sadmind

forensics disk network linux FCSC 2023 solved on

star star

Description

Our intrusion detection system has identified abnormal behavior, which could be the caused by the same hacker as in a previous intrusion; he or she used the open-source software “Tiny SHell”. However, we do not know the goal sought by this attacker, and we hope that you will enlighten us. For this purpose, our team collected the following elements:

  • the disk image of the compromised machine (HD3.hda.xz),
  • traffic corresponding to the attack (sadmind.pcap).

Good luck!

Files

  • HD3.hda.xz
    111.97 MiB – 1388c76f397af59154eeafb940d1c12663fa9293b213b387496bfcad777faaf2
  • sadmind.pcap
    28.71 KiB – b4687a5ce9aa6fb16dc6a8d149814e39eb0361b688a7756cc775c0f85bcf7ad6

Author

cde

Flag

Share my success on Fediverse, Twitter, Linkedin, Facebook, or via email.

Submit your solution

You can submit your writeup for this challenge. Read the FAQ to learn how to proceed.

You need to be logged in to submit a writeup.

Writeups

There are no public solutions for this challenge yet, but you can submit yours after getting the flag.