WhiteHat Contest 11 – For100 Extract Me

Hi guys! today i will show you how to solved Forensic 100 – Extract Me.

Download file from here and open by wireshark.

2

And find open follow tcp.stream eq 36, we can see  transfering process file.

Next tcp.stream eq 37, we can see header PK… that is zip file  (How to know header of file look at here) and see flag.png . Let’s dump file and try open it.

6

Of course, It not easy 😀 . You must have password to open it. Try find in SSL and got suspect certificate made by Bkav

7

So you can do the same writeup to know how to decrypt SSL

8.PNG

with factordb and rsatool to create file private.key

9.PNG

Decrypt file pcapng

10

Let’s extract flag.png 😀

11.PNG

 

One thought on “WhiteHat Contest 11 – For100 Extract Me

Leave a comment