URL:http://ctf.infosecinstitute.com/levelthirteen.php
the backup file contain :
<p>Do you want to download this mysterious file?</p>
<a href="misc/imadecoy">
<button class="btn">Yes</button>
</a>
<a href="misc/imadecoy">
<button class="btn">Yes</button>
</a>
Download and analyze the file misc/imadecoy :
file imadecoy
imadecoy; tcpdump
capture file (little-endian) - version 2.4 (Linux "cooked", capture
length 65535)
its a tcpdump file open it using Wireshark :
Filter HTTP traffic and extract all objects
the image HoneyPY.PNG contain the flag .
Flag :Infosec_flagis_morepackets
No comments:
Post a Comment