hover{background-color:rgba(247, 113, 74, 1);} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item .cc-menu--item__link{color:#fff;} 
[node-id="menu-69b3f8deb02de"] .cc-menu--trigger i{color:#000000;} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item.block > .cc-menu--item__link,
                    [node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item.current > .cc-menu--item__link,
                    [node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item:hover > .cc-menu--item__link{color:#fff;} 
[node-id="menu-69b3f8deb02de"].cc-menu.cc-menu--auto__mini .cc-menu--trigger i{color:#000000;} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item .cc-menu--item__link{height:43px;line-height:43px;margin:0 0;} 
} 
@media only screen and (min-width: 1180px){[node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item .cc-menu--item__link > a{width:100%;} 
[node-id="menu-69b3f8deb02de"] .cc-menu--item .cc-menu--item .cc-menu--item__link > a{width:100%;} 
}
</style>
<div node-id="menu-69b3f8deb02de" node-type="menu" class="cc-menu cc-menu--style__default cc-menu--vertical cc-menu--arrow-icon cc-menu--sub-cen" >
            <ul class="cc-menu--nav">
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn" >
                            <span class="cc-menu--item__title">
                                首页
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/%e5%85%ac%e5%8f%b8%e7%ae%80%e4%bb%8b" >
                            <span class="cc-menu--item__title">
                                关于我们
                            </span>
                            
                        </a>
                <i class="fas fa-caret-down down-icon"></i>
            </div>
            <ul class="cc-menu--nav">
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/%e5%85%ac%e5%8f%b8%e7%ae%80%e4%bb%8b" >
                            <span class="cc-menu--item__title">
                                公司简介
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/%e5%8f%91%e5%b1%95%e5%8e%86%e7%a8%8b" >
                            <span class="cc-menu--item__title">
                                发展历程
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/%e4%bc%81%e4%b8%9a%e6%96%87%e5%8c%96" >
                            <span class="cc-menu--item__title">
                                企业文化
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/%e8%8d%a3%e8%aa%89%e8%b5%84%e8%b4%a8" >
                            <span class="cc-menu--item__title">
                                荣誉资质
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    </ul>
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%ae%89%e5%85%a8%e6%9c%8d%e5%8a%a1/%e5%ae%89%e5%85%a8%e8%af%84%e6%b5%8b" >
                            <span class="cc-menu--item__title">
                                安全服务
                            </span>
                            
                        </a>
                <i class="fas fa-caret-down down-icon"></i>
            </div>
            <ul class="cc-menu--nav">
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%ae%89%e5%85%a8%e6%9c%8d%e5%8a%a1/%e5%ae%89%e5%85%a8%e8%af%84%e6%b5%8b" >
                            <span class="cc-menu--item__title">
                                安全评测
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%ae%89%e5%85%a8%e6%9c%8d%e5%8a%a1/%e5%ae%89%e5%85%a8%e6%a3%80%e6%b5%8b" >
                            <span class="cc-menu--item__title">
                                安全检测
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%ae%89%e5%85%a8%e6%9c%8d%e5%8a%a1/%e5%ae%89%e5%85%a8%e7%ae%a1%e5%ae%b6" >
                            <span class="cc-menu--item__title">
                                安全管家
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%ae%89%e5%85%a8%e6%9c%8d%e5%8a%a1/%e5%ae%89%e5%85%a8%e8%ae%be%e8%ae%a1" >
                            <span class="cc-menu--item__title">
                                安全设计
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%ae%89%e5%85%a8%e6%9c%8d%e5%8a%a1/%e5%ae%89%e5%85%a8%e5%92%a8%e8%af%a2" >
                            <span class="cc-menu--item__title">
                                安全咨询
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%ae%89%e5%85%a8%e6%9c%8d%e5%8a%a1/%e5%ae%89%e5%85%a8%e6%95%99%e8%82%b2" >
                            <span class="cc-menu--item__title">
                                安全教育
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    </ul>
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/%e6%8a%80%e6%9c%af%e5%ae%9e%e5%8a%9b" >
                            <span class="cc-menu--item__title">
                                技术实力
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%85%9a%e5%bb%ba%e5%9b%ad%e5%9c%b0" >
                            <span class="cc-menu--item__title">
                                党建园地
                            </span>
                            
                        </a>
                <i class="fas fa-caret-down down-icon"></i>
            </div>
            <ul class="cc-menu--nav">
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%85%9a%e5%bb%ba%e5%9b%ad%e5%9c%b0/%e5%85%9a%e5%bb%ba%e6%96%b0%e9%97%bb" >
                            <span class="cc-menu--item__title">
                                党建新闻
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e5%85%9a%e5%bb%ba%e5%9b%ad%e5%9c%b0/%e5%ad%a6%e4%b9%a0%e5%9b%ad%e5%9c%b0" >
                            <span class="cc-menu--item__title">
                                学习园地
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    </ul>
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e6%96%b0%e9%97%bb%e4%b8%ad%e5%bf%83/%e8%a1%8c%e4%b8%9a%e6%96%b0%e9%97%bb" >
                            <span class="cc-menu--item__title">
                                新闻中心
                            </span>
                            
                        </a>
                <i class="fas fa-caret-down down-icon"></i>
            </div>
            <ul class="cc-menu--nav">
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e6%96%b0%e9%97%bb%e4%b8%ad%e5%bf%83/%e8%a1%8c%e4%b8%9a%e6%96%b0%e9%97%bb" >
                            <span class="cc-menu--item__title">
                                行业新闻
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e6%96%b0%e9%97%bb%e4%b8%ad%e5%bf%83/%e5%85%ac%e5%8f%b8%e5%8a%a8%e6%80%81" >
                            <span class="cc-menu--item__title">
                                公司动态
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    </ul>
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/%e6%94%bf%e7%ad%96%e6%b3%95%e8%a7%84" >
                            <span class="cc-menu--item__title">
                                政策法规
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/%e8%81%94%e7%b3%bb%e6%88%91%e4%bb%ac" >
                            <span class="cc-menu--item__title">
                                联系我们
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="https://www.enst.org.cn/category/%e6%8b%9b%e8%b4%a4%e7%ba%b3%e5%a3%ab" >
                            <span class="cc-menu--item__title">
                                招贤纳士
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    </ul></div>

<script>(function() {
    useComponent('menu').default({"id":"menu-69b3f8deb02de","options":{"hover_show":"no","show_cur_sub":"no","retain_hover":"none","line-style-obj":"all_menu","line-style":"left","mode":"vertical","style":"default","menu-item-repulsion":"no"}})
})()</script></div>                <div class="Page-header--shade__widgets">
            <div tabindex="-1" class="search-wrapper">
    
    
            <div class="search-icon2">
            <i style="color:#333333" class="fas fa-search"></i>
        </div>
        <form action="https://www.enst.org.cn" target="_blank">
            <div class="search-input-text">
                <input class="cc-form--input2" type="text" name="search" placeholder="搜索">
                <button class="cc-icon">
                    <i style="color:#000000" class="fa fa-search"></i> 
                </button>
            </div>
        </form>
    
</div>
        </div>
            </div>

    
</div>
    </div>
<div class="Page-header--mobile__placeholder"></div>
<div class="Page-slot--template-header" template_type="current" template_position="template-header" template_id="19"><div node-id="id-25-di1xji1hgr" node-type="row" class="cc-row cc-slot--wrapper cc-row--flex cc-row--justify__start cc-row--align__top cc-row--width__row">
<style style-id="id-25-di1xji1hgr">
[node-id="id-25-di1xji1hgr"]{background-position:center center;background-repeat:no-repeat;background-size:cover;background-image:url(/uploads/2023/07/d42689495176d9691c509e6d0bf376d4.jpg);}
</style>
<script>(function() {
    useComponent('row').default({"id":"id-25-di1xji1hgr","options":{"full-width":"row","adaption-height":"no","background-video":"","noheader-full-height":"no","auto-flex":[],"auto-flex-enable":"no"}})
})()</script><div node-id="id-72-sycke1e0oe" node-type="column" class="cc-col cc-slot--wrapper cc-col--align__top cc-col--justify__start cc-col-24 cc-col-xl-24 cc-col-lg3-24 cc-col-lg2-24 cc-col-lg-24 cc-col-md-24 cc-col-sm-24 cc-col-xs-24"><script>(function() {
    useComponent('column').default({"id":"id-72-sycke1e0oe","options":[]})
})()</script><div class="cc-element--wrapper id-48-c8f6h8ofvj--wrapper" >
        <div node-id="id-48-c8f6h8ofvj" node-type="block" class="cc-block cc-slot--wrapper">
<style style-id="id-48-c8f6h8ofvj">
@media only screen and (max-width: 767px) {[node-id="id-48-c8f6h8ofvj"]{padding-right:10px;padding-left:10px;} 
}@media only screen and (min-width: 768px) {[node-id="id-48-c8f6h8ofvj"]{padding-right:50px;padding-left:50px;} 
}@media only screen and (min-width: 1600px) {[node-id="id-48-c8f6h8ofvj"]{padding-right:15px;padding-left:15px;} 
}
</style>
<script>(function() {
    useComponent('block').default({"id":"id-48-c8f6h8ofvj","options":[]})
})()</script><div node-id="id-58-a4aglffxpg" node-type="row" class="cc-row cc-slot--wrapper cc-row--flex cc-row--justify__start cc-row--align__top cc-row--width__default"><script>(function() {
    useComponent('row').default({"id":"id-58-a4aglffxpg","options":{"full-width":"default","adaption-height":"no","background-video":"","noheader-full-height":"no","auto-flex":[],"auto-flex-enable":"no"}})
})()</script><div node-id="id-46-lznlgg5n0n" node-type="column" class="cc-col cc-slot--wrapper cc-col--align__middle cc-col--justify__start cc-col-23 cc-col-xl-23 cc-col-lg3-23 cc-col-lg2-23 cc-col-lg-23 cc-col-md-23 cc-col-sm-23 cc-col-xs-23"><script>(function() {
    useComponent('column').default({"id":"id-46-lznlgg5n0n","options":[]})
})()</script></div><div node-id="id-71-cd7vllkx5r" node-type="column" class="cc-col cc-slot--wrapper cc-col--align__top cc-col--justify__start cc-col-1 cc-col-xl-1 cc-col-lg3-1 cc-col-lg2-1 cc-col-lg-1 cc-col-md-1 cc-col-sm-1 cc-col-xs-1"><script>(function() {
    useComponent('column').default({"id":"id-71-cd7vllkx5r","options":[]})
})()</script><div class="cc-element--wrapper id-69-tjux2pptv6--wrapper" >
<style style-id="id-69-tjux2pptv6">
@media only screen and (max-width: 767px) {[node-id="id-69-tjux2pptv6"]{padding-bottom:100px;} 
}@media only screen and (min-width: 768px) {[node-id="id-69-tjux2pptv6"]{padding-bottom:200px;} 
}@media only screen and (min-width: 1600px) {[node-id="id-69-tjux2pptv6"]{padding-bottom:280px;} 
}
</style>
<div node-id="id-69-tjux2pptv6" node-type="placeholder" class="cc-placeholder"  style="height:0px">
</div>


<script>(function() {
    useComponent('placeholder').default({"id":"id-69-tjux2pptv6","options":[]})
})()</script></div></div></div></div></div></div></div><div node-id="id-61-ep8lfjtu5n" node-type="row" class="cc-row cc-slot--wrapper cc-row--flex cc-row--justify__start cc-row--align__top cc-row--width__row">
<style style-id="id-61-ep8lfjtu5n">
[node-id="id-61-ep8lfjtu5n"]{background-color:rgba(233, 90, 48, 1);}
</style>
<script>(function() {
    useComponent('row').default({"id":"id-61-ep8lfjtu5n","options":{"full-width":"row","adaption-height":"no","background-video":"","noheader-full-height":"no","auto-flex":[],"auto-flex-enable":"no"}})
})()</script><div node-id="id-48-u3i1kxxejp" node-type="column" class="cc-col cc-slot--wrapper cc-col--align__top cc-col--justify__start cc-col-24 cc-col-xl-24 cc-col-lg3-24 cc-col-lg2-24 cc-col-lg-24 cc-col-md-24 cc-col-sm-24 cc-col-xs-24"><script>(function() {
    useComponent('column').default({"id":"id-48-u3i1kxxejp","options":[]})
})()</script><div class="cc-element--wrapper id-43-ixxd9naqyz--wrapper" >
        <div node-id="id-43-ixxd9naqyz" node-type="block" class="cc-block cc-slot--wrapper">
<style style-id="id-43-ixxd9naqyz">
@media only screen and (max-width: 767px) {[node-id="id-43-ixxd9naqyz"]{padding-right:10px;padding-left:10px;} 
}@media only screen and (min-width: 768px) {[node-id="id-43-ixxd9naqyz"]{padding-left:50px;padding-right:50px;} 
}@media only screen and (min-width: 1600px) {[node-id="id-43-ixxd9naqyz"]{padding-right:15px;padding-left:15px;} 
}
</style>
<script>(function() {
    useComponent('block').default({"id":"id-43-ixxd9naqyz","options":[]})
})()</script><div node-id="id-32-fh0x02dyhi" node-type="row" class="cc-row cc-slot--wrapper cc-row--flex cc-row--justify__start cc-row--align__top cc-row--width__default">
<style style-id="id-32-fh0x02dyhi">
[node-id="id-32-fh0x02dyhi"]{padding-top:5px;padding-bottom:5px;}
</style>
<script>(function() {
    useComponent('row').default({"id":"id-32-fh0x02dyhi","options":{"full-width":"default","adaption-height":"no","background-video":"","noheader-full-height":"no","auto-flex":[],"auto-flex-enable":"no"}})
})()</script><div node-id="id-27-c59p6ep9z5" node-type="column" class="cc-col cc-slot--wrapper cc-col--align__top cc-col--justify__start cc-col-24 cc-col-xl-24 cc-col-lg3-24 cc-col-lg2-24 cc-col-lg-24 cc-col-md-24 cc-col-sm-24 cc-col-xs-24"><script>(function() {
    useComponent('column').default({"id":"id-27-c59p6ep9z5","options":[]})
})()</script><div class="cc-element--wrapper id-27-rd3seebzf9--wrapper" >
<style style-id="id-27-rd3seebzf9">
[node-id="id-27-rd3seebzf9"].cc-breadcrumb li:nth-child(n+2)::before{content: "/";} 
[node-id="id-27-rd3seebzf9"].cc-breadcrumb{color: rgba(255, 255, 255, 1);
        font-size: 15px;}
</style>
<div node-id="id-27-rd3seebzf9" node-type="breadcrumb" class="cc-breadcrumb cc-breadcrumb cc-breadcrumb--align__left" >
    <ul><li><a  href="https://www.enst.org.cn" >首页</a></li><li><a  href="https://www.enst.org.cn/category/%e7%bd%91%e5%ae%89%e8%a7%86%e7%95%8c" >网安视界</a></li><li class="disabled"><a  href="https://www.enst.org.cn/221.html" >内存取证-Otter CTF（ 取证专项赛）</a></li></ul>
</div>
<script>(function() {
    useComponent('breadcrumb').default({"id":"id-27-rd3seebzf9","options":[]})
})()</script></div></div></div></div></div></div></div><div node-id="id-48-lsodpj8yy8" node-type="row" class="cc-row cc-slot--wrapper cc-row--flex cc-row--justify__start cc-row--align__top cc-row--width__default"><script>(function() {
    useComponent('row').default({"id":"id-48-lsodpj8yy8","options":{"full-width":"default","adaption-height":"no","background-video":"","noheader-full-height":"no","auto-flex":[],"auto-flex-enable":"no"}})
})()</script><div node-id="id-81-hf2k2cvjby" node-type="column" class="cc-col cc-slot--wrapper cc-col--align__top cc-col--justify__start cc-col-24 cc-col-xl-24 cc-col-lg3-24 cc-col-lg2-24 cc-col-lg-24 cc-col-md-24 cc-col-sm-24 cc-col-xs-24"><script>(function() {
    useComponent('column').default({"id":"id-81-hf2k2cvjby","options":[]})
})()</script><div class="cc-element--wrapper id-58-ozfky1pppk--wrapper" ><div node-id="id-58-ozfky1pppk" node-type="placeholder" class="cc-placeholder"  style="height:30px">
</div>


<script>(function() {
    useComponent('placeholder').default({"id":"id-58-ozfky1pppk","options":[]})
})()</script></div></div></div></div>        </div>
        <div class="Page-body">
            <div class="Page-sidebar sidebar-left  ">
                            </div>
            <div class="Page-content">
                
<div class="posts container ">
    <div class="posts-header">
        <h1 class="posts-title">
            内存取证-Otter CTF（ 取证专项赛）        </h1>
        <h2 class="posts-subtitle">
                    </h2>
        <div class="posts-meta">
                                        <div class="date">
                    发布于： 2024-07-05 15:55                 </div>
                                    
                                            <div class="source">
                    来源： <a href="https://mp.weixin.qq.com/s?__biz=MzIzNDY5NTY3MA==&mid=2247491014&idx=1&sn=4069a4e3490cb5e26b2740671435b837&chksm=e8f3235fdf84aa49fd5139add003c7b34b18b196bf269e1bdf1362491ac561f3b09ed847450f&token=247249813&lang=zh_CN#rd" target="_blank" rel="nofollow">卓识网安</a>                </div>
                                                            </div>
    </div>

    <div class="posts-body">
                <div class="posts-content">
            <div class="richtext">
                <section style="letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;"><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/5d9176dc5fc237fd9999c6543f6c4ad1.gif" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="margin: 0px 0px 35px;box-sizing: border-box;"><section style='display: grid;width: 100%;overflow: hidden;align-self: flex-start;line-height: 1.6;letter-spacing: 0px;color: rgb(0, 0, 0);background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;grid-template-columns: 100%;grid-template-rows: 100%;background-image: url("/uploads/2024/07/3a67ae9ac8c205bdfd4d125a2e612151.png");background-size: cover !important;box-sizing: border-box;'><section style="width: 84.3335%;height: 77.5018%;transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-o-transform: rotate(0deg);margin-left: 7.83%;margin-top: 7.75%;grid-column-start: 1;grid-row-start: 1;box-sizing: border-box;"><section style="text-align: center;line-height: 0;font-size: 17px;height: 100%;pointer-events: none;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;pointer-events: none;box-sizing: border-box;"><img src="/uploads/2024/07/56bdc57f1848adb8b9ab87d49e3dc752.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section></section><section style="grid-column-start: 1;grid-row-start: 1;display: flex;pointer-events: none;box-sizing: border-box;"><svg xmlns="http://www.w3.org/2000/svg" width="100%" height="100%" style="transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-o-transform: rotate(0deg);box-sizing: border-box;" viewbox="0  0 383 263"><svg style="overflow: initial;box-sizing: border-box;" width="83.1325%" height="19.4%" x="8.42185%" y="19.911335510589%"><foreignobject width="100%" height="100%" style="transform-origin: center center;-webkit-transform-origin: center center;-moz-transform-origin: center center;-o-transform-origin: center center;transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-o-transform: rotate(0deg);box-sizing: border-box;"><section style="height: 100%;box-sizing: border-box;"><section style="color: rgb(255, 255, 255);font-size: 32px;text-align: center;letter-spacing: 2px;word-break: break-word;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span style="box-sizing: border-box;"><strong style="box-sizing: border-box;">网安视界</strong></span></p></section></section></foreignobject></svg></svg></section><section style="grid-column-start: 1;grid-row-start: 1;display: flex;pointer-events: none;box-sizing: border-box;"><svg xmlns="http://www.w3.org/2000/svg" width="100%" height="100%" style="transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-o-transform: rotate(0deg);box-sizing: border-box;" viewbox="0  0 383 263"><svg style="overflow: initial;box-sizing: border-box;" width="83.1325%" height="76.8182px" x="9.14316%" y="42.634009279167%"><foreignobject width="100%" height="100%" style="transform-origin: center center;-webkit-transform-origin: center center;-moz-transform-origin: center center;-o-transform-origin: center center;transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-o-transform: rotate(0deg);box-sizing: border-box;"><section style="height: 100%;box-sizing: border-box;"><section style="color: rgb(255, 255, 255);font-size: 24px;text-align: center;letter-spacing: 2px;word-break: break-word;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">内存取证-Otter CTF （ 取证专项赛）</strong></p></section></section></foreignobject></svg></svg></section><section style="grid-column-start: 1;grid-row-start: 1;display: flex;pointer-events: none;box-sizing: border-box;"><svg xmlns="http://www.w3.org/2000/svg" width="100%" height="100%" style="transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-o-transform: rotate(0deg);box-sizing: border-box;" viewbox="0  0 383 263"><svg style="overflow: initial;box-sizing: border-box;" width="90%" height="16.64%" x="5%" y="63.633473647188%"><foreignobject width="100%" height="100%" style="transform-origin: center center;-webkit-transform-origin: center center;-moz-transform-origin: center center;-o-transform-origin: center center;transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-o-transform: rotate(0deg);box-sizing: border-box;"><section style="height: 100%;box-sizing: border-box;"><section style="font-size: 27px;color: rgb(52, 54, 60);text-align: center;letter-spacing: 2px;word-break: break-word;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><br></p></section></section></foreignobject></svg></svg></section><section style="grid-column-start: 1;grid-row-start: 1;padding-top: 68.8889%;box-sizing: border-box;"><svg viewbox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 45px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: 95%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-radius: 5px;height: auto;padding: 10px;overflow: hidden;background-color: rgba(255, 255, 255, 0.21);box-shadow: rgba(0, 0, 0, 0.23) 4px 4px 8px 0px;border-bottom: 6px solid rgb(13, 105, 201);box-sizing: border-box;"><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="display: none;line-height: 0px;">‍</span>内存取证是⼀种重要的数字取证技术， 它主要针对计算机内存中的信息进⾏提取和分析 。对于⼀些短暂 存在于内存中的数据， 如⽹络连接 、正在运⾏的进程 、登录⽤户 、打开的⽂件等， 内存取证能够提供⼤ 量的线索 。这种技术在⽹络安全调查 、犯罪侦查 、系统故障分析等领域有⼴泛的应⽤ 。</p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">在内存取证过程中， 主要包括以下步骤：</p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">1. 内存抓取：这是内存取证的第⼀步， 通过专⻔的⼯具对⽬标计算机的内存进⾏抓取， 得到内存镜 像。</p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">2. 内存分析：在抓取内存后， 需要对内存镜像进⾏详细的分析， 以发现有⽤的信息 。这—步可能需要 使⽤到各种内存分析⼯具。</p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">3. 信息提取：在内存分析的基础上， 对发现的有⽤信息进⾏提取和保存。</p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">4. 报告编写：最后， 将内存取证的结果以报告的形式进⾏呈现。<span style="display: none;line-height: 0px;">‍</span></p></section></section></section><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="transform-origin: left top;-webkit-transform-origin: left top;-moz-transform-origin: left top;-o-transform-origin: left top;margin-top: 0px;margin-bottom: 0px;z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 55px 0px 25px;box-sizing: border-box;"><section style='display: inline-block;vertical-align: top;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 5px 15px 0px;align-self: stretch;line-height: 1.6;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;border-bottom-left-radius: 15px;overflow: hidden;background-image: url("/uploads/2024/07/78baca3a6911e1e20f4167c6984f3769.png");background-size: cover !important;box-sizing: border-box;'><section style="margin: 0px;box-sizing: border-box;"><section style="text-align: justify;font-size: 27px;color: rgb(253, 253, 253);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"></p></section></section></section><section style='display: inline-block;vertical-align: top;width: auto;align-self: stretch;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 6px 25px;background-position: 42.8481% 0%;background-repeat: no-repeat;background-attachment: scroll;background-image: url("/uploads/2024/07/78baca3a6911e1e20f4167c6984f3769.png");background-size: 311.835% !important;box-sizing: border-box;'><section style="margin: 0px;box-sizing: border-box;"><section style="text-align: justify;color: rgb(255, 255, 255);letter-spacing: 3px;font-size: 27px;line-height: 1.5;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">内存取证练习<strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"></span></strong></p></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;margin: 0px 0px 0px -17px;line-height: 0;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="box-sizing: border-box;"><section style="display: inline-block;width: 15px;height: 15px;vertical-align: top;overflow: hidden;background-color: rgb(26, 141, 205);box-sizing: border-box;"><svg viewbox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section></section></section><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: 95%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(255, 255, 255);padding: 15px;height: auto;margin: 15px 15px 0px;box-shadow: rgba(0, 0, 0, 0.16) 4px 4px 5px 0px;border-style: solid;border-width: 1px;border-color: rgb(13, 105, 201);box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 2;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 25px 0px 10px;box-sizing: border-box;"><section style='display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 0px 10px;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;align-self: center;border-top-right-radius: 20px;border-bottom-left-radius: 20px;overflow: hidden;background-image: url("/uploads/2024/07/78baca3a6911e1e20f4167c6984f3769.png");background-size: cover !important;box-sizing: border-box;'><section style="text-align: justify;font-size: 20px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">01</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;box-sizing: border-box;"><section style="text-align: justify;color: rgb(13, 105, 201);letter-spacing: 1.5px;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 18px;box-sizing: border-box;"><strong style="box-sizing: border-box;">题⽬1-What the password?</strong></span><span style="font-size: 10px;box-sizing: border-box;"> </span></p></section></section></section></section></section><section style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 15px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;padding: 10px;background-color: rgba(160, 160, 160, 0.07);border-style: solid;border-width: 1px;border-color: rgb(13, 105, 201);border-radius: 5px;overflow: hidden;box-sizing: border-box;"><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/86ff8e75f968324d9b0d2228a7f79e88.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;line-height: 2;font-style: normal;font-weight: 400;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;line-height: 2;font-style: normal;font-weight: 400;">⾸先还是先分析⼀下镜像</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/f71f406c542c0347bf11efc06772cebe.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;line-height: 2;font-style: normal;font-weight: 400;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;line-height: 2;font-style: normal;font-weight: 400;">使⽤hashdump获取⽤户hash</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/ca260a3b9c67ec2e3ea4b3087678728f.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">发现⽆法解密成功 ，使⽤lsadump从注册表中提取LSA密钥信息， 得到密码信息MortyIsReallyAnOtter</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/aa3e508710e4653cbd85bd966f3a8026.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section></section></section><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 2;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 25px 0px 10px;box-sizing: border-box;"><section style='display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 0px 10px;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;align-self: center;border-top-right-radius: 20px;border-bottom-left-radius: 20px;overflow: hidden;background-image: url("/uploads/2024/07/78baca3a6911e1e20f4167c6984f3769.png");background-size: cover !important;box-sizing: border-box;'><section style="text-align: justify;font-size: 20px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">02</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;box-sizing: border-box;"><section style="text-align: justify;color: rgb(13, 105, 201);letter-spacing: 1.5px;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 18px;box-sizing: border-box;"><strong style="box-sizing: border-box;">题⽬2-Play Time</strong></span><span style="font-size: 10px;box-sizing: border-box;"> </span></p></section></section></section></section></section><section style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 15px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;padding: 10px;background-color: rgba(160, 160, 160, 0.07);border-style: solid;border-width: 1px;border-color: rgb(13, 105, 201);border-radius: 5px;overflow: hidden;box-sizing: border-box;"><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/cae42b96b7ec13ec5ad7d8197529b45d.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">题⽬要求找到玩的游戏以及对应IP， 先使⽤pstree查看进程</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/59d768859d7ab80f0219475d1bd499bb.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">搜索进程名称发现LunarMS.exe为⼀款游戏</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/25c140a2dfc94d8a9c61b4b783ca5bab.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">查看LunarMS该进程使⽤的⽹络连接情况查找对应IP 发现IP地址为77.102.199.102</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/2c3ac52064bd740ce4fbd6b92039dfa3.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section></section></section><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 2;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 25px 0px 10px;box-sizing: border-box;"><section style='display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 0px 10px;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;align-self: center;border-top-right-radius: 20px;border-bottom-left-radius: 20px;overflow: hidden;background-image: url("/uploads/2024/07/78baca3a6911e1e20f4167c6984f3769.png");background-size: cover !important;box-sizing: border-box;'><section style="text-align: justify;font-size: 20px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">03</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;box-sizing: border-box;"><section style="text-align: justify;color: rgb(13, 105, 201);letter-spacing: 1.5px;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 18px;box-sizing: border-box;"><strong style="box-sizing: border-box;">题⽬3-General Info</strong></span><span style="font-size: 10px;box-sizing: border-box;"> </span></p></section></section></section></section></section><section style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 15px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;padding: 10px;background-color: rgba(160, 160, 160, 0.07);border-style: solid;border-width: 1px;border-color: rgb(13, 105, 201);border-radius: 5px;overflow: hidden;box-sizing: border-box;"><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/07eccf45954ee5f1c1117d614e2d8655.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">根据题⽬提示， 需要查找PC名称以及IP地址 ⾸先使⽤hive list列出注册表</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/d94215ded0eab8301a3f4ec18df02926.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">发现注册表0xfffff8a000024010 0x000000002d50c010 \REGISTRY\MACHINE\SYSTEM</p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">主机名称注册表位置：ControlSet001\Control\ComputerName\ComputerName 获取主机名称</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/1999cb0a4130f5af6132e2480634e9cd.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">使⽤ netscan查看⽹络连接情况， 或者根据题⽬2中获取信息得到IP 192.168.202.131</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/b5487bf50afa111ae53de8197c385f91.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section></section></section><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 2;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 25px 0px 10px;box-sizing: border-box;"><section style='display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 0px 10px;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;align-self: center;border-top-right-radius: 20px;border-bottom-left-radius: 20px;overflow: hidden;background-image: url("/uploads/2024/07/78baca3a6911e1e20f4167c6984f3769.png");background-size: cover !important;box-sizing: border-box;'><section style="text-align: justify;font-size: 20px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">04</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;box-sizing: border-box;"><section style="text-align: justify;color: rgb(13, 105, 201);letter-spacing: 1.5px;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 18px;box-sizing: border-box;"><strong style="box-sizing: border-box;">题⽬4-Name Game</strong></span><span style="font-size: 10px;box-sizing: border-box;"> </span></p></section></section></section></section></section><section style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 15px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;padding: 10px;background-color: rgba(160, 160, 160, 0.07);border-style: solid;border-width: 1px;border-color: rgb(13, 105, 201);border-radius: 5px;overflow: hidden;box-sizing: border-box;"><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/fd5879af5a218aef529f82bd3d8a980e.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">根据提示， 登陆了游戏， 那尝试直接在镜像中搜索 先使⽤strings重定向到⽂本中</p>
<p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">strings OtterCTF.vmem > OtterCTF.vmem.strings</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/122fa869d45d774149ceba7392ee9a7f.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">进⾏搜索</p>
<p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">cat OtterCTF.vmem.strings | grep -C 10 "Lunar-3" 查找到Lunar-3以及对应密码0tt3r8r33z3</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/b338f6a6047bb644d8f8bc6c7232ed69.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section></section></section><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 2;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 25px 0px 10px;box-sizing: border-box;"><section style='display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 0px 10px;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;align-self: center;border-top-right-radius: 20px;border-bottom-left-radius: 20px;overflow: hidden;background-image: url("/uploads/2024/07/78baca3a6911e1e20f4167c6984f3769.png");background-size: cover !important;box-sizing: border-box;'><section style="text-align: justify;font-size: 20px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">05</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;box-sizing: border-box;"><section style="text-align: justify;color: rgb(13, 105, 201);letter-spacing: 1.5px;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 18px;box-sizing: border-box;"><strong style="box-sizing: border-box;">题⽬5-Name Game 2</strong></span><span style="font-size: 10px;box-sizing: border-box;"> </span></p></section></section></section></section></section><section style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 15px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;padding: 10px;background-color: rgba(160, 160, 160, 0.07);border-style: solid;border-width: 1px;border-color: rgb(13, 105, 201);border-radius: 5px;overflow: hidden;box-sizing: border-box;"><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/9bd01d6bf18bfdc5cf235f30e59d067a.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">根据提示， ⽤户名总在这个</p>
<p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">0x64 0x??{6-8} 0x40 0x06 0x??{18} 0x5a 0x0c 0x00{2} ） 签名之后</p>
<p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">根据上⾯题⽬ ， 我们⾸先dump进程LunarMS.exe ，根据上⾯题⽬可知LunarMS.exe的进程为708</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/91834b7db5859b37f05ae81705f16b4a.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/282571c9efb2e8a85db82a8a9739b7a5.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">接下来需要查找提示中的内容， 可使⽤ winhex, 010Editor,或者 linux 中的 hexdump等⽅式查看， 也可 使⽤xxd命令输出查看。</p></section><section style="text-align: justify;font-size: 15px;padding: 0px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">⽤于⽤⼆进制或⼗六进制显示⽂件的内容， 如果没有指定outfile参数，则把结果显示在屏幕上， 如 果指定了outfile则把结果输出到 outfile中；如果infile参数为 – 或则没有指定infile参数，则默认   从标准输⼊读⼊ 。</p>
<p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">xxd [options] [infile [outfile]] </p>
<p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">xxd -r [-s [-]offset] [-c cols] [-ps] [infile [outfile]] </p>
<p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">简单地说，xxd就是⼀个⼆进制⽂件查看器</p></section><section style="text-align: justify;line-height: 1;box-sizing: border-box;"><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">1   常⽤选项： </span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">2   -b<br style="box-sizing: border-box;"></span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="font-size: 15px;box-sizing: border-box;">3   转到  ⽐特(⼆进制  数字) 模式 , ⽽不是⼗六进制模式 。在这种模式下 , 每个字符被表示成⼋个  0/1 的数字，⽽不是⼀般的⼗六进制形式 。每⼀⾏都以⼀个⽤⼗六进制形式表示的⾏号，后⾯是ascii (或者  ebcdic) 形式开头 。命令⾏选项  -r, -p 在这个模式下不起作⽤ 。</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">4   -h</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">5   显示帮助信息后退出。 </span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">6</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">7   -l N</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">8   只输出  N 个字符。 </span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">9</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">10   -ps</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">11   以  postscript的连续⼗六进制转储输出， 这也叫做纯⼗六进制转储。 </span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">12</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">13   -r</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">14   逆向操作 : 把xxd的⼗六进制输出内容转换回原⽂件的⼆进制内容。 </span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">15</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">16   -seek offset</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">17   ⽤在  -r 之后 : 会在当前⽂档的  偏移量上增加   . </span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">18</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">19   -s [+] [-]seek</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">20   从infile的绝对或者相对偏移量  开始 .</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">21   + 表示相对于标  输⼊当前的位置   (如果不  标准输⼊就没有意义了).</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">22   – 表示从档桉末尾   (如果和  + 连⽤ : 从标准输⼊当前位置) 向前数⼀些字符 , 从那个地⽅开始 . 如果没有  -s 选项 , xxd 从  当前位置开始 .</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">23</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">24   -u</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">25   ⼗六进制输出时使⽤⼤写字⺟ ，默认是⼩写字⺟ </span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">26</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">27   示例：</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">28   以⼆进制形式，查看前16个字节，每⾏显示1个字节：</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">29   xxd -b -l 16 -c 1 a.o</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">30</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">31   从第16个字节开始（ 注：16是下标，起始为0算）， 显示40个字节，每⾏显示8个字节：</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">32   xxd -s 16 -l 40 -c 8 a.o</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">33</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">34   从第16个字节开始，每⾏8个， 显示40个字节的hex dump</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">35   xxd -s 16 -l 40 -c 8 -ps a.o</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">36</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">37   输出最后10个字节内容</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">38   xxd -s -10 a.o</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">39</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">40   查看⽂件时， ⾃动跳过⼤块的0区域来显示</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">41   xxd -a a.o</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">42</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">43   把b.txt以⼗六进制写到c.o </span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><span style="box-sizing: border-box;font-size: 15px;">44   xxd -r -ps b.txt c.o</span></section><section style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;line-height: 1.6em;"><br></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">xxd 708.dmp | grep "5a0c 0000"</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/ba250d0f374a7956ffe02743a983ebe2.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">发现c33a4a0存在M0rt信息， 怀疑可能是⽤户名信息， ⽤ xxd将M0rt其他信息读取出来</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/dee4c9547dd71c35beb9d3b3eebf5bc9.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">读取信息为M0rtyL0L， 提交成功。</p></section></section></section><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 2;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 25px 0px 10px;box-sizing: border-box;"><section style='display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 0px 10px;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;align-self: center;border-top-right-radius: 20px;border-bottom-left-radius: 20px;overflow: hidden;background-image: url("/uploads/2024/07/78baca3a6911e1e20f4167c6984f3769.png");background-size: cover !important;box-sizing: border-box;'><section style="text-align: justify;font-size: 20px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">06</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;box-sizing: border-box;"><section style="text-align: justify;color: rgb(13, 105, 201);letter-spacing: 1.5px;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 18px;box-sizing: border-box;"><strong style="box-sizing: border-box;">题⽬6-Silly Rick</strong></span><span style="font-size: 10px;box-sizing: border-box;"> </span></p></section></section></section></section></section><section style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 15px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;padding: 10px;background-color: rgba(160, 160, 160, 0.07);border-style: solid;border-width: 1px;border-color: rgb(13, 105, 201);border-radius: 5px;overflow: hidden;box-sizing: border-box;"><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/64b4a9e719b07b5e1e6d89d70cb80ad5.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">根据题⽬描述， rick将密码复制粘贴， 那密码将存在于剪贴板中， 直接进⾏读取</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/5a0441e1a803df7fb23f63b1929fc64a.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">得到剪贴板中密码信息M@il_Pr0vid0rs</p></section></section></section><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 2;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 25px 0px 10px;box-sizing: border-box;"><section style='display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 0px 10px;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;align-self: center;border-top-right-radius: 20px;border-bottom-left-radius: 20px;overflow: hidden;background-image: url("/uploads/2024/07/78baca3a6911e1e20f4167c6984f3769.png");background-size: cover !important;box-sizing: border-box;'><section style="text-align: justify;font-size: 20px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">07</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;box-sizing: border-box;"><section style="text-align: justify;color: rgb(13, 105, 201);letter-spacing: 1.5px;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 18px;box-sizing: border-box;"><strong style="box-sizing: border-box;">题⽬7-Hide And Seek</strong></span><span style="font-size: 10px;box-sizing: border-box;"> </span></p></section></section></section></section></section><section style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 15px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;padding: 10px;background-color: rgba(160, 160, 160, 0.07);border-style: solid;border-width: 1px;border-color: rgb(13, 105, 201);border-radius: 5px;overflow: hidden;box-sizing: border-box;"><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/1059692ffe9dbf6fd964c0921068c84a.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">根据提示， 需要查找恶意软件进程名称， ⾸先再次查看进程列表</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/a9338dd56225d2af0aa1954668782386.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/5a7c3ad4d754d8a8fc1062a3f97ac333.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">发现其中存在部分可疑进程， 搜索发现Rick And Morty为</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/d0e3f70280accff31482c839ce80595d.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">结合BitTorrent.exe， 猜测可能该进程存在问题， 查看该进程的进程树</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/98ef3d22405056fa0ac9f92e380b35dc.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">发现Rick And Morty下存在⼦进程vmware-tray.ex 查看—下该进程下运⾏的程序</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/d804bf61cbd4896e1dba05e9ad3d1ea4.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">查看后发现， 该进程为Rick And Morty下载vmware-tray.ex并在默认下载路径RarSFX下运⾏ ，则判断 恶意软件进程名称为vmware-tray.exe</p></section></section></section><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 2;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 25px 0px 10px;box-sizing: border-box;"><section style='display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 0px 10px;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;align-self: center;border-top-right-radius: 20px;border-bottom-left-radius: 20px;overflow: hidden;background-image: url("/uploads/2024/07/78baca3a6911e1e20f4167c6984f3769.png");background-size: cover !important;box-sizing: border-box;'><section style="text-align: justify;font-size: 20px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">08</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;box-sizing: border-box;"><section style="text-align: justify;color: rgb(13, 105, 201);letter-spacing: 1.5px;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 18px;box-sizing: border-box;"><strong style="box-sizing: border-box;">题⽬8-Path To Glory</strong></span><span style="font-size: 10px;box-sizing: border-box;"> </span></p></section></section></section></section></section><section style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 15px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;padding: 10px;background-color: rgba(160, 160, 160, 0.07);border-style: solid;border-width: 1px;border-color: rgb(13, 105, 201);border-radius: 5px;overflow: hidden;box-sizing: border-box;"><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/1868c2b9cb894e7b84af0b20f38f596e.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">题⽬要求查找恶意软件如何进⼊rick电脑</p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">由于题⽬7已发现Rick And Morty下载导致 ，则对⽂件进⾏搜索查看</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/5d0da7af4e5c1a553cec5b6da0f48fd4.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">分别将6条数据dump下来进⾏查看， 发现第四条数据中有不同内容</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/cf511b482607530da70749ab1773442b.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/eb1b1dcc367fa10f79fa7cdd98a542ab.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">发现途径</p></section></section></section><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 2;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 25px 0px 10px;box-sizing: border-box;"><section style='display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 0px 10px;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;align-self: center;border-top-right-radius: 20px;border-bottom-left-radius: 20px;overflow: hidden;background-image: url("/uploads/2024/07/78baca3a6911e1e20f4167c6984f3769.png");background-size: cover !important;box-sizing: border-box;'><section style="text-align: justify;font-size: 20px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">09</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;box-sizing: border-box;"><section style="text-align: justify;color: rgb(13, 105, 201);letter-spacing: 1.5px;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 18px;box-sizing: border-box;"><strong style="box-sizing: border-box;">题⽬9-Path To Glory 2</strong></span><span style="font-size: 10px;box-sizing: border-box;"> </span></p></section></section></section></section></section><section style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 15px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;padding: 10px;background-color: rgba(160, 160, 160, 0.07);border-style: solid;border-width: 1px;border-color: rgb(13, 105, 201);border-radius: 5px;overflow: hidden;box-sizing: border-box;"><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">总结是事后对某一阶段的工作或某项工作的完成情况，包括取得的成绩、存在的问题及得到的经验和教训加以回顾和分析，为今后的工作提供帮助和借鉴。</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/be19a5a4c8c2ed3d0ac81e5e5a91a482.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">根据前⾯题⽬内容可知，BitTorrent⽂件是通过web下载的，⽽且进程中发现有chrome进程，转存该⽂ 件进⾏查看</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/04dfae091034ecb456c27f87286d09d5.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/faf42ee8277ad6eb812e80b89966bfad.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">使⽤Navicat打开数据库查看</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/8daba6c25881e95dbca1513afabb393e.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">并未发现flag信息 ，但发现该种⼦⽂件来源于—个mail地址</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/f7baaf3721211c5578614cdf8fce1982.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">通过关键字查找⼀下镜像中内容</p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">由于查找内容过⼤， 将查找结果写⼊txt查看</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/0101a16ec2b83b62437e4916d77dced1.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">查找发现两个⽤户名 rickypinky@mail.com rickopicko@mail.com</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/349f88a02413756d8e78ce1f41c6a47f.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">继续查找两个⽤户有没有可疑⾏为</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/6b2a48790a75bf031874c8a5e50aaae8.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/0ef949c2037f5e09be9deb67e0039bd1.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;color: rgba(0, 0, 0, 0.62);box-sizing: border-box;">分析发现rickopicko@mail.com⽤户内存⽂件中包含—部分类似邮件源数据字符， 猜测 e0wumo+6qbbc5zrnw7kk@guerrillamail.comcn为hack邮箱， 继续进⾏查找</span></p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/13e41b50be59a22c383e688ed86e5db0.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">发现原数据包下有—串字符， 猜测为flag， 尝试发现正确。</p></section></section></section><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 2;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 25px 0px 10px;box-sizing: border-box;"><section style='display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 0px 10px;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;align-self: center;border-top-right-radius: 20px;border-bottom-left-radius: 20px;overflow: hidden;background-image: url("/uploads/2024/07/78baca3a6911e1e20f4167c6984f3769.png");background-size: cover !important;box-sizing: border-box;'><section style="text-align: justify;font-size: 20px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">10</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;box-sizing: border-box;"><section style="text-align: justify;color: rgb(13, 105, 201);letter-spacing: 1.5px;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 18px;box-sizing: border-box;"><strong style="box-sizing: border-box;">题⽬10-Bit 4 Bit</strong></span><span style="font-size: 10px;box-sizing: border-box;"> </span></p></section></section></section></section></section><section style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 15px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;padding: 10px;background-color: rgba(160, 160, 160, 0.07);border-style: solid;border-width: 1px;border-color: rgb(13, 105, 201);border-radius: 5px;overflow: hidden;box-sizing: border-box;"><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/8e9c1e7245715a4b58b959739c540870.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;color: rgba(0, 0, 0, 0.62);box-sizing: border-box;">题⽬要求查找hack的⽐特币地址</span></p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;color: rgba(0, 0, 0, 0.62);box-sizing: border-box;">根据题⽬提示， 尝试直接查找ransomware</span></p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/2e1bf127760da036844f921f7bdb4c40.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;color: rgba(0, 0, 0, 0.62);box-sizing: border-box;">发现信息</span></p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;color: rgba(0, 0, 0, 0.62);box-sizing: border-box;">1MmpEmebJkqXG8nQv4cjJSmxZQFVmFo63M</span></p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;color: rgba(0, 0, 0, 0.62);box-sizing: border-box;">看⼤佬⽂章还有另—种⽅式， 将勒索病毒的进程进⾏转存， 然后使⽤ILSpy进⾏反编译分析可以查找到</span></p></section></section></section><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 2;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 25px 0px 10px;box-sizing: border-box;"><section style='display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 0px 10px;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;align-self: center;border-top-right-radius: 20px;border-bottom-left-radius: 20px;overflow: hidden;background-image: url("/uploads/2024/07/78baca3a6911e1e20f4167c6984f3769.png");background-size: cover !important;box-sizing: border-box;'><section style="text-align: justify;font-size: 20px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">11</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;box-sizing: border-box;"><section style="text-align: justify;color: rgb(13, 105, 201);letter-spacing: 1.5px;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 18px;box-sizing: border-box;"><strong style="box-sizing: border-box;">题⽬11-Graphic's For The Weak</strong></span><span style="font-size: 10px;box-sizing: border-box;"> </span></p></section></section></section></section></section><section style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 15px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;padding: 10px;background-color: rgba(160, 160, 160, 0.07);border-style: solid;border-width: 1px;border-color: rgb(13, 105, 201);border-radius: 5px;overflow: hidden;box-sizing: border-box;"><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/6f105fbe80dd46b743b872a5758fd26a.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">根据题⽬所说，恶意软件的图形存在问题， 先将进程进⾏转存</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/bcc8941569d492e23a96a50e8add4ea4.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">转存出来为exe，binwalk查看—下</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/9bc5dac8227a9baeda759c9fd599feca.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">分离图⽚</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/cae7c0e66c50a3879f61f677d41a7282.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/8d41e75fd80f48aafa7319db753c92ff.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section></section></section><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 2;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 25px 0px 10px;box-sizing: border-box;"><section style='display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 0px 10px;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;align-self: center;border-top-right-radius: 20px;border-bottom-left-radius: 20px;overflow: hidden;background-image: url("/uploads/2024/07/78baca3a6911e1e20f4167c6984f3769.png");background-size: cover !important;box-sizing: border-box;'><section style="text-align: justify;font-size: 20px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">12</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;box-sizing: border-box;"><section style="text-align: justify;color: rgb(13, 105, 201);letter-spacing: 1.5px;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 18px;box-sizing: border-box;"><strong style="box-sizing: border-box;">题⽬12-Recovery</strong></span><span style="font-size: 10px;box-sizing: border-box;"> </span></p></section></section></section></section></section><section style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 15px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;padding: 10px;background-color: rgba(160, 160, 160, 0.07);border-style: solid;border-width: 1px;border-color: rgb(13, 105, 201);border-radius: 5px;overflow: hidden;box-sizing: border-box;"><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">总结是事后对某一阶段的工作或某项工作的完成情况，包括取得的成绩、存在的问题及得到的经验和教训加以回顾和分析，为今后的工作提供帮助和借鉴。</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/3c23863d533fb5dc6a8c9e20241de829.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">题⽬要求恢复⽂件，需要加密⽂件的密码</p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">通过ILSpy得知密码⻓度为15，格式为：computerName + "-" + userName + " " + password</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/a12983dad9a034266e3dcf5753dbe27e.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">在上⾯已经找到computerName和userName，进⾏全局搜索</p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">但由于.NET字符串类使⽤UTF16进⾏编码 ，所以strings需要加上-e b 或者 -e l参数</p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">先导出3720进程 ，在进⾏搜索</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/58f4094a2d83e8ed1fb11e1869fda2e3.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/d9caea4c73fedf84d163c99b6ece98d3.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section></section></section><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 2;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 25px 0px 10px;box-sizing: border-box;"><section style='display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 0px 10px;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;align-self: center;border-top-right-radius: 20px;border-bottom-left-radius: 20px;overflow: hidden;background-image: url("/uploads/2024/07/78baca3a6911e1e20f4167c6984f3769.png");background-size: cover !important;box-sizing: border-box;'><section style="text-align: justify;font-size: 20px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">01</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;box-sizing: border-box;"><section style="text-align: justify;color: rgb(13, 105, 201);letter-spacing: 1.5px;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 18px;box-sizing: border-box;"><strong style="box-sizing: border-box;">题⽬13-Closure</strong></span><span style="font-size: 10px;box-sizing: border-box;"> </span></p></section></section></section></section></section><section style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 15px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;padding: 10px;background-color: rgba(160, 160, 160, 0.07);border-style: solid;border-width: 1px;border-color: rgb(13, 105, 201);border-radius: 5px;overflow: hidden;box-sizing: border-box;"><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/b39701af6375660aef84925eb2769d8f.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">题⽬要求解密⽂件</p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">已知勒索病毒，直接上沙箱进⾏查看</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/36ef1c6d5629f6b2a1029e973b5e9207.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">回想前⾯解出的图⽚存在$ucyLocker，搜索发现是开源Hidden Tear勒索软件的变种， 找到解密器</p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">https://www.bleepingcomputer.com/download/hidden-tear-decrypter/</p>
<p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">提取之前看到的flag.txt⽂件</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/e8a40278bacbe86a99397743b96a887c.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/5366769164f2d60d10eb488caccb1460.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">查看⽂件内容</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/5eda993fdc68ab0f49d4b4d7abccb0d1.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">发现只有前⼏个字节有内容，提取前⼏个字节，并重命名</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/d58b98689a612c62940e31f77df15f16.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section><section style="text-align: justify;font-size: 15px;color: rgba(0, 0, 0, 0.62);letter-spacing: 2px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">使⽤解密⼯具对其进⾏解密，得到结果</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/6af4b331ec06eb74dea7f37a3c8d939e.png" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"></p>
<section style="text-align: left;font-size: 15px;padding: 0px 40px;line-height: 1.75;letter-spacing: 1.5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">参考：</strong></p></section><section style="margin: 0px 0px 15px;box-sizing: border-box;"><section style="font-size: 15px;padding: 0px 40px;line-height: 1.75;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">https://blog.csdn.net/Nancy523/article/details/125786459</p>
<p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">https://blog.csdn.net/qq_38626043/article/details/128102509 https://otterctf.com/</p></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img src="/uploads/2024/07/3619e1649a8f9093f13394c3744c5102.gif" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;"></section></section></section><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p><br/><br/>本篇文章来源于微信公众号:卓识网安            </div>
                    </div>
    </div>
        
    <div class="posts-share lay-fx lay-ai-c">
    <div>
        分享    </div>
    <div class="cc-element--wrapper share-69b3f8de87087--wrapper" >
<style style-id="share-69b3f8de87087">
[node-id="share-69b3f8de87087"].cc-share ul li img{width:44;
        height:44;}
</style>
<div node-id="share-69b3f8de87087" node-type="share" class="cc-share" >
    <div class="share-label"></div>
    <ul>
        
                <li>
                    <a href="javascript:_share_.weibo();">
                        <img src="/dist/theme/static/imgs/icon-weibo.png" alt="weibo">
                    </a>
                </li>
                
                <li>
                    <a href="javascript:_share_.wechat();">
                        <img src="/dist/theme/static/imgs/icon-wechat.png" alt="wechat">
                    </a>
                </li>
                
                <li>
                    <a href="javascript:_share_.QQ();">
                        <img src="/dist/theme/static/imgs/icon-qq.png" alt="QQ">
                    </a>
                </li>
                
                <li>
                    <a href="javascript:_share_.qzone();">
                        <img src="/dist/theme/static/imgs/icon-qzone.png" alt="qzone">
                    </a>
                </li>
                    </ul>
</div>

<script>(function() {
    useComponent('share').default({"id":"share-69b3f8de87087","options":[]})
})()</script></div></div>

</div>

            </div>
            <div class="Page-sidebar sidebar-right  ">
                            </div>

                    </div>

                <div class="Page-footer">
            <div class="Page-slot--template-footer" template_type="global" template_position="template-footer" template_id="6"><div node-id="id-98-mn89rwmr19" node-type="row" class="cc-row cc-slot--wrapper cc-row--flex cc-row--justify__start cc-row--align__top cc-row--width__row">
<style style-id="id-98-mn89rwmr19">
[node-id="id-98-mn89rwmr19"]{background-color:rgba(248, 248, 248, 1);}
</style>
<script>(function() {
    useComponent('row').default({"id":"id-98-mn89rwmr19","options":{"full-width":"row","adaption-height":"no","background-video":"","noheader-full-height":"no","auto-flex":[],"auto-flex-enable":"no"}})
})()</script><div node-id="id-50-lh5pcgg368" node-type="column" class="cc-col cc-slot--wrapper cc-col--align__top cc-col--justify__start cc-col-24 cc-col-xl-24 cc-col-lg3-24 cc-col-lg2-24 cc-col-lg-24 cc-col-md-24 cc-col-sm-24 cc-col-xs-24"><script>(function() {
    useComponent('column').default({"id":"id-50-lh5pcgg368","options":[]})
})()</script><div class="cc-element--wrapper id-18-l7q5sfufuu--wrapper" >
        <div node-id="id-18-l7q5sfufuu" node-type="block" class="cc-block cc-slot--wrapper">
<style style-id="id-18-l7q5sfufuu">
@media only screen and (max-width: 767px) {[node-id="id-18-l7q5sfufuu"]{padding-right:10px;padding-left:10px;} 
}@media only screen and (min-width: 768px) {[node-id="id-18-l7q5sfufuu"]{padding-right:50px;padding-left:50px;} 
}@media only screen and (min-width: 1600px) {[node-id="id-18-l7q5sfufuu"]{padding-right:15px;padding-left:15px;} 
}
</style>
<script>(function() {
    useComponent('block').default({"id":"id-18-l7q5sfufuu","options":[]})
})()</script><div node-id="id-26-kiyhis6jex" node-type="row" class="cc-row cc-slot--wrapper cc-row--flex cc-row--justify__start cc-row--align__top cc-row--width__default">
<style style-id="id-26-kiyhis6jex">
[node-id="id-26-kiyhis6jex"]{border-bottom-color:rgba(0, 0, 0, 0.06);border-bottom-width:1px;padding-bottom:20px;border-style:solid;} 
@media only screen and (max-width: 767px) {[node-id="id-26-kiyhis6jex"]{padding-top:40px;} 
}@media only screen and (min-width: 768px) {[node-id="id-26-kiyhis6jex"]{padding-top:40px;} 
}@media only screen and (min-width: 1600px) {[node-id="id-26-kiyhis6jex"]{padding-top:50px;} 
}
</style>
<script>(function() {
    useComponent('row').default({"id":"id-26-kiyhis6jex","options":{"full-width":"default","adaption-height":"no","background-video":"","noheader-full-height":"no","auto-flex":[],"auto-flex-enable":"no"}})
})()</script><div node-id="id-75-kbwnpblgyb" node-type="column" class="cc-col cc-slot--wrapper cc-col--align__top cc-col--justify__start cc-col-2 cc-col-xl-2 cc-col-lg3-2 cc-col-lg2-2 cc-col-lg-2 cc-col-md-2 cc-col-sm-2 cc-col-xs-5"><script>(function() {
    useComponent('column').default({"id":"id-75-kbwnpblgyb","options":[]})
})()</script><div class="cc-element--wrapper id-21-oe6eqxse4n--wrapper" >
<style style-id="id-21-oe6eqxse4n">
[node-id="id-21-oe6eqxse4n"] .cc-textblock__body{padding: 0px;}
</style>
<div node-id="id-21-oe6eqxse4n" node-type="textblock" class="cc-textblock" >
    <div class="cc-textblock__body richtext">
        <p>友情链接：</p>    </div>
</div>

<script>(function() {
    useComponent('textblock').default({"id":"id-21-oe6eqxse4n","options":[]})
})()</script></div></div><div node-id="id-63-q75fsdsswb" node-type="column" class="cc-col cc-slot--wrapper cc-col--align__top cc-col--justify__start cc-col-22 cc-col-xl-22 cc-col-lg3-22 cc-col-lg2-22 cc-col-lg-22 cc-col-md-22 cc-col-sm-22 cc-col-xs-19"><script>(function() {
    useComponent('column').default({"id":"id-63-q75fsdsswb","options":[]})
})()</script><div class="cc-element--wrapper id-99-jc0fgyqz20--wrapper" >
<style style-id="id-99-jc0fgyqz20">
[node-id="id-99-jc0fgyqz20"]{transform:translateX(0px) translateY(-2px) ;} 
[node-id="id-99-jc0fgyqz20"].cc-menu.cc-menu--vertical  .cc-menu--nav  .cc-menu--item{box-sizing:border-box;} 
[node-id="id-99-jc0fgyqz20"].cc-menu--style__line .line_box{background:rgba(255, 255, 255, 0);} 
[node-id="id-99-jc0fgyqz20"].cc-menu--style__line .cc-menu--item.current > .line_box{width:100%;} 
[node-id="id-99-jc0fgyqz20"] li.menu{color:#000000;} 
[node-id="id-99-jc0fgyqz20"] .icon-active{color:#3c3c3c!important;} 
[node-id="id-99-jc0fgyqz20"] .item-icon-active{color:#3c3c3c!important;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item  a{font-size:16px;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--nav > .cc-menu--item a{font-size:15px;} 
[node-id="id-99-jc0fgyqz20"].cc-menu--horizontal{text-align:left;} 
[node-id="id-99-jc0fgyqz20"].cc-menu--horizontal > .cc-menu--nav > .cc-menu--item{height:32px;line-height:32px;padding:0 20px;margin:0px 0px;} 
[node-id="id-99-jc0fgyqz20"].cc-menu--vertical > .cc-menu--nav > .cc-menu--item{margin:0px 0;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item .cc-menu--item__link{height:43px;line-height:43px;margin:0px 0;} 
[node-id="id-99-jc0fgyqz20"].cc-menu--vertical .cc-menu--item{line-height:32px;} 
[node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item,
                    [node-id="id-99-jc0fgyqz20"].cc-menu--style__line > .cc-menu--nav >.cc-menu--item{background-color:rgba(255, 255, 255, 0);} 
[node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item.block,
                    [node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item.current,
                    [node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item:hover{background-color:rgba(255, 255, 255, 0);} 
[node-id="id-99-jc0fgyqz20"]{font-size:16px;} 
[node-id="id-99-jc0fgyqz20"].cc-menu--style__line .cc-menu--item.block,
                    [node-id="id-99-jc0fgyqz20"].cc-menu--style__line .cc-menu--item.current,
                    [node-id="id-99-jc0fgyqz20"].cc-menu--style__line .cc-menu--item:hover{border-bottom-color:rgba(255, 255, 255, 0);} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item__link{color:#666666;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item.block > .cc-menu--item__link,
                    [node-id="id-99-jc0fgyqz20"] .cc-menu--item.current > .cc-menu--item__link,
                    [node-id="id-99-jc0fgyqz20"] .cc-menu--item:hover > .cc-menu--item__link{color:#E95A30;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item{background-color:#00b5ae;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item.block,
    [node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item.current,
    [node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item:hover,
    [node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item .cc-menu--item.block,
    [node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item .cc-menu--item.current,
    [node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item .cc-menu--item:hover,
    [node-id="id-99-jc0fgyqz20"].cc-menu--line-main .cc-menu--item .cc-menu--item.block,
    [node-id="id-99-jc0fgyqz20"].cc-menu--line-main .cc-menu--item .cc-menu--item.current,
    [node-id="id-99-jc0fgyqz20"].cc-menu--line-main .cc-menu--item .cc-menu--item:hover{background-color:#009892;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item .cc-menu--item__link{color:#fff;text-align:left;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item.current > .cc-menu--item__link{color:#fff;text-align:left;} 
[node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item .cc-menu--item.block > .cc-menu--item__link,
                [node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item .cc-menu--item.current > .cc-menu--item__link,
                [node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item .cc-menu--item:hover > .cc-menu--item__link,
                [node-id="id-99-jc0fgyqz20"].cc-menu--line-main .cc-menu--item .cc-menu--item.block > .cc-menu--item__link,
                [node-id="id-99-jc0fgyqz20"].cc-menu--line-main .cc-menu--item .cc-menu--item.current > .cc-menu--item__link,
                [node-id="id-99-jc0fgyqz20"].cc-menu--line-main .cc-menu--item .cc-menu--item:hover > .cc-menu--item__link{color:#fff;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item__link{justify-content:flex-start;text-align:left;} 
[node-id="id-99-jc0fgyqz20"].cc-menu--auto > .cc-menu--nav{font-size:16px;} 
[node-id="id-99-jc0fgyqz20"].cc-menu--style__line .cc-menu--nav .cc-menu--item .cc-menu--item:hover > .cc-menu--item__link{color:#fff;} 
[node-id="id-99-jc0fgyqz20"].cc-menu.cc-menu--auto__mini .item-icon-active{color:#3c3c3c!important;} 
@media only screen and (max-width:767px){[node-id="id-99-jc0fgyqz20"].cc-menu--auto .cc-menu--expand__header{display:block;} 
[node-id="id-99-jc0fgyqz20"].cc-menu--auto > .cc-menu--nav{display: none;
        opacity: 0;
        /*position: fixed;*/
        position: relative;
        z-index: 25;
        width: 100%;
        left: 0;
        top: 50px;
        height: calc(100% - 50px);
        padding: 0 10px;
        box-sizing: border-box;
        overflow: hidden;
        overflow-y: auto;} 
} 
@media only screen and (max-width: 767px){[node-id="id-99-jc0fgyqz20"] .cc-menu--item a{font-size:14px;} 
[node-id="id-99-jc0fgyqz20"]  .cc-menu--item .cc-menu--nav > .cc-menu--item a{font-size:16px;} 
[node-id="id-99-jc0fgyqz20"].cc-menu--horizontal > .cc-menu--nav > .cc-menu--item{height:30px;line-height:30px;padding:0 10px;} 
[node-id="id-99-jc0fgyqz20"].cc-menu--vertical > .cc-menu--nav > .cc-menu--item{margin:10px 0;} 
[node-id="id-99-jc0fgyqz20"].cc-menu--vertical .cc-menu--item{line-height:30px;} 
[node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item{background-color:rgba(255, 255, 255, 0);} 
[node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item.block,
                    [node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item.current,
                    [node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item:hover{background-color:rgba(37, 34, 34, 0);} 
[node-id="id-99-jc0fgyqz20"].cc-menu--style__line .cc-menu--item.block,
                    [node-id="id-99-jc0fgyqz20"].cc-menu--style__line .cc-menu--item.current,
                    [node-id="id-99-jc0fgyqz20"].cc-menu--style__line .cc-menu--item:hover{border-bottom-color:rgba(37, 34, 34, 0);} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item__link{color:#666666;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item.block > .cc-menu--item__link,
    [node-id="id-99-jc0fgyqz20"] .cc-menu--item.current > .cc-menu--item__link,
    [node-id="id-99-jc0fgyqz20"] .cc-menu--item:hover > .cc-menu--item__link{color:#E95A30;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item{background-color:#00b5ae;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item.block > .cc-menu--item__link,
                    [node-id="id-99-jc0fgyqz20"] .cc-menu--item.current > .cc-menu--item__link,
                    [node-id="id-99-jc0fgyqz20"] .cc-menu--item:hover > .cc-menu--item__link{color:#E95A30;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item{background-color:#00b5ae;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item.block,
                    [node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item.current,
                    [node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item:hover,
                    [node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item .cc-menu--item.block,
                    [node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item .cc-menu--item.current,
                    [node-id="id-99-jc0fgyqz20"].cc-menu--style__default .cc-menu--item .cc-menu--item:hover,
                    [node-id="id-99-jc0fgyqz20"].cc-menu--line-main .cc-menu--item .cc-menu--item.block,
                    [node-id="id-99-jc0fgyqz20"].cc-menu--line-main .cc-menu--item .cc-menu--item.current,
                    [node-id="id-99-jc0fgyqz20"].cc-menu--line-main .cc-menu--item .cc-menu--item:hover{background-color:#009892;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item .cc-menu--item__link{color:#fff;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--trigger i{color:#000000;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item.block > .cc-menu--item__link,
                    [node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item.current > .cc-menu--item__link,
                    [node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item:hover > .cc-menu--item__link{color:#fff;} 
[node-id="id-99-jc0fgyqz20"].cc-menu.cc-menu--auto__mini .cc-menu--trigger i{color:#000000;} 
[node-id="id-99-jc0fgyqz20"] .cc-menu--item .cc-menu--item .cc-menu--item__link{height:43px;line-height:43px;margin:0px 0;} 
} 
@media screen and (min-width: 767px){[node-id="id-99-jc0fgyqz20"].cc-menu>.cc-menu--nav>.cc-menu--item::after{content: "";
            position: absolute;
            right: 0;
            top: 0;
            height: 12px;
            bottom: 0;
            margin: auto;
            width: 1px;
            background-color: #d1d1d1;} 
[node-id="id-99-jc0fgyqz20"].cc-menu>.cc-menu--nav>:nth-last-of-type(1)::after{content: "";
            position: absolute;
            right: 0;
            top: 10%;
            height: 0px;
            bottom: 10%;
            width: 0px;} 
} 
@media only screen and (min-width: 767px){}
</style>
<div node-id="id-99-jc0fgyqz20" node-type="menu" class="cc-menu cc-menu--style__default cc-menu--horizontal cc-menu--line-main" >
            <ul class="cc-menu--nav">
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_blank" href="https://www.djbh.net/" >
                            <span class="cc-menu--item__title">
                                网络安全等级保护网
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_self" href="http://www.trimps.net.cn/" >
                            <span class="cc-menu--item__title">
                                公安部第三研究所认证中心
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_blank" href="https://www.oscca.gov.cn/sca/xwdt/2024-11/11/content_1061214.shtml" >
                            <span class="cc-menu--item__title">
                                国家密码局
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_blank" href="https://www.cacrnet.org.cn/" >
                            <span class="cc-menu--item__title">
                                中国密码学会
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_blank" href="https://wap.miit.gov.cn/" >
                            <span class="cc-menu--item__title">
                                工业和信息化部
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_blank" href="https://www.tc260.org.cn/" >
                            <span class="cc-menu--item__title">
                                全国网络安全标准化技术委员会
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_blank" href="https://www.itsec.gov.cn/" >
                            <span class="cc-menu--item__title">
                                中国信息安全测评中心
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_blank" href="https://www.china-nea.cn/" >
                            <span class="cc-menu--item__title">
                                中国核能行业协会
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_blank" href="http://www.nea.gov.cn/" >
                            <span class="cc-menu--item__title">
                                国家能源局
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_blank" href="https://www.cac.gov.cn/" >
                            <span class="cc-menu--item__title">
                                中国网信网
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_blank" href="https://www.mps.gov.cn/" >
                            <span class="cc-menu--item__title">
                                公安部
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_blank" href="http://www.sgcc.com.cn/html/sgcc_main/index.shtml" >
                            <span class="cc-menu--item__title">
                                国家电网
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_blank" href="https://www.csg.cn/" >
                            <span class="cc-menu--item__title">
                                南方电网
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    
        <li class="cc-menu--item">
            <div class="cc-menu--item__link">
                <a  target="_blank" href="http://www.chinaccia.org.cn/" >
                            <span class="cc-menu--item__title">
                                中国计算机行业协会
                            </span>
                            
                        </a>
                
            </div>
            
        </li>
    </ul></div>

<script>(function() {
    useComponent('menu').default({"id":"id-99-jc0fgyqz20","options":{"hover_show":"no","show_cur_sub":"no","retain_hover":"none","line-style-obj":"main_menu","line-style":"left","mode":"horizontal","style":"default","menu-item-repulsion":"no"}})
})()</script></div></div></div><div node-id="id-73-l98g8gplhg" node-type="row" class="cc-row cc-slot--wrapper cc-row--flex cc-row--justify__start cc-row--align__top cc-row--width__default"><script>(function() {
    useComponent('row').default({"id":"id-73-l98g8gplhg","options":{"full-width":"default","adaption-height":"no","background-video":"","noheader-full-height":"no","auto-flex":[],"auto-flex-enable":"no"}})
})()</script><div node-id="id-26-x0u8uo155d" node-type="column" class="cc-col cc-slot--wrapper cc-col--align__top cc-col--justify__start cc-col-24 cc-col-xl-24 cc-col-lg3-24 cc-col-lg2-24 cc-col-lg-24 cc-col-md-24 cc-col-sm-24 cc-col-xs-24"><script>(function() {
    useComponent('column').default({"id":"id-26-x0u8uo155d","options":[]})
})()</script><div class="cc-element--wrapper id-46-tohu3aj591--wrapper" ><div node-id="id-46-tohu3aj591" node-type="placeholder" class="cc-placeholder"  style="height:45px">
</div>


<script>(function() {
    useComponent('placeholder').default({"id":"id-46-tohu3aj591","options":[]})
})()</script></div></div></div><div node-id="id-23-kksts56wg3" node-type="row" class="cc-row cc-slot--wrapper cc-row--flex cc-row--justify__start cc-row--align__top cc-row--width__default"><script>(function() {
    useComponent('row').default({"id":"id-23-kksts56wg3","options":{"full-width":"default","adaption-height":"no","background-video":"","noheader-full-height":"no","auto-flex":[],"auto-flex-enable":"no"}})
})()</script><div node-id="id-49-oylj46y4ly" node-type="column" class="cc-col cc-slot--wrapper cc-col--align__middle cc-col--justify__start cc-col-4 cc-col-xl-4 cc-col-lg3-4 cc-col-lg2-4 cc-col-lg-4 cc-col-md-4 cc-col-sm-4 cc-col-xs-24"><script>(function() {
    useComponent('column').default({"id":"id-49-oylj46y4ly","options":[]})
})()</script><div class="cc-element--wrapper id-14-frcfmdyryc--wrapper" >
<style style-id="id-14-frcfmdyryc">
[node-id="id-14-frcfmdyryc"] .cc-textblock__body{padding: 0px;}
</style>
<div node-id="id-14-frcfmdyryc" node-type="textblock" class="cc-textblock" >
    <div class="cc-textblock__body richtext">
        <p style="line-height: 1;"><img src="/uploads/2023/07/0261e24bd4abd3ded3a729e98cfe7d42.png" width="121" height="80" /></p>    </div>
</div>

<script>(function() {
    useComponent('textblock').default({"id":"id-14-frcfmdyryc","options":[]})
})()</script></div></div><div node-id="id-35-wg3yoauow7" node-type="column" class="cc-col cc-slot--wrapper cc-col--align__middle cc-col--justify__start cc-col-18 cc-col-xl-18 cc-col-lg3-18 cc-col-lg2-18 cc-col-lg-18 cc-col-md-18 cc-col-sm-18 cc-col-xs-24"><script>(function() {
    useComponent('column').default({"id":"id-35-wg3yoauow7","options":[]})
})()</script><div class="cc-element--wrapper id-27-izcfrlotcq--wrapper" >
<style style-id="id-27-izcfrlotcq">
[node-id="id-27-izcfrlotcq"] .cc-textblock__body{padding: 0px;}
</style>
<div node-id="id-27-izcfrlotcq" node-type="textblock" class="cc-textblock" >
    <div class="cc-textblock__body richtext">
        <p style="line-height: 1.5;"><span style="font-size: 15px; color: #666666;">总部地址：北京市海淀区宝盛南路1号院26号楼领智中心A座6层（100192） </span></p>
<p style="line-height: 1.5;"><span style="font-size: 15px; color: #666666;">电话：010-60605180、60605185</span></p>
<p style="line-height: 1.5;"><span style="font-size: 15px; color: #666666;">版权所有2025&copy; &nbsp;北京卓识网安技术股份有限公司 &nbsp; | &nbsp; <a href="https://beian.miit.gov.cn/#/Integrated/index" target="_blank" style="color: #666666;" rel="noopener">京ICP备19035388号-1</a> &nbsp; | &nbsp; <a href="https://beian.mps.gov.cn/#/query/webSearch?code=11010802034101" target="_blank" style="color: #666666;" rel="noopener">&nbsp;<img src="/uploads/2023/07/090f7f4688c97a900176bd60820a598c.png" /> 京公安备11010802034101号</a></span></p>    </div>
</div>

<script>(function() {
    useComponent('textblock').default({"id":"id-27-izcfrlotcq","options":[]})
})()</script></div></div><div node-id="id-72-bs8omln2sq" node-type="column" class="cc-col cc-slot--wrapper cc-col--align__top cc-col--justify__start cc-col-2 cc-col-xl-2 cc-col-lg3-2 cc-col-lg2-2 cc-col-lg-2 cc-col-md-2 cc-col-sm-2 cc-col-xs-24"><script>(function() {
    useComponent('column').default({"id":"id-72-bs8omln2sq","options":[]})
})()</script><div class="cc-element--wrapper id-10-c60fkooz6k--wrapper" >
<style style-id="id-10-c60fkooz6k">
[node-id="id-10-c60fkooz6k"] .cc-textblock__body{padding: 0px;}
</style>
<div node-id="id-10-c60fkooz6k" node-type="textblock" class="cc-textblock" >
    <div class="cc-textblock__body richtext">
        <p style="line-height: 1;"><img src="/uploads/2023/07/635e3eff615df2b114a44baccb81ce60.png" width="137" height="134" style="display: block; margin-left: auto; margin-right: auto;" /></p>
<p style="text-align: center; line-height: 1;"><span style="font-size: 14px; color: #666666;">微信公众号</span></p>    </div>
</div>

<script>(function() {
    useComponent('textblock').default({"id":"id-10-c60fkooz6k","options":[]})
})()</script></div></div></div><div node-id="id-87-os5xo9h5u8" node-type="row" class="cc-row cc-slot--wrapper cc-row--flex cc-row--justify__start cc-row--align__top cc-row--width__default"><script>(function() {
    useComponent('row').default({"id":"id-87-os5xo9h5u8","options":{"full-width":"default","adaption-height":"no","background-video":"","noheader-full-height":"no","auto-flex":[],"auto-flex-enable":"no"}})
})()</script><div node-id="id-13-rgqamine5c" node-type="column" class="cc-col cc-slot--wrapper cc-col--align__top cc-col--justify__start cc-col-24 cc-col-xl-24 cc-col-lg3-24 cc-col-lg2-24 cc-col-lg-24 cc-col-md-24 cc-col-sm-24 cc-col-xs-24"><script>(function() {
    useComponent('column').default({"id":"id-13-rgqamine5c","options":[]})
})()</script><div class="cc-element--wrapper id-22-tfv57gyl38--wrapper" ><div node-id="id-22-tfv57gyl38" node-type="placeholder" class="cc-placeholder"  style="height:45px">
</div>


<script>(function() {
    useComponent('placeholder').default({"id":"id-22-tfv57gyl38","options":[]})
})()</script></div></div></div></div></div></div></div></div>
            

  
        </div>
            
        <div class="Page-widgets">
          
            
        <div class="side-toolbar position-right-bottom">
    <ul>
                <li>
            <div class="toolbar-icon
                "
                            >
                <a  target="_self" title="在线留言" href="javascript:_utils_.handler(JSON.parse(decodeURIComponent('%7B%22action%22%3A%22open%22%2C%22options%22%3A%7B%22bg_color%22%3A%22%23fff%22%2C%22min_height%22%3A%22200%22%2C%22target%22%3A%22_blank%22%2C%22close%22%3A%221%22%2C%22autoPlay%22%3A%220%22%2C%22template_id%22%3A%2236%22%2C%22width%22%3A%22%22%2C%22url%22%3A%22https%3A%5C%2F%5C%2Ftd91msdq7z.jiandaoyun.com%5C%2Ff%5C%2F5e3d046d3ac9f300062af7fe%22%7D%7D')));" ><img  src="data:image/svg+xml;utf8,<svg xmlns='http://www.w3.org/2000/svg' width='10' height='10'></svg>" class=" async-load" data-src="https://www.enst.org.cn/uploads/2024/11/5defd0ba7eae1bd63b158d9753944472.png" /></a>            </div>

                            <div class="toolbar-img ">
                    <img  src="data:image/svg+xml;utf8,<svg xmlns='http://www.w3.org/2000/svg' width='10' height='10'></svg>" class=" async-load" />                </div>
                    </li>
                <li>
            <div class="toolbar-icon
                "
                            >
                <a  target="_self" href="javascript:_utils_.handler(JSON.parse(decodeURIComponent('%7B%22action%22%3A%22backtop%22%2C%22options%22%3A%7B%22bg_color%22%3A%22%23fff%22%2C%22min_height%22%3A%22200%22%2C%22target%22%3A%22_self%22%7D%7D')));" ><img  src="data:image/svg+xml;utf8,<svg xmlns='http://www.w3.org/2000/svg' width='10' height='10'></svg>" class=" async-load" data-src="/uploads/2023/07/f5a06d2a016796fa8bc0124b9d43f9c8.png" /></a>            </div>

                            <div class="toolbar-img ">
                    <img  src="data:image/svg+xml;utf8,<svg xmlns='http://www.w3.org/2000/svg' width='10' height='10'></svg>" class=" async-load" />                </div>
                    </li>
            </ul>
</div>
        </div>
    </div>
</div>
<script class="custom-js-code">
(function() {
    var custom_js_code = 
    []
    for ( var i = 0; i < custom_js_code.length; i++ ) {
        var code = custom_js_code[i].code
        var title = custom_js_code[i].title
        _utils_.sandbox(code, title)
    }
})();
</script>

</body>
</html>
