> For the complete documentation index, see [llms.txt](https://ravins-organization.gitbook.io/ctf-writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ravins-organization.gitbook.io/ctf-writeups/2024/blahajctf-2024/rev/unsafe-pdf.md).

# Unsafe PDF

They've put javascript in my PDF!! Get it out of there!!!  Files available here  Author: @scuffed

By putting the pdf given into Cyberchef, we can see that there is some javascript in the PDF<br>

<figure><img src="https://175444261-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyxEI13wXOyST4LLTOUiS%2Fuploads%2Fyrzl1jexFTI0mgXnNrHM%2Fimage.png?alt=media&amp;token=6533ccef-0ddf-424d-84db-9d2bfed0946d" alt=""><figcaption><p>Some very cool JS script</p></figcaption></figure>

So since its a reverse chall, we have to reverse engineer this to get back the original flag.&#x20;

Thus by creating this script, we are able to obtain the flag

```python
grass = [
    39, 199, 20, 133, 19, 174, 186, 16, 102, 83, 172, 147, 207, 223, 81, 237, 
    78, 237, 209, 58, 38, 92, 38
]

def reverse_world(a):
    return ((a & 0xf) << 4) + (a >> 4)

def space(n):
    a = 0
    b = 1
    o = []
    for i in range(n):
        c = a + b
        a = b
        b = c
        o.append(a % 256)
    return o

def decode_flag(grass):
    fib_sequence = space(len(grass))
    flag = []
    for i in range(len(grass)):
        decoded_char = grass[i] ^ fib_sequence[i]
        reversed_char = reverse_world(decoded_char)
        flag.append(chr(reversed_char))
    return ''.join(flag)

decoded_flag = decode_flag(grass)
print(f"Decoded Flag: {decoded_flag}")
```

After running this, we obtain `Decoded Flag: blahaj{PDF_0bj3c7_HuN7}`, thus the flag is `blahaj{PDF_0bj3c7_HuN7}`
