Jump to content
Tuts 4 You

LabyREnth Capture the Flag (CTF) Challenge - 2017


Recommended Posts

Posted

@crystalboy

  Reveal hidden contents


 

Posted

guys, any hint about a good tool to parse HWP files for docs #3?

Posted

Microsoft converter. Or you can Google for challenge authors' name and HWP to find explanation of file format.

Posted (edited)
  On 6/17/2017 at 8:36 PM, Etor Madiv said:

@kao

  Reveal hidden contents

 

Expand  
  Reveal hidden contents

 

Edited by imaqt
Posted

Can I borrow a Mac from you guys, I will not be able to continue binary challenges because Binary #4 is an osxransomware

Posted

You can get VM images of OSX 10.12, for instance

Posted

anyone here solved mobile 1 ? this seems to have no logic :wacko:

Posted

@NotSure: yes. It does have logic and is perfectly solvable.

 

Posted

Thanks @kao got the Microsoft converter to work now.

Posted
  On 6/20/2017 at 1:01 PM, pop said:

Its getting an exception because the number is too big to parse

Expand  

Well, then you need to find a much smaller number..

  Reveal hidden contents

 

Posted (edited)

For mobile #1, here is solution i found leaked online, but still have no idea how to get that value.

  Reveal hidden contents

 

Edited by Loki
No solutions please
Posted

@Etor Madiv: please don't spoil the fun by giving full solutions! It's just ruining the game. :(

  • Like 2
Posted

Could anyone point me in the right direction for Docs #2 ? At least I think its docs 2, not sure because I did a bunch of the random challenges as well ... but its the ppt with vb that has 2 embeded word docs in it with some vb ... literally spent so many hours on it and tried every tool I can think of/find in windows and linux ... just keep hitting a brick wall. Would appreciate if anyone can suggest anything.

Posted

Can anyone plz help with binary 01,

  Reveal hidden contents

Plz plz plz helps, I only want to complete binary01 to get the noob track done.

Posted

@Loki

why not delete the whole reply in the first place and I will be fine if you sent me a notification privately expressing that one should not post full solutions. unless if you forgot to add that rule to The Board Rules.

Posted

@re_sigh: You mean "Please help me find the n33dle_challenge_File.ppt"? That's Random #5.

  Reveal hidden contents

 

Posted

@kao: Yeah I did notice some embedded OCX stuff when I initially pulled the docs out but it didn't work well in my version of office (2016) with compatibility settings, so I guess I'll give a different version a shot. Thanks for the tip in any case. ;)

Posted (edited)

@DivBy0

  Reveal hidden contents

 

Edited by crystalboy
Posted (edited)

Has anyone solved Level 2 in Binary #5? I truly hate that part as it has nothing to do with reversing.

 

EDIT: nevermind, solved. This and Programming #3 are great examples of how to ruin otherwise really fun challenge. :(

 

Edited by kao
Posted

I have some more time this weekend for reversing, my question is: do you really need a VM for the Binary #3? Or can I overcome those checks for virtual machine and continue running the application on my PC? Like are there certain values from the VM necessary for the Flag or can I skip that whole part and try to modify the binary so it will run on my pc without VM?

 

  Reveal hidden contents

 

Posted

@Castor: No, you don't *need* it. In fact, I did 95% of analysis in IDA. But debugging goes so much faster with VM as you can focus on reversing instead of trying to modify binary to make it run.

  Reveal hidden contents

 

  • Like 1
Posted
  On 6/21/2017 at 6:17 PM, Etor Madiv said:

@Loki

why not delete the whole reply in the first place and I will be fine if you sent me a notification privately expressing that one should not post full solutions. unless if you forgot to add that rule to The Board Rules.

Expand  

1. I havent given you a warning, just removed part of your post. I saw no need to delete your post and see little need to justify editing it either tbh

2. Board rules are board rules, there are many things we could spell out in there but choose not to. We expect some common sense and general courtesy. We also reserve the right to remove content, even though we censor very little. Again, I dont really feel the need to justify moderating your post (hence no PM etc) but I am doing so out of courtesy because you have asked.

Posted
  On 6/10/2017 at 5:25 PM, evandrix said:

i'm stuck on Document #3 - got the images from usb.pcap, then what?

Expand  

I got the second half of the flag, any hints where to look for the first half?

Posted
  On 6/26/2017 at 9:48 PM, fasya said:

I got the second half of the flag, any hints where to look for the first half?

Expand  

Look back! You have missed it.

It is way easier than part1.

Posted
  On 6/27/2017 at 2:39 AM, tec said:

Look back! You have missed it.

It is way easier than part1.

Expand  

yup I know it must be back but cant find exactly where it was, pdf, hwp or javascript

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...