arrow-left

All pages
gitbookPowered by GitBook
1 of 6

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Spy Cam

Open the pcap in wireshark, some TCP packets have a long length. Once converting the hexdump of these to an image, you'll eventually get the flag of:

hashtag
Flag: flag{i_spy_with_my_little_eye}

Mercury

good ol' strings + grep

hashtag
Flag: flag{version_control_for_the_solar_system}

Amnesia

Download file, run volatility for profile, install chromehistory plugin, run it on file and flag.

hashtag
Flag: flag{forensic_cookie_huntet}

Mobility

Used apkstudio, had a look in MainActivity.smali, saw an array which seemed to have chars in the ascii range, so decoded those and got the flag.

hashtag
Flag: flag{classic_apk_decompile_shenanigans}

Patchwork Quilt

We're provided with a download of the VScode source code, slightly modified. The name hinted at a patch happening, so I ran git diff and found a 'backdoor' leading to congonator.me/?id=ZmxhZ3tkb250X3RydXN0X2RvZGd5X2Rvd25sb2Fkc30%3D&key= when a key was pressed. I just decoded the id paramater, which revealed the flag.

hashtag
flag{dont_trust_dodgy_downloads}

Forensics