当前位置:网站首页>中科磐云—数据分析与取证数据包flag
中科磐云—数据分析与取证数据包flag
2022-07-04 04:12:00 【Beluga】
数据分析与取证
需要可私
1. 使用 Wireshark 查看并分析虚拟机 windows 7 桌面下的 attack.pcapng 数据包文件,通 过分析数据包 attack.pcapng 找出黑客的 IP 地址,并将黑客的 IP 地址作为 FLAG(形式:[IP 地址])提交:
tcp.connection.syn
通过分析端口,因为黑客都是扫描常用端口的
Flag:[172.16.1.102]
2. 继续查看数据包文件 attack.pacapng,分析出黑客扫描了哪些端口,并将全部的端口作 为 FLAG(形式:[端口名 1,端口名 2,端口名 3…,端口名 n])从低到高提交:
tcp.connection.syn and ip.src==172.16.1.102
Flag:[21,23,80,445,3389,5007]
3. 继续查看数据包文件 attack.pacapng 分析出黑客最终获得的用户名是什么,并将用户 名作为 FLAG(形式:[用户名])提交:
http.request.method==POST
Flag:[Lancelot]
4. 继续查看数据包文件 attack.pacapng 分析出黑客最终获得的密码是什么,并将密码作 为 FLAG(形式:[密码])提交:
http.request.method==POST
flag:[12369874]
5. 继续查看数据包文件 attack.pacapng 分析出黑客连接一句话木马的密码是什么,并将 一句话密码作为 FLAG(形式:[一句话密码])提交:
Ctrl+f
Flag:[alpha]
6. 继续查看数据包文件 attack.pacapng 分析出黑客下载了什么文件,并将文件名及后缀 作为 FLAG(形式:[文件名.后缀名])提交:
http.request.method==POST
flag:[flag.zip]
7. 继续查看数据包文件 attack.pacapng 提取出黑客下载的文件,并将文件里面的内容为 FLAG(形式:[文件内容])提交:
binwalk -eM attack.pcapng
flag:[ flag{Manners maketh man}]
边栏推荐
- 《Cross-view Transformers for real-time Map-view Semantic Segmentation》论文笔记
- Annexe VI: exposé sur les travaux de défense. Docx
- Error response from daemon: You cannot remove a running container 8d6f0d2850250627cd6c2acb2497002fc3
- Rhcsa 06 - suid, sgid, sticky bit (to be added)
- @Feignclient comments and parameters
- 附件一:202x年xxx攻防演习授权委托书
- MAUI 入门教程系列(5.XAML及页面介绍)
- 红队视角下的防御体系突破之第一篇介绍、阶段、方法
- Share some of my telecommuting experience
- Test cs4344 stereo DA converter
猜你喜欢
![[Yugong series] go teaching course 001 in July 2022 - Introduction to go language premise](/img/f2/3b95f53d67cd1d1979163910dbeeb8.png)
[Yugong series] go teaching course 001 in July 2022 - Introduction to go language premise

Correct the classpath of your application so that it contains a single, compatible version of com.go

appliedzkp zkevm(13)中的Public Inputs

Unity中RampTex介绍和应用: 溶解特效优化

Distributed cap theory

rac删除损坏的磁盘组

Talking about JVM

6-5 vulnerability exploitation SSH weak password cracking and utilization

The "functional art" jointly created by Bolang and Virgil abloh in 2021 to commemorate the 100th anniversary of Bolang brand will debut during the exhibition of abloh's works in the museum

牛客小白月赛49
随机推荐
【MATLAB】MATLAB 仿真模拟调制系统 — FM 系统
The paddlehub face recognition scheme is deployed, and the trained model is deployed and applied in pytchrom
GUI application: socket network chat room
定制一个自己项目里需要的分页器
CRS-4013: This command is not supported in a single-node configuration.
附件四:攻击方评分标准.docx
@Feignclient comments and parameters
Sample template of software design document - learning / practice
6-4漏洞利用-SSH Banner信息获取
Wobo Union ended its strategic evaluation and decided to retain Bozi's business with excellent performance
cmake
Experience sharing of epidemic telecommuting | community essay solicitation
Unity中RampTex介绍和应用: 溶解特效优化
郑州正清园文化传播有限公司:针对小企业的7种营销技巧
Maui introductory tutorial series (5.xaml and page introduction)
由于使用flash存放参数时,擦除掉了flash的代码区导致进入硬件错误中断
QT qtableview data column width adaptation
Deep parsing structured exception handling (SEH) - by Matt Pietrek
拼夕夕二面:说说布隆过滤器与布谷鸟过滤器?应用场景?我懵了。。
Correct the classpath of your application so that it contains a single, compatible version of com. go