Saturday, 24 June 2017

TrendMicroCTF 2017 - Forensics100

After a long time looking playing ctf's and here's my solution for forensics - 100 .

As i don't have access to the challenges. I'll try explaining the question as much as i can.

Question  : 
There is a pcap given and said that hackers used an old technique to communicate to the server from victim machine.

Link to file : Forensics100

Solution : 
As we look at the pcap using our trade of tool "Wireshark". It shows that its all DNS query and response.

The only strings changing is the dns query values like:  ASfsbGivEQsT2aQPHzaB.gzpgs.trendmicro.co.jp
5GBJZEAWX7WJASGCg5Br.gzpgs.trendmicro.co.jp
9TvJjPCj9kRW9fk5XU2b.gzpgs.trendmicro.co.jp
etc.,

so i used tshark to extract all the 255 values and dump it into for100.txt as below:

tshark  -r  output.pcap  -T  fields  -e  ip.src  -e  dns.qry.name  -Y  "dns.flags.response eq 0" | awk '{print $2}'  |  tr  -d  "gzpgs.trendmicro.co.jp \n"  >  for100.txt

Now interesting is that if we look at the total characters in the file using awk and sort and uniq we find that its 58 characters and not 64 to guess it as base64 encoding

I used the below command to find the total characters :

awk 'BEGIN{FS=""}  {for(i=1;i<=NF;i++)  print $(i) ; } ;'  for100.txt  |  sort |  uniq |  tr -d '\n' 
output : 123456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz

Now all that is left is to find the base58 decoder. On googling i found a website : 
base58-decode

And finally decoding we get the flag in the end as "TMCTF{DNSTunnelExfil}"

w00t w00t!!

Sunday, 21 February 2016

Internetwache CTF 2016 Quick Run

Question :

Solution :

Link to the file inside zip : https://app.box.com/s/8aoepmqzfetr2syj9usq433kptaz8nid 

I just tried Base64 on it due to the padding "==" in the texts. and i found QR codes on each block of texts


Hence , decoding which gives us :

Flag is IW{QR_C0DES_RUL3}



FLAG : IW{QR_C0DES_RUL3}


Internetwache CTF 2016 The hidden message

Question :

Solution :

The README.txt inside the zip file had contents :

0000000 126 062 126 163 142 103 102 153 142 062 065 154 111 121 157 113
0000020 122 155 170 150 132 172 157 147 123 126 144 067 124 152 102 146
0000040 115 107 065 154 130 062 116 150 142 154 071 172 144 104 102 167
0000060 130 063 153 167 144 130 060 113 012
0000071

Looking at the numbers its clear that its a octal system. Converting from octal to ascii gives us :

"V2VsbCBkb25lIQoKRmxhZzogSVd7TjBfMG5lX2Nhbl9zdDBwX3kwdX0K"

Decoding the above Base64 string gives us :

Well done!

Flag: IW{N0_0ne_can_st0p_y0u}


FLAG : IW{N0_0ne_can_st0p_y0u}

Internetwache CTF 2016 Crypto-Pirat

Question :

Word of Caution : Highly frustrating challenge due to multiple encryption,encoding etc,. :-p

Attachment : crypto50.zip

Solution :
Attachment has a README.txt which has :

♆♀♇♀♆ ♇♇♀♆⊕ ♇♀♇♀♆ ♇♆♇♆⊕ ♆♇♆♇♇ ♀♆♇♆⊕ ♆♇♆♇♆ ♇♆♇♆⊕ ♆♇♇♀♇ ♀♆⊕♇♀ ♆⊕♇♀♆ ⊕♆♇♆♇ ♇♀♆♇♆ ⊕♇♀♇♀ ♆⊕♆♇♆ ♇♆♇♇♀ ♆⊕♆♇♆ ♇♆♇♆⊕ ♆♇♆♇♆ ♇♆⊕♇♀ ♆♇♇♀♆ ♇♆⊕♇♀ ♆♇♆♇♇ ♀♆⊕♆♇ ♆♇♇♀♇ ♀♇♀♆⊕ ♆♇♆♇♇ ♀♆⊕♇♀ ♇♀♆♇♆ ⊕♆♇♇♀ ♆⊕♇♀♆ ♇♇♀♇♀ ♆⊕♆♇♆ ♇♆♇♆♇ ♆⊕♇♀♆ ♇♇♀♆♇ ♆⊕♇♀♆ ♇♆♇♇♀ ♆⊕♆♇♆ ♇♇♀♇♀ ♇♀♆⊕♇ ♀♆♇♆♇ ♆⊕♇♀♇ ♀♇♀♆⊕ ♇♀♇♀♆ ♇♆♇♆⊕ ♆♇♆♇♆ ♇♆⊕♆♇ ♇♀♇♀♆ ⊕♆♇♆♇ ♆♇♆♇♇ ♀♆⊕♇♀ ♇♀♆♇♆ ♇♆⊕♆♇ ♆♇♆♇♇ ♀♇♀♆⊕ ♆♇♆♇♆ ♇♆⊕♆♇ ♇♀♆♇♆ ♇♆⊕♆♇ ♆♇♆♇♆ ♇♆♇♆⊕ ♆♇♇♀♇ ♀♆⊕♇♀ ♇♀♆♇♆ ⊕♆♇♆⊕ ♆♇♆♇♇ ♀♇♀♇♀ ♆⊕♇♀♆ ♇♇♀♆♇ ♆⊕♇♀♇ ♀♆♇♆♇ ♆♇♆⊕♇ ♀♆♇♆⊕ ♇♀♇♀♆ ♇♆♇♆⊕ ♆♇♆♇♆ ♇♆⊕♇♀ ♆♇♆♇♇ ♀♆⊕♆♇ ♆⊕♇♀♇ ♀♇♀♆⊕ ♆♇♇♀♆ ♇♆⊕♆♇ ♇♀♇♀♇ ♀♆⊕♆♇ ♇♀♇♀♆ ♇♆⊕♆♇ ♆♇♇♀♆ ⊕♇♀♆♇ ♆♇♆♇♇ ♀♆⊕♇♀ ♆♇♆♇♆ ♇♇♀♆⊕ ♇♀♆♇♆ ♇♆♇♇♀ ♆⊕♇♀♆ ♇♆♇♆♇ ♇♀♆⊕♇ ♀♆♇♆♇ ♆♇♇♀♆ ⊕♇♀♆♇ ♆♇♆♇♇ ♀


Internetwache CTF 2016 Replace with Grace

Question:

Service : https://replace-with-grace.ctf.internetwache.org/

Solution :

The webpage had 3 parameters : search,replace and content

An example would be :
search : /cow/
replace : cat
content : cows are cute

output : cats are cute.

As the webpage uses php, I googled for php search and replace regex

Now I was clear that it uses preg_replace function. Searching for flaws in preg_replace I found that it is prone to command execution using the modifier "e"

Internetwache CTF 2016 0ldsk00lBlog

Question :

Service : https://0ldsk00lblog.ctf.internetwache.org/

Solution :

As the blog shows that "All people are talking about a tool called 'Git'. I think I might give this a try." , which leaves us a hint and lets check whats in "https://0ldsk00lblog.ctf.internetwache.org/.git/"

"403 Forbidden" , which means directory exists but cannot be accessed.

So now after reading through this wonderful website anyone would understand the git directory structure.

Having said that now , I went through couple of writeups on similar challenges and found a useful tool called dvcs-ripper , which can find us all the commits and check if the directories in .git is accessbile like logs,config,objects etc,.

Internetwache CTF 2016 TexMaker

Question :

Service : https://texmaker.ctf.internetwache.org/


Solution :
The webpage gives you to program a latex and create a pdf .

After a bit of searching for latex hacks I found the guide

http://cseweb.ucsd.edu/~hovav/dist/texhack.pdf

Well, this has a amazing article on how to use latex for malicious purpose. I went through usual approach of using \input{"ls"} as we have no clue where is the file is and what the file extension is for the flag.

we see "BLACKLISTED commands cannot be used."

I saw few evading techniques that can be used by following the above article like
\csname \begin \@@ ^^5C \cat_code , No luck though.

Lets change the view, search for commands that can execute us the shell commands.

After a bit of digging i finally found this command was not BLACKLISTED and that is \write18
which is also called shell-escape.

http://tex.stackexchange.com/questions/16790/write18-capturing-shell-script-output-as-command-variable

It was simple after to use \write18{ls ../}

and \write18{cat ../flag.php}


FLAG : IW{L4T3x_IS_Tur1ng_c0mpl3te}

Sunday, 7 February 2016

Monday, 1 February 2016

Hackim 2016 Forensics-200

Its been long playing CTF. Am back again.


Question :

Hint : Forensics2 - Ext4 or btrfs …… err I forgot

File : f200

Tools :
FiletypeID , network miner , mount command , online sha512 hash generator. arj ,arc

Monday, 13 October 2014

ASIS CTF 2014 Recon - Fact or Real


First thing which came to my mind id twitter.So i checked ASIS twitter handle. Later i found that usually a guy named factoreal is the main guy in hosting asis-ctf.When you check his twitter photos there you go,you see the given hint "fact or real" and the motto in the picture : "NO+$=YES"



Flag is ASIS_md5(NO+$=YES)

FLAG : ASIS_d25b9c2f1c29e49e81e8fdfaf4d16fc6

Monday, 12 May 2014

ASIS Quals 2014 Trivia-50 [ Image ]

Sorry, Been long time writing writeups. Exams and project work.Well, had no time for ASIS also.pwned only 1 challenge.Next is defcon and i promise ill write more writeups.Stay updated.

Question : Find the flag.
Description : File


Solution :

Step 1 : Download the file joy_50_25b927e48a23a4b41f215303ca988a01

Step 2 : using " http://mark0.net/onlinetrid.aspx " find the file type.

Step 3 : using 7zip software we can extract .xz as it is one of the compression algorithms like .zip or .tar etc.

Step 4 : repeat step 2 and step 4 as its double packed (.xz + .tar).

Step 5 : repeat step 2 and see that its a .NES file which is Nintendo entertainment system file.For more info see the wiki page

Step 6 : Find a appropriate emulator to run the game. I used fceux emulator . find it here " http://www.fceux.com/web/download.html "

Step 7 : Play the game and pass the level 1 to get the flag in level 2

Step 8 : You see this in level 2 " Flag : 8 BIT RULES"



Admins had posted to ping about this question.They told that the flag is actually 8BIT_RULEZ if you had got till here correctly.

FLAG : 8BIT_RULEZ

NOTE : you actually don't have to play the game.Start with stage 1 and press F10 you would see this saved state :-)  . Dont know how many found this , but this is an easier way of it :-D

Saturday, 5 April 2014

Nuit de Hack Quals - 2014 Carbonara

This was easy and i actually over thought it..
Question :

the ciphertext was : "%96 7=28 7@C E9:D 492= :D iQx>A6C2E@C xF=:FD r26D2C s:GFDQ]"

My first approach:
substitution by looking at asciitable.com

":" - "i"
"D" - "s"

after which with the help of this (which i just guessed as it was a 2 letter string and my guess was it would be "is")
decoding which i got
THE FLAG FOR THIS CHAL IS "iMPERATOR jULIUS cAESAR dIVUS"
i was stuck with the letter x actually..Later my friend told that it was a rot-47 :-D all my work in vain..i got the string as :
The flag for this chal is :"Imperator Iulius Caesar Divus".

Flag : Imperator Iulius Caesar Divus 

Nuit de Hack Quals -2014 Here Kitty Kitty!

Not much flags this time too..Managed to get 3 of them and will write however i got it.
Question:
Mirror Link : http://1drv.ms/1jjplOH

So well first thing we would think of is audacity.Lets try our luck..You get a weird waveform.I just zoomed in to see the waveform.I got a view of Morse code,before which i thought it was a binary . Dont zoom in much coz you would over think as binary numbers.It would look like this :

Note down accordingly and you would get this Morse code

..... -... -.-. ----. ..--- ..... -.... ....- ----. -.-. -... ----- .---- ---.. ---.. ..-. ..... ..--- . -.... .---- --... -.. --... ----- ----. ..--- ----. .---- ----. .---- -.-.

Decoding which will give a md5 hash : 5BC925649CB0188F52E617D70929191C
As the flag was case sensitive and was lowercase so the flag would be : 5bc925649cb0188f52e617d70929191c

Flag : 5bc925649cb0188f52e617d70929191c

Sunday, 30 March 2014

Volga CTF 2014 Quals Joy-300

This was just a replica of flappy bird game.

Question was in short "Autopilot mode isn't working and the rocket is unable to reach the destination point.reach the destination point for the message(42level)" [Not exact but it meant this]

Well i thought of reversing the game and figured it was written in Delphi and used the Delphi dissasembler also.But just as a confirmation i asked people whether the task was just to reach 42nd level? I got a reply saying "Yes" .Ah perfect timing for showing my flappy bird skills. Bwah it was just 42 level.Piece of cake i thought. But its not easy playing with keboard. Check it yourself.Download the game using the link below.
The game given

After so many attempts i reached 42 level and got this :

Ah observe that at level 42 i crashed :-D This is pure luck :-D

FLAG : it_was_not_so_hard_rrly

Volga CTF 2014 Quals Web-100

Well,It was very hard to solve challenges frankly speaking.We were well prepared for the CTF but was in vain.

The question was to find the hidden flag in their webpage (http://tasks.2014.volgactf.ru:28101/)

Note: [Server is down so cannot fetch the exact question.Sorry about that]

I really have no clue about web challenges as i am not the guy at all.But i know the basics.Hence as a challenge with blank mind i just looked at the login page

I just logged in.I saw this.

Monday, 24 March 2014

Backdoor CTF 2014 Misc-150

First i thought it was like Defkthon's zip challenge..Wrote script and it went wrong. :-p

Question :
This wierd file was found by H4XOR when trying to search for his flags. Can you get him his flag ?


Submit flag as flag_obtained


After 6 times unzipping you would get a file called Misc150. A quick file command tells this :

So its time for mounting now.
Command : mount -t ext2 Misc150 ../../../mnt/image -o loop 
Note: file path is different for you.Adjust it accordingly.


Backdoor CTF 2014 Misc-200-2

This was an awesome challenge and we solved it in a different way.It was fun solving this challenge.We knew that using python we can code this.But we were almost getting the flag when we realized that.

Question :
Username and password based login seemed a bit too monotonous. We developed an indigenous image based login system.

The login service is available here.

The image below can be used to login as the backdoor user. Unfortunately that doesn't serve any purpose.
Login as the sdslabs user for a change.


Submit the flag as: md5(flag_obtained)

Before we got in we loaded the image and saw how it would look like..

So our first approach was paint and look what we found..
So we tried figuring out logic for this coz when we took out the last dot we were getting " Logged in as backdoop"
After which my friend figured out the logic.
01100010 -b
01100001 -a
01100011 -c
01101011 -k
01100100 -d
01101111 -o
01101111 -o
01110010 -r

01110011 -s
01100100 -d
01110011 -s
01101100 -l
01100001 -a
01100010 -b
01110011 -s

Black dot was 1 and the space or blank is 0..This is how we figured it out.
We used colorfiller and filled out accordingly what sdslabs would look like and when put in paint and seen it would look like this.
"Logged in as sdslabs
Congrats the flag is practice_makes_one_perfect"

md5("practice_makes_one_perfect") => c16a3c8504985a8c91956c29f7338184

FLAG : c16a3c8504985a8c91956c29f7338184

Saturday, 22 March 2014

Backdoor CTF 2014 Binary-10

Just a basic skill of viewing the strings of files is required.

Question :
Information Security Agency uses preshared passwords for sending senstive information to its agents.

Somehow we managed to know that one such piece of sensitive information exists in this file.
File : http://1drv.ms/1lCxm3N

Submit the flag as flag_obtained


FLAG : 40511702a6193f9b38d37699e676fd40

Backdoor CTF 2014 Web-10

Got help from a teammate..He did it actually.Just learnt it so thought of sharing.Am not a web guy moreover.

Question :
H4x0r is a curious guy. He normally looks into every detail around. H4x0r managed to find the flag of this level. Can you ?

Looking at the http headers gave us the flag:

FLAG : 28b3324be8b003ee7e1d0d153fad3c32

Backdoor CTF 2014 Crypto-10

Just cracked this in seconds..Have a very good experience with these kind of stego's.

Question :
H4x0R recently went missing. An investigating team specializing in hacking was deployed to search around his place. All they found was this file. Please help them obtain secret 32characters string that can lead to him

Submit the flag as: flag_obtained
Image given :


So the below image says ther is a image inside this image.How to extract? just rename the jpg to rar and extract it you would see a image.