competition-zip-archive skill
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for ZIP and PKZIP archive challenges, legacy ZipCrypto identification, known-plaintext recovery with bkcrack, key-based decryption, and reproducible extraction. Use when the user asks to solve an encrypted ZIP challenge, inspect ZipCrypto metadata, recover keys from a known file prefix, or unlock an archive without starting with password brute force. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
Is the competition-zip-archive skill safe?
Clean: nothing in its files matched our rules. We read 3 files in the folder on 2026-09-28.
No findings.
Install the competition-zip-archive skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git /tmp/reverse-skill mkdir -p ~/.claude/skills cp -r /tmp/reverse-skill/CTF-Sandbox-Orchestrator/competition-zip-archive ~/.claude/skills/competition-zip-archive
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Competition ZIP Archive
Use this skill only as a downstream specialization after $ctf-sandbox-orchestrator is active and has established sandbox assumptions, evidence priorities, and the analysis project root. If that has not happened yet, return to $ctf-sandbox-orchestrator first.
Use this skill when the decisive path is an encrypted ZIP/PKZIP archive rather than an upload parser or a generic crypto blob. Prefer the legacy ZipCrypto known-plaintext path when the challenge gives a predictable file, format header, template, or other recoverable plaintext. Do not begin with blind password brute force.
Reply in Simplified Chinese unless the user explicitly requests English. Keep commands and tool output in their original form.
Quick Start
- Preserve the original archive, compute a hash, and work on a copy under the analysis project's work// directory.
- Confirm the actual archive format and list entries before attempting a password attack.
- Determine whether the entry uses legacy ZipCrypto. bkcrack does not recover WinZip AES or other modern encryption.
- Build an exact known-plaintext candidate. The attack needs at least 12 known plaintext bytes, including at least 8 contiguous bytes.
- Recover the internal keys with bkcrack, then create an unencrypted copy and extract it.
- Preserve the command, entry names, known-plaintext source, recovered keys, output hash, and final flag as evidence.
Tool Setup
Use the normal tool index and bootstrap path before guessing an executable location:
powershell -NoProfile -ExecutionPolicy Bypass -File skills/scripts/refresh-tool-index.ps1
powershell -NoProfile -ExecutionPolicy Bypass -File skills/scripts/bootstrap-reverse.ps1 -Capability bkcrackOn Kali, use the equivalent capability command:
bash kali/scripts/bootstrap-reverse.sh bkcrackThe Windows capability is pinned to the v1.8.1 release and verifies the GitHub asset digest. If the tool is installed manually, refresh skills/tool-index.md afterward.
Workflow
1. Establish Archive Truth
Keep the original immutable and record:
sha256sum challenge.zip
file challenge.zip
bkcrack -L challenge.zipOn Windows, use Get-FileHash in place of sha256sum. bkcrack -L shows entry names, compression methods, and encryption status. Do not infer the encryption type from the .zip extension alone.
Check the entry that will provide the known plaintext. A useful candidate is a stored or otherwise predictable file such as a PNG, PDF, text template, or challenge-generated configuration. A local ZIP header (PK\x03\x04) is metadata for the archive entry, not plaintext inside the encrypted member, so it is not by itself a useful known-plaintext sample.
2. Recover Keys With Known Plaintext
When the ciphertext entry is flag.txt and a matching plaintext entry is available in known.zip:
bkcrack -C challenge.zip -c flag.txt -P known.zip -p flag.txtFor raw ciphertext and plaintext files:
bkcrack -c cipherfile -p plainfileThe plaintext must match the bytes represented in the encrypted entry. If the entry was deflated, an uncompressed copy of the file is not automatically the right input; use a matching ZIP fixture or the exact compressed bytes.
If the known bytes begin at an offset, add -o . If only 8-11 bytes are contiguous, combine them with other known bytes using sparse hints:
bkcrack -c cipherfile -p plainfile -x 25 4b4f -x 30 21The successful run yields three internal ZipCrypto keys. Record them exactly as printed; they are not the original password.
3. Unlock And Validate
Use the recovered keys to make a new archive, leaving the source untouched:
bkcrack -C challenge.zip -k K0 K1 K2 -D unlocked.zip
7z t unlocked.zip
7z x unlocked.zip -ounpackedReplace K0 K1 K2 with the hexadecimal values printed by bkcrack. Validate the output with the archive test command and a hash or exact flag comparison. If only one raw member is needed, -d can write its deciphered bytes; deflated raw data may need the inflate.py helper shipped with bkcrack.
4. Re-route When Preconditions Fail
- WinZip AES or another modern encryption mode: stop this path and identify the challenge-specific primitive.
- No reliable known plaintext: inspect filenames, metadata, compression choices, challenge source, and other entries before considering password recovery.
- Known plaintext shorter than the requirement: locate more contiguous bytes or use evidence-backed sparse offsets.
- The problem is an application upload/parser chain: hand off to $competition-file-parser-chain.
- The problem is a generic ciphertext or custom cipher after archive extraction: hand off to $competition-crypto-mobile.
Evidence To Preserve
- Original and working-copy paths plus SHA-256 hashes
- bkcrack -L output and the selected encrypted member
- Exact plaintext fixture, compression method, offsets, and sparse byte hints
- Key recovery command and the three recovered internal keys
- unlocked.zip validation output, extraction path, and final artifact hash
Read references/zip-archive.md for the decision table and evidence checklist.
More skills from zhaoxuya520/reverse-skill
- Fapi-securityUse for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.
- Capk-reverse在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native 分析。优先使用本机已安装的 jadx、apktool、frida、adb、ida-reverse、radare2。
- Cattack-chainUse for authorized multi-stage attack-path planning and orchestration when a task spans reconnaissance, initial access, privilege escalation, lateral movement, or impact assessment. Route single-stage tasks directly to their specialist skill.
- Abinary-diff跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。 核心方法:用 LLM 做结构化差异比对,程序化输入输出,成本极低(200 函数 ~1 元)。 触发关键词:符号迁移、bindiff、跨版本、PDB 缺失、函数偏移迁移、symbol migration、binary diff、版本对比。
- Abinary-ninja-reverseUse for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection, strings/imports/exports, cross-references, types, patch review, Python API automation, and optional Binary Ninja MCP or localhost HTTP integration.
- Abrowser-automation统一自动化入口。覆盖浏览器自动化(Playwright)和 Windows 桌面应用自动化(OpenReverse)。 浏览器场景:打开网页、点击、填表、爬取、截图、自动化登录、渗透页面交互。 桌面场景:操作 IDA/x64dbg 等 GUI 工具、Windows UI Automation、视觉驱动交互、桌面应用网络抓包。 触发关键词:浏览器自动化、桌面自动化、打开网页、填表、爬取、截图、自动化登录、Playwright、agent-browser、headless、OpenReverse、UIA、CUA、桌面操作、Windows 自动化。
- Abrowser-extension-reverseUse for authorized reverse engineering of browser extensions (Chrome/Firefox) including manifest analysis, background workers, and extension-based credential or traffic logic recovery.
- Acase-reviewReviews a reverse-skill case package for scope readiness, Evidence to Finding to Path traceability, work item coverage, timeline references, and optional artifact hash integrity before report handoff.
- Acloud-k8sUse for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
- Acode-auditUse for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.
- Acompetition-ad-certificate-abuseInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AD CS, certificate templates, enrollment rights, EKUs, SAN controls, PKINIT, certificate mapping, and cert-based privilege paths. Use when the user asks about ESC-style abuse, certificate templates, enrollment agents, EKUs, SAN or subject controls, smartcard or PKINIT logon, CA policy, or how an issued cert turns into accepted privilege. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
- Acompetition-agent-cloudInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AI-agent, prompt-injection, MCP or toolchain, cloud, container, CI/CD, and supply-chain challenges. Use when the user asks to analyze prompt-to-tool flows, retrieval poisoning, mounted secrets, deployment drift, runtime-vs-manifest mismatches, registry provenance, or CI-produced artifacts under sandbox assumptions. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.