RITSEC_CTF
RITSEC_CTF
RITSEC_CTF Forensics Writeup
Challenge : Intercepted Transmission
Challenge Description
- We have intercepted a transmission from the aliens. We believe they were pinging government installations in order to find the locations.
Solution
- Analyze the PCAP file:
- Filter ICMP packets:
- Apply the following Wireshark filter to isolate ICMP traffic:
1
icmp
- Observing the data field in ICMP packets, we notice that some contain readable text.
- Apply the following Wireshark filter to isolate ICMP traffic:
- Identify Flag Containing Packets:
- Extract Flag using TShark:
Flag
1
2
RS{Its_A_Coverup}
This post is licensed under CC BY 4.0 by the author.