{"id":912,"date":"2015-09-10T00:45:50","date_gmt":"2015-09-09T22:45:50","guid":{"rendered":"https:\/\/0x90r00t.com\/fr\/?p=912"},"modified":"2015-09-10T00:49:59","modified_gmt":"2015-09-09T22:49:59","slug":"mma-2015-forensics-warmup-splitted-write-up","status":"publish","type":"post","link":"https:\/\/0x90r00t.com\/fr\/2015\/09\/10\/mma-2015-forensics-warmup-splitted-write-up\/","title":{"rendered":"[MMA 2015] [Forensics \/ Warmup &#8211; Splitted] Write up"},"content":{"rendered":"<h2>Description<\/h2>\n<blockquote><p>Nous nous retrouvons avec une <a href=\"https:\/\/0x90r00t.com\/wp-content\/uploads\/2015\/09\/splitted.zip\">archive<\/a> contenant une capture r\u00e9seau.<\/p><\/blockquote>\n<p><!--more--><\/p>\n<h2>Resolution<\/h2>\n<p>Tout d&rsquo;abord, nous avons ouvert le fichier .pcap avec wireshark.<\/p>\n<p>En quelques secondes on se rend compte que la capture contient le t\u00e9l\u00e9chargement en plusieurs parties d&rsquo;un fichier flag.zip, int\u00e9ressant !<\/p>\n<p><a href=\"https:\/\/0x90r00t.com\/wp-content\/uploads\/2015\/09\/Capture-16.png\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-914 size-large\" src=\"https:\/\/0x90r00t.com\/wp-content\/uploads\/2015\/09\/Capture-16-1024x550.png\" alt=\"wireshark zip export\" width=\"474\" height=\"255\" srcset=\"https:\/\/0x90r00t.com\/wp-content\/uploads\/2015\/09\/Capture-16-1024x550.png 1024w, https:\/\/0x90r00t.com\/wp-content\/uploads\/2015\/09\/Capture-16-300x161.png 300w, https:\/\/0x90r00t.com\/wp-content\/uploads\/2015\/09\/Capture-16.png 1920w\" sizes=\"auto, (max-width: 474px) 100vw, 474px\" \/><\/a>On exporte alors tous ces fichiers, ce qui nous fait 8 parties de fichier zip.<\/p>\n<p>Gr\u00e2ce au header http \u00ab\u00a0Content-Range\u00a0\u00bb nous pouvons retrouver l&rsquo;ordre dans lequel renommer les fichier .zip extraits.<\/p>\n<pre>| File N | Range |\r\n|----------------|\r\n| 1\u00a0\u00a0\u00a0\u00a0\u00a0 | 0\u00a0\u00a0\u00a0\u00a0 |\r\n| 5\u00a0\u00a0\u00a0\u00a0\u00a0 | 469\u00a0\u00a0 |\r\n| 6\u00a0\u00a0\u00a0\u00a0\u00a0 | 938\u00a0\u00a0 |\r\n| 2\u00a0\u00a0\u00a0\u00a0\u00a0 | 1407\u00a0 |\r\n| 7\u00a0\u00a0\u00a0\u00a0\u00a0 | 1876\u00a0 |\r\n| 0\u00a0\u00a0\u00a0\u00a0\u00a0 | 2345\u00a0 |\r\n| 3\u00a0\u00a0\u00a0\u00a0\u00a0 | 2814\u00a0 |\r\n| 4\u00a0\u00a0\u00a0\u00a0\u00a0 | 3283\u00a0 |\r\n<\/pre>\n<p>On renomme alors \u00e0 la main, les fichiers export\u00e9s en part-x.zip, en suivant l&rsquo;ordre du \u00ab\u00a0Content-Range\u00a0\u00bb.<\/p>\n<p>On assemble le zip puis on extrait l&rsquo;archive.<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\n$ cat part-*.zip &gt; assembled.zip\r\n$ unzip .\/assembled.zip<\/pre>\n<p><code>Archive:\u00a0 .\/assembled.zip<br \/>\ninflating: flag.psd<\/code><\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">$ file flag.psd<\/pre>\n<p><code>flag.psd: Adobe Photoshop Image, 640 x 400, RGB, 3x 8-bit channels<\/code><\/p>\n<p>Oh, un fichier psd, voyons voir le contenu de ses calques.<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\n$ convert flag.psd flag.png\r\n$ ls *.png<\/pre>\n<p><code>flag-0.png\u00a0 flag-1.png\u00a0\u00a0 \u00a0flag-2.png<\/code><\/p>\n<p>Le calque extrait dans le fichier flag-1.png contient le flag !<\/p>\n<p><a href=\"https:\/\/0x90r00t.com\/wp-content\/uploads\/2015\/09\/flag.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-916\" src=\"https:\/\/0x90r00t.com\/wp-content\/uploads\/2015\/09\/flag.png\" alt=\"flag\" width=\"640\" height=\"400\" srcset=\"https:\/\/0x90r00t.com\/wp-content\/uploads\/2015\/09\/flag.png 640w, https:\/\/0x90r00t.com\/wp-content\/uploads\/2015\/09\/flag-300x188.png 300w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a>Le flag est : MMA{sneak_spy_sisters}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Description Nous nous retrouvons avec une archive contenant une capture r\u00e9seau.<\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34,35,52],"tags":[31,47,42,56],"class_list":["post-912","post","type-post","status-publish","format-standard","hentry","category-2015-fr","category-ctf-fr","category-mma-2015-fr","tag-forensics","tag-mma","tag-wireshark","tag-warmup"],"_links":{"self":[{"href":"https:\/\/0x90r00t.com\/fr\/wp-json\/wp\/v2\/posts\/912","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/0x90r00t.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/0x90r00t.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/0x90r00t.com\/fr\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/0x90r00t.com\/fr\/wp-json\/wp\/v2\/comments?post=912"}],"version-history":[{"count":10,"href":"https:\/\/0x90r00t.com\/fr\/wp-json\/wp\/v2\/posts\/912\/revisions"}],"predecessor-version":[{"id":930,"href":"https:\/\/0x90r00t.com\/fr\/wp-json\/wp\/v2\/posts\/912\/revisions\/930"}],"wp:attachment":[{"href":"https:\/\/0x90r00t.com\/fr\/wp-json\/wp\/v2\/media?parent=912"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/0x90r00t.com\/fr\/wp-json\/wp\/v2\/categories?post=912"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/0x90r00t.com\/fr\/wp-json\/wp\/v2\/tags?post=912"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}