Project Sekai
🔒 CrewCTF 2023 / 🩸-forensics-quirky
Sutx
BOT
07/07/2023 10:02 PM
Quirky - 1000 points
Category:
Forensics
Description:
Quirky ? yes Author : Fredd
Files:
https://crewc.tf/files/0b1666278e6bb041b61c6fcfc480e98e/chall.pcap?token=eyJ1c2VyX2lkIjoyMSwidGVhbV9pZCI6MTYsImZpbGVfaWQiOjIzfQ.ZKjt5Q.qu0IVqrpyFNqSrf34zDEIrRIhD0
Tags:
No tags.
Sutx
pinned
a message
to this channel.
07/07/2023 10:02 PM
Sutx
BOT
07/07/2023 10:10 PM
@Surg
wants to collaborate
Surg
07/07/2023 10:18 PM
tcp_stream outputs this jpeg
22:18
ok
Sutx
BOT
07/08/2023 2:31 AM
@Violin
wants to collaborate
Sutx
BOT
07/08/2023 5:09 AM
@Guesslemonger
wants to collaborate
Guesslemonger
07/08/2023 5:09 AM
there is an alternate http stream forcefully fed with scapy
05:10
lot of malformed packets, i manually carved all data but still some error
Sutx
BOT
07/08/2023 5:31 AM
@Legoclones
wants to collaborate
Legoclones
07/08/2023 6:58 AM
I've extracted about half of the alternate http stream, exiftool says there are unknown bytes after segments. Extra data somewhere
Guesslemonger
07/08/2023 6:59 AM
packets are fucked, there is data in even http headers
06:59
ff d9 marker is in one of http header data
(edited)
Legoclones
07/08/2023 7:00 AM
which packet?
Guesslemonger
07/08/2023 7:01 AM
398
Guesslemonger
07/08/2023 8:08 AM
this chal looks broken most likely, ff db markers are missing
08:08
not wasting time on it
08:08
since no reply on modmail too
sahuang
07/08/2023 8:08 AM
yeah it could be broken
08:08
author is dead too
Legoclones
07/08/2023 8:08 AM
oh fredd is author huh
Guesslemonger
07/08/2023 8:09 AM
in packet 10, it should start with ff db, instead of just db
08:09
since previous packet has full ff db marker
08:09
more markers might be broken going further
08:09
if jpeg full blown repair is also intentional, then idk
Legoclones
07/08/2023 8:09 AM
hmm the first packet is missing the
H
for
HTTP
...
08:10
maybe that's the quirk, is that the first byte is missing on some or all packets?
Guesslemonger
07/08/2023 8:14 AM
yup
08:14
that is the case, this chall is broken
08:15
ff d4 markers also has 1 byte missing
08:15
it's length is 1A but only 19 bytes
08:15
since first byte is missing
sahuang
07/08/2023 8:16 AM
skip this chal lol until fix
08:16
or tell admin
Guesslemonger
07/08/2023 8:16 AM
not ready to admit it is broken lol
sahuang
07/08/2023 8:17 AM
they said its correct
08:17
moriarty solved
Guesslemonger
07/08/2023 8:17 AM
f, repairing manually then
Legoclones
07/08/2023 8:18 AM
f
Guesslemonger
used /ctf submit
Sutx
BOT
07/08/2023 8:18 AM
❌ Incorrect flag.
08:19
❌ Incorrect flag.
sahuang
07/08/2023 8:20 AM
Guesslemonger
used /ctf submit
Sutx
BOT
07/08/2023 8:20 AM
❌ Incorrect flag.
Guesslemonger
07/08/2023 8:20 AM
almost there, have asked for a sanity check
08:21
but it is broken, since missing bytes. if adding bytes is also intended then sure
Guesslemonger
used /ctf submit
Sutx
BOT
07/08/2023 8:24 AM
❌ Incorrect flag.
08:25
Well done, you got first blood!
Guesslemonger
07/08/2023 8:25 AM
they had a typo in flag
sahuang
07/08/2023 8:25 AM
lol
08:26
dont tell them
08:26
other teams suffer
Guesslemonger
07/08/2023 8:26 AM
no, they corrected it
sahuang
07/08/2023 8:26 AM
o
Guesslemonger
07/08/2023 8:26 AM
only then i was able to submit
Legoclones
07/08/2023 8:26 AM
did u add missing bytes?
Guesslemonger
07/08/2023 8:27 AM
yes
08:27
image data didn't need it, but i had to correct markers
08:27
image was kinda visible
Legoclones
07/08/2023 8:27 AM
gotcha, just fixed headers to see image
Guesslemonger
07/08/2023 8:27 AM
i would like to see their solution lol
Exported 60 message(s)