Tuesday, April 30, 2013

BSidesChicago CTF: Keep it Secret, Keep it Safe

Forensics Challenge: Keep it Secret, Keep it Safe

This is a write up for the "Keep it Secret, Keep it Safe" forensics challenge rated as moderate difficulty. We're presented with the following description and a zip file:

This is a reminder that your annual performance review is in 2 weeks. We will be criticizing every thing you have done since you have joined us. Don't worry too much about it. I've been messing things up since I was hired 25 years ago and they still haven't fired me.

During a recent raid, we were able to get a copy of a virtual machine saved state file from a hard drive we found in a wooden box. We believe this may have had some vital information on it and we need you to figure it out.

Oh, the department heads wanted me to remind you that your performance review weighs heavily on your success of this challenge. So no pressure. Go get em!

The file is attached.

Good luck!

Time for another ascii.io session.

We end up extracting a PNG file from the virtual machine saved state file as instructed using a tool called binwalk. Let's take a look at this file with vital information on it.

At first we tried SGFja2VycyBSdWx1cyEhIQ== as the flag, and then face palmed as it's base64 encoded. We can use a variety of tools to decode base64. The flag ended up being "Hackers Rulus!!!" after decoding the string.


