w3pwnz

{ w3pwnz, therefore we are }

recherche

To content | To menu | To search

CTF › Prequals ndh2k12

NDH2k12 Prequals - Debriefing

home.pngThis year challenges were organized an unusual way: we were some hax0rz hired by a company to complete some tasks they asked for, rewarded by money. Thus it was storyline, quite messy, hence the following tree, trying... lire la suite

NDH2k12 Prequals - New email from our

From: Jessica To: w3pwnz Subject: New email from our contact Attachments : executable2.ndh Thank you again for your help, our technical staff has a pretty good overview of... lire la suite

NDH2k12 Prequals - What is it about this

soundmail.pngThe cover document was a song from the Blues Brothers, "Rawhide". The title suggests that the method used is simple. This was indeed one of the most straightforward challenges: take the lsb from every frame, and you're... lire la suite

NDH2k12 Prequals - unknown binary, need

From: Jessica To: w3pwnz Subject: unknown binary, need your help Attachments : executable1.ndh Hello again, Thank you very much for your help. It is amazing that our... lire la suite

NDH2k12 Prequals - We are looking for a

UnknownZipArchive.pngFile sp112.rar The rar file is password protected => Let’s try to crack it... Open Advanced Archive Password Recovery and launch a dictionary attack : After some hours or some minutes depending on your dictionary, the... lire la suite

NDH2k12 Prequals - Another weird link -

From: Piotr To: w3pwnz Subject: Another weird link Attachments : web3.ndh Thank you again for these informations! we have just credited your account with $1700. Our spy... lire la suite

NDH2k12 Prequals - Any idea how to use

ndh_webapp_hdrAfter decrypting the secret message, we got a new email, from Piotr this time, a supposed technical operative. From: Piotr To: w3pwnz Subject: Any idea how to use this file?... lire la suite

NDH2k12 Prequals - We are looking for a

WallpaperImage.pngThe bmp file has no padding bytes, and its size matches the image dimensions (4374054 = 810*1800*3 +0x36 for the header). On the other hand, applying an LSB filter reveals that something is wrong on the left side of the... lire la suite

NDH2k12 Prequals - We are looking for a

UnknownText.pngFile sp111 After opening the sp111 text file, we guessed that it was encrypted with vigenere. We tried an auto-decrypt with http://www.apprendre-en-ligne.net/crypto/vigenere/decryptauto.html, revealing that... lire la suite

NDH2k12 Prequals - What is it about this

BinaryFileNdh.pngFile: 11925.ndh Once again it is a VM file. We quickly take a look at the hexdump to find the remote port used (4004). % tail 11925.ndh|hexdump -C 00000000 00 16 b7 0e 00 02 02 04 00 00 02 03 04 03 03 03... lire la suite

NDH2k12 Prequals - New email from our

Newemailfromourcontact.pngAccording to the description http://sci.nuitduhack.com was a url shortening service. After searching about how these services work i found two “common” practises. The first was inserting urls in the database and then... lire la suite

NDH2k12 Prequals - What is it about this

MoleInformation.pngIn the sp113.pdf found in the bitmap “Wallpaper image”, we can see “author: SciteekSmith”. Google is our friend : http://lmgtfy.com/?q=SciteekSmith There is 1 result : http://www.facebook.com/SciteekSmith... lire la suite

- page 1 of 2

© w3pwnz - 2012

Licence Creative Commons
Ce(tte) œuvre est mise à disposition selon les termes de la Licence Creative Commons Attribution - Pas d’Utilisation Commerciale - Pas de Modification 3.0 France.