Showing posts with label Wargames. Show all posts
Showing posts with label Wargames. Show all posts

Tuesday, November 18, 2014

UTPHax'14 - Writeup for Audio Stego Round 5

Its a great experience handling another hacking contest in a local university recently. As usual, there will be some questions that the contestants were not able to answer it and they keep on asking how the hell are it can be solved?

Well, here's one of the way for this challenge :)

Question : Chill out the pressure and listen to the rhyme. Enjoy! 
Participant provided with a WAV where when they play it will hear a nice piano rhythm. However, it seems there's something buggy at the middle of the play.

Hint given 

By looking at the hint, we can know that this sound generated from an online tool which can be manipulated using our keyboard.
Simple google for "piano generator" will lead us to this website http://www.gootar.com/piano/ and yes, this is the right URL :)

By default, there's already a piano tone available on the URL and if we play it, woh! it is the similar sound with our question WAV audio.right?!

Open up our audacity and record the sound. Open the original WAV and compare it with our question WAV. It will looks like below.



From the analysis, we can say that the starting and ending point is just like what I squared out in the picture above. So let us see what is actually the key that was used before our flag located is.



Yerp. you are right. symbol. So what we should do next? Looking back at our keyboard based piano, we can know that each tone have different frequency (high,high peak,low,etc) as described in the picture below, I divided it into 4 different layer of frequency.


If we hear the sound where our flag located is, the first tone actually belong to the 2nd layer. So back again to the URL, and 1 by 1 we test to capture the sound.
Start the tone with ; then continue with the character in the 2nd layer. As example,
;]_;[_;p_;o -continue yourself- do note that _ symbol actually just a rest tone. so we can hear the tone much clearer.
Once done for that, again record and compare it using audacity. It will look like below.


Aha! we can see some similarities between the sound we created just now with the original question WAV (from the starting point of the flag).
So the flag either start with ;p or ;o

Let us pick and proceed with a new tone. Hear it back again, and we can say the tone quite low and belong to 3rd layer.

Go to URL, and start recording the tone. 
;p;_;pl_;pj_;ph_;pg -blalala continue yourself-

Compare it again with our question WAV.

Auw yeahh!! we are on the right track! Then? just continue the same step until you finish the line. once done you'll get the flag :)
flag is pl4yme

That's all. Thanks!


Thursday, April 18, 2013

Ihack 2013 - Forensic Challenge - Writeup Collections.

So, I'll put all of them in 1 post so everyone can refer it easier :)

10 Points
-----------
- just find my twitter on that day.

50 Points
------------
- http://www.youtube.com/watch?v=MJXww8aizAM
- look at the phone numbers

100 Points
--------------
1 - Pokemon Cryptography - here
2 - Kamen Rider Image Forensic - here
3 - Snow White - here

200 Points
-------------
1 - XOR Crypto - By BeardBazen
2 - Packet Analysis - By Naja

300 Points
-------------
1 - VM Forensic - here
2 - File Recovery - By Naja

400 Points
-------------
1 - Packet Analysis - By BeardBazen
2 - Audio/Video Forensic - By BeardBazen

500 Points
-------------
1 - File Recovery - By BeardBazen
2 - File Recovery - By Nafiez
3 - QR Code - here


Complete! And again congratz to all participants. :)

Ihack2013 - Forensic Writeup Challenge 500 Point - QReption

Hopefully this last writeup will complete the solutions for all forensic questions in Ihack2013. BeardBazen, you owe me writeups for any puzzle that is(are) not published yet :P

This is the another question that no one able to solve. Yes,I made this one for that purpose LOL. This is my trump card in case any team manage to solve other questions.

Team was given with this QR image
The clue? Look at the question.
Leonardo asked if you guys ever watched inception. Its a story where a person jump into others dream and so on.. same as this puzzle. there'll be QR code in another Qr code and so on.
hahahaha..that's the real thing that you guys should do actually..BUT....
































I uploaded a wrong qr file. so its impossible to solve it.muahahahahahahahahahhahahahahahaha just noticed it few minutes ago. ROFL!

guys,i'm sorry.haha



Wednesday, April 17, 2013

Ihack2013 - Forensic Writeup Challenge 100 Point - Snow White

Hi again, another writeup from me for you guys to learn especially the 1st timer in Ihack. Most of the team really give their best in solving each puzzle/challenge. Its good to see that kind of passion in youngsters. Do send me your CV if once you graduated :P

For this challenge each team was given this kind of task

again, the clue is right in front of you..SPACEWHITE..what kind of IT related to the SPACEWHITE? its a whitespace programming.
read it here

Can see lots of contestants give some efforts in googling..but less of them give an effort to READ them carefully.
Patience young padawan. Read if you must, dont too depend on the online tools.
From the wikipedia, can see that this whitespace programming
"Onlyspacestabs and linefeeds have meaning"
Read more about it.

"Data is represented in binary using spaces (0) and tabs (1), followed by a linefeed, space-space-space-tab-space-tab-tab-linefeed is the number 11"
Yes. That's the right way to understand how to solve this puzzle. Look at the Snow White poem given during the game. Each paragraph,there'll be a weird spacing..Decode each of them to get a binary code and you'll get the flag on the spot once its been decoded.
How I can decode those spaces and tabs into binary? Simple.Use notepad++ :)



Once you replaced all the tabs and spaces available ( note that just change those between paragraph,else your poem will be messy )

the flag is th1s_!5_s0_s1mPl3


Tuesday, April 16, 2013

Ihack2013 - Forensic Writeup Challenge 300 Point - VM Forensic

As requested by Mr Ramadhan, here's the writeup!
The question was
So each team was given with this file 695f616d5f7468655f6861786f72.7z.
Extract it will gives them another folder and in it there's a file named ihaxor.
What kind of file is that? Again, use FILE command.
Yes. Its a tar archive. Extract it again will give you a virtualbox image. Import it in your virtualbox machine.

Hello Slitaz! Its a slitaz VM. Dont know the password? Please,google it.

Ok now I'm in. What's next? Most of the teams were confused with the files exist in this slitaz. Everyone keep thinking the way to be a root user..But its not the right way to solve it! Why those folders existed? Yeah, of course I put it as a troll LOL!

Read the question "Dont think too hard". As a Pro Hacker, please..a basic step. Look for ALL files available first.

Yeah. There's a .ash_history  file. Look at that file. Its a common thing once you get into someone's PC in order to do some forensic investigation.
Viewed the file and will noticed that there's a weird file named wipipipipi.txt. Did you guys try to look for that file??
Woot!! I found the file. Its in the /log folder. (and its one of the folder that a forensic investigator should look at )
Found,lets look what is inside.
TADAAAAAA!!! there's your flag!
flag is f0r3ns!c.is.3asy

muahahahaha..easy right?! Trolled hard?yeah you got trolled. Stop claiming yourself as a hacker now. LOL

Monday, April 15, 2013

Ihack2013 - Forensic Writeup Challenge 100 Point - Image Analysis

Here's the 2nd one for Forensic Challenge 100 points. People keep up trying on this one..seems there's no one can answer this during the game..so unlucky :P
If you guys look back at the previous Ihack 2010 by Yondie, there's a similar puzzle given in Hack&Defence category.

Let's look at the writeup!
Team were given with this Kamen Rider GIF file.

If you guys look at the file carefully. There are several images with same design.YERP! the one with kamen rider + their airing years :P
Extract them and eliminate those that are not related.
Then?
Did you guys read the question carefully?again..there's already a CLUE in it!!
"you should start watching them"
when we'r going to watch a series, we should watch starting from the first one. So, put the kamen rider in order based on their airing years.
Some of the contestants already manage until this part,but then they dont know what to do.hahaha..
Here's the way to get the flag.
For each images extracted, look at the COLORS!

- Open up your photo editor such as GIMP or Photoshop.
- Use Color Picker Tool.
- Click on the Font's color.
- Look at the color's code!!

By put the code in order,you'll get the hex code,decode it you'll get the flag :P


muahahahahahaha :P

Ihack2013 - Forensic Writeup Challenge 100 Point - Cryptography

Ihack2013 already finished but most of the contestants still eager to know what's the solution for most of the questions.
Here's 1 of them.

They were given a file with this image as a clue.

A clue?!! yes..each image for every questions is THE CLUE!
So what's the relation between Ash Ketchum from Pokemon with this cryptography?

 Wait.How did I know that file is an image file? Basic forensic step. Use FILE command in linux to identify the type of that file.

So I can see some of the contestants using many ways to decode the code. Applause to them. Its great to see some efforts from the youngsters :D

So what's actually this code is about? And the important thing is,WTF IS THIS CODE?!!
Its a bionicle encoding.
Google about them :)

Then,WHY THE HELL THERE ARE LOTS OF POKEBALLS?!!
Hard to decode it 1 by 1? Here's the trick, you just need to decode the 1st line of the cryptography message. Once you decoded it, try to google them.
Yes! The code is coming from Pokemon's wikipedia which already mentioned by the clue!
So encode the paragraph where your 1st line decoded message were using online bionicle encoding tool, compare it with the question given by the forensic game, you'll notice a slightly difference in the coded message. Yes there's where the flag located. Decode that part and voilla. You got the flag!
Flag is g0tta.h4cK.th3m.@LL

Its not hard at all :P
Congratz for those manage to get the flag.

Sunday, October 14, 2012

iHack+ 2012 - Hacking Competition

Are you a student from any local university in Malaysia? if Yes, come and join this hacking competition!
a Hacking Competition organized by UiTM for students in Malaysia.
for more info Click Here

RM80,000 awaits you all!!

Friday, August 3, 2012

Wargames2012 - Crypto100,200 Writeups

again, there's a wargames conducted by HiTB KL Crews this year. I'm participated but not doing well just like previous year..since..there were some other commitments during that weekends. So, here are two writeups for crypto

  Crypto100
Easy crypto: 82 73 81 81 61 83 52 62 63 41 74 22 01 42 73 31 74 52 01 21 74 01 71 83 83 01 92 73 83 32 61 73 01 81 62 43 01 74 63 51 01 71 43 92 32 92 92 22 23 43 42 61 01 51 51 72 41 62 81 72 42 22 91 01 74 91 52 74 01 42 33 23 61 23 43 21 61 52 22 01 52 74 42 01 82 63 43 94 92 93 91 32 23 32 01 94 43 01 21 62 21 74 52 81 32 71 91 33 93 01 43 51 63 42 01 32 01 52 53 32 94 63 74 91 42 01 52 81 83 92 92 01 21 74 01 91 31 41 53 82 91 62 63 01 73 42 82 91 21 22 51 71 01 91 94 32 01 51 83 22 62 61 51 63 52 94 82 01 41 33 01 83 73 01 92 82 41 62 61 41 32 42 83 01 61 94 91 53 42 52 21 01 41 93 53 82 91 31 01 63 53 92 01 52 43 93 23 82 81 72 93 01 81 94 41 21 82 61 61 43 83 01 93 42 91 31 94 42 01 61 83 01 83 21 72 33 41 42 51 01 81 23 43 01 42 93 61 23 91 32 53 63 01 21 62 21 74 52 81 32 71 91 33 93 01 73 33 53 81 01 21 22 21 53 01 32 22 52 71 72 83 32 93 01 83 92 51 61 53 91 83 93 91 52 01 81 23 43 52 53 33 82 01 31 43 71 33 31 82 93 61 41 62 01 93 51 52 73 93 91 91 31 01 52 43 52 94 74 51 41 01 52 94 01 41 41 01 81 23 43 01 53 42 72 21 01 41 94 93 33 91 01 91 51 83 32 52 01 21 91 33 01 33 93 42 01 74 62 93 01 92 21 53 01 32 94 51 83 93 91 01 41 33 01 63 53 92 01 51 74 43 31 53 32 42 51 01 81 23 43 01 33 53 92 31 23 82 31 01 92 52 32 93 01 92 42 01 51 32 62 33 71 01 94 92 53 01 23 61 23 43 21 74 42 23 92 51 01 52 74 83 94 01 33 92 51 74 43 74 01 94 93 33 51 32 83 91 22 82 52 42 61 01 81 94 71 42 53 94 22 01 81 82 42 01 32 42 51 01 53 74 42 53 31 41 81 21 61 52 22 01 31 94 82 91 01 91 31 42 92 94 81 62 74 73 63 ------------- Description: ------------ Look carefully! Does it look like hex?
the numbers refers phone keypad. decode it and then you'll get another cipher which is a vignere cipher. decrypt it and you'll get an article about cryptography. the 'key' is a hint to this challenge's flag.

  Crypto200
FN1hJU9XAJZhTF8qbnJENt1XBMd6i0utzJpHCGyVt4yp8LsHYHUJP+/M+37eNjldkx4T5xnliSrIsz/qQHB9PA==
as you can see,this is just a normal base64. decode it and you'll get some scrabble/rubbish/random words+symbols.view hex of the decoded base64 just like below.
yerp.its an md5 hash.you just need to decrypt in and you'll get the flag :) this year,these two are the only crypto challenges that the crew released. maybe quite hard compared last year so players struggle to solve them. thanks.

Sunday, June 3, 2012

Wargames.My 2011 - crypto200


 Above is the ciphered words given to the players. What the players need to do? Decode it,simple :P Google images for "logo cipher" or "code image". And lots of images with their own cipher code from the images. Find the one that similar to the crypto200.png There are some that you can list in. 1 - freemason cipher 2 - pigpen cipher 3 - more.. I chose pigpen cipher since that's the most similar to the crypto200.png.. My friend said it is ok to chose either one since the next step after deciphering this cipher is the real challenge. once decode it to words,this is what i got
ndeunf ofqugzdg cdru kuus zdpul
dsl giyisp uatvsuseiannf ev kgisp
lvzs ovgghtecl pvrugswusey dsl eh
ogudeu egdsytdgusof dsl kgispisp
tvzug kdom ev ecu tuvtnu!zlugu
ecugu iy sv riyivs,ecu tuvtnu zinn
tugiyc

svz dsyzug;zcioc pgvht zdy gfds
onudgf doohyul vx ev ku dyyvoideul
ziec?wl5 ecudsyzug dsl yhkwie ecu
yhw.ecde iy fvhgxnp.
End? not yet! you still need to decode the 2nd cipher,Substitution Cipher! Here's a wikilink for this cipher. how this cipher works? here's an example rabbit - real words. so the person who want to send this message want to cipher it,so he substitute letter r = x, a = w, b = e, i = k, t = u so the rabbit,once ciphered will become xweeku. so,how to get the real answer for this challenge? reverse the decoded words up there :P thanks.

Tuesday, May 29, 2012

Wargames.My 2011 - crypto100

Crypto100
Players given this code.


fvrwslwslswhgacsremfberbubgrihgbtvi


Hint given was : I like big,long and yellow
the first thing came in my mind once read the hint was = banana!!..so the answer/passphrase should be monkey.

I googled a little bit about type of ciphers that need a passphrase/key to decrypt it.
I found vignere ciphers.Then try to use online cracker available to crack it, and wollah~ lucky me :D
Flag is = themonkeyisjumpingaroundinthejungle


Here's a python code made by johnburn to solve this challenge. its a dictionary attack btw.

#!/usr/bin/python
charset   = 'abcdefghijklmnopqrstuvwxyz'
encoded = 'fvrwslwslswhgacsremfberbubgrihgbtvi'

keys = open("wordlist.txt", "r")
for key in  keys.read().split('\n'):
    message = ''
    for i in range(len(encoded)) :
        p = charset.index(encoded[i])
        k = charset.index(key[i % len(key)])
        if k - p < 0 :
                   message += charset[((p - k) + 26) % len(charset)]
        else :
                   message += charset[(p - k) % len(charset)]
    if message[:-2].count('the')>1:
        print 'The key: ' + key        
        print 'The message: ' + message
        break

Wargames.My 2011 - writeups

This year there'll be another online ctf games a.k.a wargames in malaysia.Thanks to hackerspace community + TheSexyKambing
http://wargames.my/wgmy2012/
Last year,the game dominated by Kueytiow. He/She manage to solve two binary bonus challenge which made him started the game in a comfort zone.
Can view the last year result here
result

So for those that have interest to join this year wargames do register ASAP.

In my blog I'm gonna share with you some of the writeups for the previous challenge.

Web100
Available in wargames website, web100 writeups

Forensic200
OHMAIGAWD! It seems like we've been hacked! But what did the hackers 
steal? From the logs, it seems like they exploited an SQL injection bug 
on our website. Help us find the name of the database that they stole 
and we shall reward you handsomely.
So players were given with a log to analyze them. You can get it here
From the logs, the attacker just use an automated tool;sqlmap to exploit the web. The injection use Blind technique. If you are good enough in Blind SQL injection,you should get the flag in less than a minute :) goodluck.
Flag = wgmy2011

more will be in my next post...hopefully :P