A digital identity inspired by Oman was transmitte...
Créé le : 14 juillet 2026
Répondu en utilisant GPT-5.6 Thinking par Chat01
Créé le : 14 juillet 2026
Répondu en utilisant GPT-5.6 Thinking par Chat01
A digital identity inspired by Oman was transmitted across the network, but the data was divided and hidden among thousands of packets.
Analyze the captured traffic and recover the final identity code.
Flag Format: 1940{...}
solved challenge rồi viết writeup
Đã solve xong.
Flag: 1940{0M4N1_N3TW0RK_H1DD3N_M3SS4G3}
:::writing{variant="document" id="68421"}
Capture chứa hai lớp dữ liệu bị che giấu:
Quy trình giải:
textPCAP ├── Reassemble 9 TCP streams có header OMN │ └── oman_artifact.jpg │ └── Khôi phục 4 key fragments ├── Hex ├── Base64 ├── ROT13 └── Reverse ↓ we@are@omani@team ↓ Steghide extraction ↓ final_identity.txt ↓ 1940{0M4N1_N3TW0RK_H1DD3N_M3SS4G3}
Mặc dù file có đuôi .pcapng, magic bytes cho thấy đây thực chất là classic PCAP.
Capture có tổng cộng 3665 packet:
| Protocol | Packet |
|---|---|
| TCP | 2275 |
| UDP | 744 |
| ICMP | 426 |
Trong capture có rất nhiều traffic đánh lạc hướng:
XYZ.not-the-real-pass.we@are@testing@only.Điểm đáng chú ý là các TCP stream gửi tới port 4919.
Wireshark filter:
texttcp.dstport == 4919 && tcp.len > 0
Có 9 TCP stream thật từ:
text10.40.19.77 → 10.40.19.200:4919
Mỗi stream bắt đầu bằng header tùy biến:
textOffset Size Nội dung 0 3 Magic "OMN" 3 1 Chunk index 4 1 Tổng số chunk 5 4 Chunk length, big-endian 9 N Chunk data
Các chunk:
| Index | Source port | Body length |
|---|---|---|
| 0 | 8981 | 38784 |
| 1 | 33111 | 38784 |
| 2 | 39809 | 38784 |
| 3 | 14807 | 38784 |
| 4 | 8758 | 38784 |
| 5 | 64147 | 38784 |
| 6 | 54543 | 38784 |
| 7 | 21359 | 38784 |
| 8 | 31026 | 38780 |
Sau khi TCP reassembly, bỏ 9 byte header của từng stream và nối body theo thứ tự chunk:
pythonartifact = b"".join(chunks[i] for i in range(9))
Kết quả:
textFile: oman_artifact.jpg Size: 349052 bytes Type: JPEG JFIF, 1600 × 1200 SHA-256: c2414ac003839cc226b4300affb34c696a59cd487ee267a118767068920d3587
Ảnh thu được là phong cảnh Oman và có chữ OMAN. Tuy nhiên, flag không xuất hiện trực tiếp trong ảnh, cho thấy còn một lớp steganography.
Bốn fragment thật nằm gần cuối capture.
DNS query:
textvault-key.archive.oman-lab.local
TXT response chứa:
text1:776540
Giải hex:
text77 65 40 → we@
ICMP payload:
textKEYFRAG:2:YXJlQA==
Base64 decode:
textYXJlQA== → are@
HTTP request:
httpGET /heritage/session-check HTTP/1.1 Host: archive.oman-lab.local Cookie: keyfrag=3:bznav@
Áp dụng ROT13:
textbznav@ → omani@
TCP payload:
textCTRL:4:maet
Đảo ngược chuỗi:
textmaet → team
textwe@ + are@ + omani@ + team
Passphrase hoàn chỉnh:
textwe@are@omani@team
Có thể dùng trực tiếp steghide:
bashsteghide extract \ -sf oman_artifact.jpg \ -p 'we@are@omani@team'
File được trích:
textfinal_identity.txt
Nội dung:
textCongratulations. You recovered the hidden Omani transmission. Flag: 1940{0M4N1_N3TW0RK_H1DD3N_M3SS4G3}
Do môi trường giải không có sẵn steghide, payload cũng được trích bằng cách tái hiện thuật toán trên JPEG:
libjpeg đọc các hệ số DCT khác 0.Header thu được:
textMagic: 0x73688d Version: 0 Algorithm: rijndael-128 Mode: CBC Plaintext size: 1145 bits
Một số thông số khác:
textNon-zero DCT coefficients: 252845 Compressed payload: Yes Uncompressed size: 1017 bits Embedded filename: final_identity.txt Payload length: 104 bytes
Cài dependency:
bashpython3 -m pip install -r requirements.txt
Máy cần có gcc và thư viện phát triển libjpeg.
Chạy solver:
bashpython3 solve.py Echoes_of_Oman.pcapng -o extracted
Output:
text[+] Parsed 3665 packets [+] Rebuilt JPEG: extracted/oman_artifact.jpg [+] Passphrase: we@are@omani@team [+] Extracted file: extracted/final_identity.txt [+] FLAG: 1940{0M4N1_N3TW0RK_H1DD3N_M3SS4G3}
text1940{0M4N1_N3TW0RK_H1DD3N_M3SS4G3}
Điểm chính của challenge là không bị đánh lừa bởi các token giả trong HTTP. Artifact thật được nhận diện nhờ header OMN nhất quán và chỉ số chunk rõ ràng.
Sau khi khôi phục JPEG, passphrase phải được tổng hợp từ nhiều giao thức và nhiều phép biến đổi khác nhau. Đây là sự kết hợp giữa TCP stream reconstruction, protocol analysis, encoding và JPEG steganography. :::
Phần extractor thủ công đã được đối chiếu với mã nguồn Steghide/Stegseek về magic header, selector dựa trên MD5, parity của hệ số DCT và việc sử dụng ba sample cho mỗi vertex bit. (GitHub)
Tệp kết quả: [Gói solution đầy đủ] · Writeup Markdown · Solver Python · [C helper đọc DCT] · Ảnh đã khôi phục · Payload chứa flag
Bản Markdown hiện phù hợp để nộp CTF; có thể rút gọn lại theo format CTFtime hoặc blog kỹ thuật.