[CSAW 2016] Kill Writeup



Is kill can fix? Sign the autopsy file?

This challenge was the first in the Forensics category and was very very simple. We are given with what seems like a corrupted pcapng file, I wasn’t able to open it in Wireshark nor Tcpdump. I ran strings on it with a hope to find the flag:

[Megabeets] /tmp/CSAW/kill# strings kill.pcapng | grep -i flag

And to my great surprise I got it, the flag was written plain-text in the file.


Leave a Reply

Your email address will not be published. Required fields are marked *