Comments on: [NDH 2016] [FORENSICS 200 – I’M AFRAID OF A GH0ST NAMED POISON IVY] Write Up https://0x90r00t.com/2016/07/08/ndh-2016forensics-200-im-afraid-of-a-gh0st-named-poison-ivy-write-up/ 0x90r00t, 0x90r00f Sat, 30 Jul 2016 09:56:47 +0000 hourly 1 https://wordpress.org/?v=6.7.2 By: The lsd https://0x90r00t.com/2016/07/08/ndh-2016forensics-200-im-afraid-of-a-gh0st-named-poison-ivy-write-up/#comment-7532 Sat, 30 Jul 2016 09:56:47 +0000 https://0x90r00t.com/?p=2541#comment-7532 Hello Big5,

Thanks for your feedback, I waited it for a looooong time 🙂
Even if there was some bugs, it was a really nice challenge. I loved to bang my head against the wall during hours.
Concerning the junk data at the end of the decrypted text, the goal for me was to find something (at least the beginning of the flag), so I didn’t racked my brain to strip the junk.
I hope you’ll do other networking challenges for the next NDH (but without bug please :p)

Oh, and I’m always ready for beer, just tell me when and where, I’ll be there 🙂

Enjoy

The lsd

]]>
By: nicolas zilio https://0x90r00t.com/2016/07/08/ndh-2016forensics-200-im-afraid-of-a-gh0st-named-poison-ivy-write-up/#comment-7162 Mon, 11 Jul 2016 21:21:44 +0000 https://0x90r00t.com/?p=2541#comment-7162 Ah nice guys!

i would like to apologize, i have just checked it tonight, and in my client/server implementation i still used my previous send_test function (so not the final one) to make that pcap file (eheh comment). Hence, the double \x78\x9c is indeed not correct, and at the third packet, i wanted to reproduce the structure of payload, but instead of DWORD,i used to put a single byte… Glad you got it with my mistakes (i will get you some beer!)

just a note: the junk you get at the end is due to the length you use for decrypt, you have a key of 32 bytes, and you make the decrypt on a length of 64 bytes (so on some undetermined data). By the way, the 0x20 acting for payload length in the third packet was here to say it’s 32 bytes long.

another note: on the stegano chall, the strings command on the image returns “code rate is 0.571”, that would have been the hint for the size of generator matrix used.

regards,
Big5

]]>
By: majinboo https://0x90r00t.com/2016/07/08/ndh-2016forensics-200-im-afraid-of-a-gh0st-named-poison-ivy-write-up/#comment-7141 Sun, 10 Jul 2016 17:25:23 +0000 https://0x90r00t.com/?p=2541#comment-7141 Nice write-up, I confirm that the flag at the end of the write-up is the correct one.

]]>