Skip to content

Commit 94f20d2

Browse files
committed
HiddenGem finalize2
1 parent 1b2a678 commit 94f20d2

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

content/ctfwriteups/hgm.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -372,7 +372,7 @@ Decrypting Credential:
372372
```
373373
So the whole flag is: `idek{crEDential_4C3S5_f0R_1@73rAl_mOv3M3n7}`
374374

375-
## Part 3 -
375+
## Part 3 - DNS Exfiltration and reconstruction
376376
The previous flag can be used as a hint on how to move on, since we still have a big .pcap we have not touched upon and I already felt a bit lost at this point.
377377

378378
The flag from part 2 refers to `stealing credentials in order to do lateral movement`. We can also see that the second part of the flag was from a target domain with IP address `192.168.209.134`. Searching this IP address inside `Autopsy` as we previously did, we see logs related to RDP connection:

0 commit comments

Comments
 (0)