Saturday 31 August 2013

ASIS CTF 2013 - Forensics 25 - spcap

Task:
spcap = simple pcap
Find the flag. flag

 This has to be simple network forensics task as the title says. Let's look at the protocols hierarchy at the wireshark to detect something interesting.
There is nothing interesting except JPEG image is being transferred. Let's go to File -> Export -> Objects -> HTTP and look at files. There is a file called flag.jpg, save it to your filesystem and open.
This picture contains the flag.

P.S. Also look at NetworkMiner which is a wonderful utility to get files and images from pcap files.

No comments:

Post a Comment