Write-up author: jon-brandy
We have got informed that a hacker managed to get into our internal network after pivoiting through the web platform that runs in public internet. He managed to bypass our small product stocks logging platform and then he got our costumer database file. We believe that only one of our costumers was targeted. Can you find out who the customer was?
- NONE
- First, unzip the
.zip
file given.
RESULT
- Let's open the file in wireshark.
RESULT
- Let's start by follow the
TCP
stream. - Found nothing good here.
- Let's try to filter the
HTTP
stream.
RESULT
- The bottom one quite interesting.
- Let's follow the stream.
- Notice found unique string there.
- Decode it using cyberchef.
RESULT
- Got the flag!
HTB{DonTRuNAsRoOt!MESsEdUpMarket}