Writeup by NiveusEmi for Cap ou Pcap

intro forensics network

January 2, 2025

  1. Download the attached file cap.pcap
  2. To resolve this challenge, I used Wireshark
  3. Open the downloaded file with Wireshark
  4. While parsing packets, we can find some commands image
  5. Continue parsing the packets until you find interesting commands and returns:
  1. You can export the packet bytes into a zip file image
  2. Unzip it
  3. The flag is located into the file flag.txt