bi0s
  •  Home
  •  Categories
  •  Archives
  •  Tags
  •  Home
  •  Categories
  •  Archives
  •  Tags

EV3 Player - HITCON Quals 2019

stuxn3t
2019-10-14
Forensics / Network

tl;dr

  • EV3 Robot pklg analysis
  • .RSF file recovery
Read More
EV3 Robot Wireshark HITCON

"...---..." - InCTF Internationals 2019

f4lc0n
2019-10-10
Forensics / Network

Write-Up for the “…—…” challenge from InCTF Internationals 2019

tl;dr

  1. Alert signals encoded in morse transfered to the Mi-Band
  2. Traverse through the packets and find the appropriate BLE handles of the encoded message
  3. Decode the morse encoded message
Read More
InCTFi Wireshark BLE Morse Code

Fresh From The Oven - InCTF Internationals 2019

g4rud4
2019-10-03
Forensics / Network

tl;dr

  • Decoding the strings found in TCP stream 0.
  • Analysing and extracting data sent via different ports of TCP.
  • Using character-wise caesar from the extracted data.
  • Zip cracking
Read More
InCTFi Wireshark Stego

Notch It Up - InCTF Internationals 2019

stuxn3t
2019-09-24
Forensics / Memory

tl;dr

  • Chrome history analysis
  • File recovery from the memory dump
  • Raw analysis of email content
  • Environment variables analysis
  • RAR password cracking
  • Corrupted file analysis
Read More
InCTFi Volatility Windows Memory Analysis

Just Do It - InCTF Internationals 2019

stuxn3t
2019-09-24
Forensics / Memory

tl;dr

  • Master File Table Analysis
  • Deleted file data recovery
Read More
InCTFi Volatility Windows Memory Analysis

SecurinetsQuals2019-Contact_Me

stuxn3t
2019-08-24
Forensics / Memory

tl;dr

  1. Analysis of memory dump using Volatility framework.
  2. Using mac_contacts plugin to get relevant data.
  3. Base64 decode to get flag.

Solved by: stuxn3t

Read More
MacOS Memory Analysis

FakeTCP - CyBRICS Quals 2019

f4lc0n
2019-07-25
Forensics / Network

tl;dr

  1. Open a raw socket.
  2. Craft the outgoing packets with the byte order of S-PORT, D-PORT, SEQ, ACK reversed.
  3. Establish the three way handshake in this fashion.
  4. Send “GET_FLAG” to the server.
Read More
CustomTCP

Acronym - ISITDTU Quals 2019

stuxn3t
2019-07-08
Forensics / Steganography

Full solution of Acronym challenge from ISITDTU Quals 2019.
tl;dr - Steganography

Read More
Steganography

Easy Husky - ISITDTU Quals 2019

stuxn3t
2019-07-08
Forensics / Memory

tl;dr - Volatility + Corrupted file analysis
Full solution of Easy Husky challenge from ISITDTU Quals 2019.

Read More
Windows Memory Analysis

 Previous 

3 / 3

Official blog of team bi0s

  Projects
  •   bi0s-wargame
    (Unraveling)
  •   bi0s-wiki
    (Free Encyclopedia)
  •   InCTF
    (Nationals CTF)
  •   InCTFj
    (Juniors CTF)

Made With Love and Coffee



Blog content follows the Attribution-NonCommercial-ShareAlike 4.0 International (CC BY-NC-SA 4.0) License

Use Material X as theme, total visits times.