Stolen Mount Walkthrough

Challenge Statement#

image

Solution#

We have a .pcapng which shows us the packets transmitted when the NFS server was infiltrated.
We can use the filter nfs.data.

image

We then follow the TCP Stream to view the contents of the packet. We find that there is a md5 hash of an “Archive” Password.

image

We can use any tool to crack the md5 hash and get the password. I’ve used this site.

image

To retrieve the “Archive” file, we can change the data type to RAW and save it as a zip file.
Then, we just have to unzip the file and enter the password that we had retrieved.

image

We get a QR code, which gives us the flag when scanned.

image


Adapted from harishkannan05/THM-HackfinityBattle-Writeup under MIT.

Find us elsewhere

Merch, stickers, and moreSupport the work at the Solvere Labs shop