3.2 KiB
Day 01
We learn how to manipulate an AI chatbot using malicious prompts, also termed prompt injection.
Answers:
What is McGreedy's personal email address?
What is the password for the IT server room door?
BtY2S02
What is the name of McGreedy's secret project?
Purple Snow
Day 02
Here, we understand the basics of data science, including working with libraries such as pandas and matplotlib.
Answers:
How many packets were captured (looking at the PacketNumber)?
100
What IP address sent the most amount of traffic during the packet capture?
10.10.1.4
What was the most frequent protocol?
ICMP
Day 03
We use the programs crunch and hydra to generate passwords and enter them respectively.
Answers:
Using crunch and hydra, find the PIN code to access the control system and unlock the door. What is the flag?
THM{pin-code-brute-force}
Day 04
Answers:
We use the program cewl to generate username and password combinations to a list usernames.txt and passwords.txt. We then use the program wfuzz to enter them in brute-force fashion.
What is the correct username and password combination? Format username:password
isaias:Happiness
What is the flag?
THM{m3rrY4nt4rct1crAft$}
Day 05
We are put into a DOS environment and use the command line program EDIT to fix the file signature of an executable.
Answers:
How large (in bytes) is the AC2023.BAK file?
12,704
What is the name of the backup program?
BackupMaster3000
What should the correct bytes be in the backup's file signature to restore the backup properly?
41 43
What is the flag after restoring the backup successfully?
THM{0LD_5CH00L_C00L_D00D}
Day 06
We use a memory overflow bug through the game's debug mode to find the flag.
Answers:
If the coins variable had the in-memory value in the image below, how many coins would you have in the game?
1397772111
What is the value of the final flag?
THM{mchoneybell_is_the_real_star}
Day 07
We use the shell and basic unix commands to find the answers and flag.
How many unique IP addresses are connected to the proxy server?
9
How many unique domains were accessed by all workstations?
111
What status code is generated by the HTTP requests to the least accessed domain?
503
Based on the high count of connection attempts, what is the name of the suspicious domain?
frostlings.bigbadstash.thm
What is the source IP of the workstation that accessed the malicious domain?
10.10.185.225
How many requests were made on the malicious domain in total?
1581
Having retrieved the exfiltrated data, what is the hidden flag?
THM{a_gift_for_you_awesome_analyst!}
Day 08
We use the program FTK Image to scan for deleted files in a USB drive and find information relating to them.
What is the malware C2 server?
mcgreedysecretc2.thm
What is the file inside the deleted zip archive?
JuicyTomaToy.exe
What flag is hidden in one of the deleted PNG files?
THM{byt3-L3vel_@n4Lys15}
What is the SHA1 hash of the physical drive and forensic image?
39f2dea6ffb43bf80d80f19d122076b3682773c2