Differences

This shows you the differences between two versions of the page.

Link to this comparison view

isc:lab-test [2026/10/01 17:12]
florin.stancu
isc:lab-test [2026/10/01 17:59] (current)
florin.stancu
Line 59: Line 59:
  
 ==== 01. Decode 'til You Drop ==== ==== 01. Decode 'til You Drop ====
- 
-{{page>:​isc:​agents_h&​nofooter&​noeditbutton&​noheader}} 
  
   * One of your friends gave you this string which looks encoded... Figure out what encoding was used and decode it. Be patient, it may take a couple of decoding rounds :)   * One of your friends gave you this string which looks encoded... Figure out what encoding was used and decode it. Be patient, it may take a couple of decoding rounds :)
-  ​* Hint: Spot the encoding: chars //A-Z a-z 0-9 + / =// with length a multiple of 4 :? ...+    * **Hint**: Spot the encoding: chars //A-Z a-z 0-9 + / =// with length a multiple of 4 :? ...
  
 <spoiler SPOILER! scratch to reveal..>​ <spoiler SPOILER! scratch to reveal..>​
Line 89: Line 87:
  
 ==== 02. Zip it good ==== ==== 02. Zip it good ====
- 
-{{page>:​isc:​agents_h&​nofooter&​noeditbutton&​noheader}} 
  
   * The archive contains the flag. What is the password?   * The archive contains the flag. What is the password?
-    * **Hint:** the password is in the wordlist+    * **Hint:** the password is in the wordlist ​=> dictionary attack! 
 +    * You have a helper Python skeleton for this (using the [[https://​docs.python.org/​3/​library/​zipfile.html|zipfile module]]), or you can use a classic CLI tool (//the ripper//​)! 
 + 
 +<spoiler SPOILER: Useful Python zip snippets + CLI tool...>​ 
 +  * Using Python3'​s ''​zipfile''​ module: 
 +    * you can [[https://​docs.python.org/​3/​library/​zipfile.html#​zipfile.ZipFile.setpassword|set the zip password]] in code: ''​z.setpassword(bytes(test_passwd,​ "​ASCII"​))''​ (remember encodings? this function requires ''​bytes''​!);​ 
 +    * then try to extract either  
 +  * As mentioned before, you can also use a classic cracking tool called ''​john''​! You must first extract the password hash using ''​ziptojohn ZIP_FILENAME > hash.txt''​ then simply call it using the ''​%%--%%wordlist=..''​ + hash.txt command-line arguments ;)  
 +</​spoiler>​
  
 ==== 03. Find the impostor ==== ==== 03. Find the impostor ====
 +
   * The flag for this exercise is found in a file under the inhere directory. The file has the following properties:   * The flag for this exercise is found in a file under the inhere directory. The file has the following properties:
     * human-readable     * human-readable
isc/lab-test.1790863925.txt.gz · Last modified: 2026/10/01 17:12 by florin.stancu
CC Attribution-Share Alike 3.0 Unported
www.chimeric.de Valid CSS Driven by DokuWiki do yourself a favour and use a real browser - get firefox!! Recent changes RSS feed Valid XHTML 1.0