Writeup of CERT-SE Challenge 2020
The Swedish national CERT published a CTF on their website to kick of the cyber security month in the form of a zip-file: CERT-SE_challenge2020.zip Step 1 Open pcap in Wireshark. Most of the activity is between 192.168.122.156 and 192.168.122.129. Let’s filter by it. ip.addr == 192.168.122.156 && ip.addr == 192.168.122.129 Chat tcp.stream eq 7 The interesting parts: :[email protected] JOIN :#RetroForum :[email protected] PRIVMSG #RetroForum :Yo! PRIVMSG #RetroForum :Yo!/Sup? :[email protected] PRIVMSG #RetroForum :Sup?...