diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/challenges/network-security/encrypted-c2-v2.md b/list/thailand-cyber-top-talent-2024-senior-qualifier/challenges/network-security/encrypted-c2-v2.md index 50058be..2eb3179 100644 --- a/list/thailand-cyber-top-talent-2024-senior-qualifier/challenges/network-security/encrypted-c2-v2.md +++ b/list/thailand-cyber-top-talent-2024-senior-qualifier/challenges/network-security/encrypted-c2-v2.md @@ -1,3 +1,25 @@ # Encrypted C2 v2 -## WIP +![1.png](../../images/network-security/encrypted-c2-v2/1.png) + +[open_netsec3.pcapng](../../files/open_netsec3.pcapng) + +## Solving + +![2.png](../../images/network-security/encrypted-c2-v2/2.png) + +export ไว้รอเลย + +![3.png](../../images/network-security/encrypted-c2-v2/3.png) + +จากที่ดูคือเราต้องเอา maps ไปใช้ในการถอดรหัส จะได้จาก handshake และ ข้อความจะเกิดขึ้นตอน callback + +![4.png](../../images/network-security/encrypted-c2-v2/4.png) + +เราเลยเขียน code loop ถอดมันทุกแบบไปเลย + +## Result + +![5.png](../../images/network-security/encrypted-c2-v2/5.png) + +it work diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/challenges/network-security/http-mayhem.md b/list/thailand-cyber-top-talent-2024-senior-qualifier/challenges/network-security/http-mayhem.md index 38feadf..2160dc5 100644 --- a/list/thailand-cyber-top-talent-2024-senior-qualifier/challenges/network-security/http-mayhem.md +++ b/list/thailand-cyber-top-talent-2024-senior-qualifier/challenges/network-security/http-mayhem.md @@ -1,3 +1,33 @@ # HTTP Mayhem -## WIP +![1.png](../../images/network-security/http-mayhem/1.png) + +[open_netsec1.pcapng](../../files/open_netsec1.pcapng) + +## Solving + +เราเปิดมาพบ 2 stream ที่เป็น http + +![2.png](../../images/network-security/http-mayhem/2.png) + +มันคือ code python ที่เอาไว้ใช้ทำอะไรสักอย่าง + +![3.png](../../images/network-security/http-mayhem/3.png) + +รูป + +![4.png](../../images/network-security/http-mayhem/4.png) + +เราจึงลองเอารูปนั้นมาเปิดดู แต่ทำไมไม่มีอะไรเลย ? + +![5.png](../../images/network-security/http-mayhem/5.png) + +เราจึงกลับไปดูที่ code เราจึงเดาๆได้ว่า code นี้ใช้ในการซ่อนข้อมูลใน pixle bit สุดท้าย + +![6.png](../../images/network-security/http-mayhem/6.png) + +เราจึงเขียนแก้ code ให้ใช้เป็นการถอดรหัส + +## Result + +![7.png](../../images/network-security/http-mayhem/7.png) diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/challenges/network-security/slient-whisper.md b/list/thailand-cyber-top-talent-2024-senior-qualifier/challenges/network-security/slient-whisper.md index c3f8e5f..df1476e 100644 --- a/list/thailand-cyber-top-talent-2024-senior-qualifier/challenges/network-security/slient-whisper.md +++ b/list/thailand-cyber-top-talent-2024-senior-qualifier/challenges/network-security/slient-whisper.md @@ -1,3 +1,23 @@ # Silent Whisper -## WIP +![1.png](../../images/network-security/slient-whisper/1.png) + +[open_netsec2.pcapng](../../files/open_netsec2.pcapng) + +## Solving + +![2.png](../../images/network-security/slient-whisper/2.png) + +หน้าที่ของเราคือต้องมาหาว่า password ไหนที่ใช้เข้าสู่ระบบได้สำเร็จ + +![3.png](../../images/network-security/slient-whisper/3.png) + +เราจึงทดลองด้วย key word สักตัวเพื่อดูว่ามันจะมีคำไหนบ้าง ซึ่งดูเหมือนถ้า login สำเร็จจะมีคำนี้ + +![4.png](../../images/network-security/slient-whisper/4.png) + +เราจึงเอาคำนั้นไป filter ใน wireshark + +## Result + +![5.png](../../images/network-security/slient-whisper/5.png) diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/encrypted-c2-v2/1.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/encrypted-c2-v2/1.png new file mode 100644 index 0000000..7af9cdc Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/encrypted-c2-v2/1.png differ diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/encrypted-c2-v2/2.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/encrypted-c2-v2/2.png new file mode 100644 index 0000000..3551739 Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/encrypted-c2-v2/2.png differ diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/encrypted-c2-v2/3.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/encrypted-c2-v2/3.png new file mode 100644 index 0000000..8236a6d Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/encrypted-c2-v2/3.png differ diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/encrypted-c2-v2/4.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/encrypted-c2-v2/4.png new file mode 100644 index 0000000..bcfbdc9 Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/encrypted-c2-v2/4.png differ diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/encrypted-c2-v2/5.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/encrypted-c2-v2/5.png new file mode 100644 index 0000000..acbb621 Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/encrypted-c2-v2/5.png differ diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/1.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/1.png new file mode 100644 index 0000000..ac33d2c Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/1.png differ diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/2.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/2.png new file mode 100644 index 0000000..bb68b51 Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/2.png differ diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/3.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/3.png new file mode 100644 index 0000000..17f66bc Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/3.png differ diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/4.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/4.png new file mode 100644 index 0000000..bcce52c Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/4.png differ diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/5.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/5.png new file mode 100644 index 0000000..29ba420 Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/5.png differ diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/6.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/6.png new file mode 100644 index 0000000..61ddb92 Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/6.png differ diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/7.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/7.png new file mode 100644 index 0000000..81da1b8 Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/http-mayhem/7.png differ diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/slient-whisper/1.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/slient-whisper/1.png new file mode 100644 index 0000000..7682f50 Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/slient-whisper/1.png differ diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/slient-whisper/2.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/slient-whisper/2.png new file mode 100644 index 0000000..df18fb5 Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/slient-whisper/2.png differ diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/slient-whisper/3.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/slient-whisper/3.png new file mode 100644 index 0000000..cb1559b Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/slient-whisper/3.png differ diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/slient-whisper/4.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/slient-whisper/4.png new file mode 100644 index 0000000..bb7c6e6 Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/slient-whisper/4.png differ diff --git a/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/slient-whisper/5.png b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/slient-whisper/5.png new file mode 100644 index 0000000..8a7bbcb Binary files /dev/null and b/list/thailand-cyber-top-talent-2024-senior-qualifier/images/network-security/slient-whisper/5.png differ