htb-challenges-stego-davinci
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| htb-challenges-stego-davinci [2019/06/19 13:10] – didzkovitchz | htb-challenges-stego-davinci [2020/12/15 21:44] (current) – removed didzkovitchz | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | HTB ~~ Stego Challenges ~~ Da Vinci | ||
| - | [[htb|Retour]] | ||
| - | |||
| - | - | ||
| - | |||
| - | ===== Présentation ===== | ||
| - | |||
| - | < | ||
| - | Try to find out the secret which is hiding inside of these pictures and learn the truth about Mona Lisa! | ||
| - | </ | ||
| - | |||
| - | 3 fichiers : | ||
| - | * '' | ||
| - | * '' | ||
| - | * '' | ||
| - | |||
| - | ===== Résolution ===== | ||
| - | |||
| - | |||
| - | '' | ||
| - | |||
| - | < | ||
| - | monalisa.jpg: | ||
| - | |||
| - | Plans.jpg: | ||
| - | |||
| - | Thepassword_is_the_small_name_of_the_actor_named_Hanks.jpg: | ||
| - | </ | ||
| - | |||
| - | |||
| - | |||
| - | '' | ||
| - | |||
| - | < | ||
| - | DECIMAL | ||
| - | -------------------------------------------------------------------------------- | ||
| - | 0 | ||
| - | |||
| - | WARNING: Extractor.execute failed to run external extractor 'jar xvf ' | ||
| - | 450363 | ||
| - | 450440 | ||
| - | 568411 | ||
| - | 568537 | ||
| - | </ | ||
| - | |||
| - | L' | ||
| - | J'ai essayé plusieurs mots de passe différents en me basant sur l' | ||
| - | |||
| - | '' | ||
| - | ça ne semble rien m' | ||
| - | |||
| - | |||
| - | En éditant le fichier '' | ||
| - | Les fois précédentes c' | ||
| - | Du coup on essaie, surtout que nous avons une indication du mot de passe possible ('' | ||
| - | |||
| - | < | ||
| - | steghide --extract -sf Thepassword_is_the_small_name_of_the_actor_named_Hanks.jpg | ||
| - | Enter passphrase: | ||
| - | wrote extracted data to " | ||
| - | </ | ||
| - | |||
| - | Le fichier '' | ||
| - | < | ||
| - | Hey Filippos, | ||
| - | This is my secret key for our folder.... (key: | ||
| - | I used an encryption with 32 characters. hehehehehe! No one will find it! ;) | ||
| - | Decrypt it... It's easy for you right? | ||
| - | Don't share it with anyone...plz! | ||
| - | |||
| - | |||
| - | if you are reading that, call me! | ||
| - | I need your advice for my new CTF challenge! | ||
| - | |||
| - | Kisses, | ||
| - | -Luc1f3r | ||
| - | </ | ||
| - | |||
| - | On retrouve un hash md5 : '' | ||
| - | |||
| - | Il s' | ||
| - | |||
| - | Détermination du type de fichier : | ||
| - | < | ||
| - | file Mona.jpg | ||
| - | Mona.jpg: JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 612x612, components 3 | ||
| - | </ | ||
| - | |||
| - | J'ai essayé quelques analyses (strings, binwalk, hexdump, stegsolve...), | ||
| - | |||
| - | Je retrouve la chaine ''&' | ||
| - | |||
| - | Je retourne sur la vidéo YouTube trouvée précédemment dans un des fichiers. | ||
| - | ça semble ne rien ne m' | ||
| - | |||
| - | Du coup j' | ||
| - | |||
| - | < | ||
| - | steghide --extract -sf Mona.jpg | ||
| - | Enter passphrase: | ||
| - | wrote extracted data to " | ||
| - | </ | ||
| - | |||
| - | Le fichier '' | ||
| - | |||
| - | C'est du base64. Décodé ça donne '' | ||
| - | On reste dans du base64. | ||
| - | |||
| - | Décodé ça donne '' | ||
| - | Toujours du base64. | ||
| - | |||
| - | Décodé ça donne '' | ||
| - | |||
| - | Voilà :-) 8-) | ||
| - | |||
| - | Ma seule difficulté dans ce challenge a été de trouver que le mot de passe pour une des archive était une partie du titre de la vidéo YouTube. | ||
| - | |||
| - | ===== FLAG ===== | ||
| - | |||
| - | HTB{M0n@_L1z@_!s_D3@D} | ||
htb-challenges-stego-davinci.1560942603.txt.gz · Last modified: 2019/06/19 13:10 by didzkovitchz
