w3pwnz

{ w3pwnz, therefore we are }

recherche

To content | To menu | To search

Tag - prequals

NDH2k12 Prequals - New email from our

From: Jessica To: w3pwnz Subject: New email from our contact Attachments : executable2.ndh Thank you again for your help, our technical staff has a pretty good overview of... lire la suite

NDH2k12 Prequals - unknown binary, need

From: Jessica To: w3pwnz Subject: unknown binary, need your help Attachments : executable1.ndh Hello again, Thank you very much for your help. It is amazing that our... lire la suite

NDH2k12 Prequals - Another weird link -

From: Piotr To: w3pwnz Subject: Another weird link Attachments : web3.ndh Thank you again for these informations! we have just credited your account with $1700. Our spy... lire la suite

NDH2k12 Prequals - Any idea how to use

ndh_webapp_hdrAfter decrypting the secret message, we got a new email, from Piotr this time, a supposed technical operative. From: Piotr To: w3pwnz Subject: Any idea how to use this file?... lire la suite

NDH2k12 Prequals - We are looking for a

WallpaperImage.pngThe bmp file has no padding bytes, and its size matches the image dimensions (4374054 = 810*1800*3 +0x36 for the header). On the other hand, applying an LSB filter reveals that something is wrong on the left side of the... lire la suite

NDH2k12 Prequals - We are looking for a

UnknownText.pngFile sp111 After opening the sp111 text file, we guessed that it was encrypted with vigenere. We tried an auto-decrypt with http://www.apprendre-en-ligne.net/crypto/vigenere/decryptauto.html, revealing that... lire la suite

NDH2k12 Prequals - What is it about this

BinaryFileNdh.pngFile: 11925.ndh Once again it is a VM file. We quickly take a look at the hexdump to find the remote port used (4004). % tail 11925.ndh|hexdump -C 00000000 00 16 b7 0e 00 02 02 04 00 00 02 03 04 03 03 03... lire la suite

NDH2k12 Prequals - New email from our

Newemailfromourcontact.pngAccording to the description http://sci.nuitduhack.com was a url shortening service. After searching about how these services work i found two “common” practises. The first was inserting urls in the database and then... lire la suite

NDH2k12 Prequals - What is it about this

MoleInformation.pngIn the sp113.pdf found in the bitmap “Wallpaper image”, we can see “author: SciteekSmith”. Google is our friend : http://lmgtfy.com/?q=SciteekSmith There is 1 result : http://www.facebook.com/SciteekSmith... lire la suite

NDH2k12 Prequals - Time is running out -

mail_captured_file.pngThere is one file : sciteekadm.cap It’s a 802.11 capture. Let’s crack it with aircrack-ng and a wordlist. Then we decrypted the capture with Cain. We opened the decrypted capture with Wireshark. We can see a png file.... lire la suite

NDH2k11 Prequals - Compte Rendu !

ndh.pngLe week end dernier, se sont déroulées pendant 48h, les préqualifications du CTF de la Nuit Du Hack 2011 ! Les consignes étaient claires : * Les 10 premières équipes seront qualifiées d'office pour le CTF, et gagneront... lire la suite
© w3pwnz - 2012

Licence Creative Commons
Ce(tte) œuvre est mise à disposition selon les termes de la Licence Creative Commons Attribution - Pas d’Utilisation Commerciale - Pas de Modification 3.0 France.