URL:http://ctf.infosecinstitute.com/levelthirteen.php
the backup file contain  :
<p>Do you want to download this mysterious file?</p>
<a href="misc/imadecoy">
<button class="btn">Yes</button>
</a>
<a href="misc/imadecoy">
<button class="btn">Yes</button>
</a>
Download and analyze  the file misc/imadecoy :
file imadecoy
imadecoy; tcpdump
capture file (little-endian) - version 2.4 (Linux "cooked", capture
length 65535)
its a tcpdump file open it using Wireshark :
Filter HTTP traffic and extract all objects
the image HoneyPY.PNG  contain the flag .
Flag  :Infosec_flagis_morepackets


 
No comments:
Post a Comment