Network Detective
[Unbreakable 2023]
- Open the network-detective capture with wireshark
- Open the HTTP packet
- We know that HTTP does not encrypt data we should see the following result:
data:image/s3,"s3://crabby-images/2056d/2056d7d07d4a42686fb5be7830c8422aa2b81359" alt="wireshark capture"
- The X-HERE header is an unusual header furthermore we notice that the data is quiet suspicious and looks like a ROT
encryption because if we shift from 1 to right, DUG gave is CTF which is the flag format.
- Go to rot-cipher and enter the data string
- Select ROT 1 (which is equal to shift one to right)
- Select full ASCII table
- Here you go :)
data:image/s3,"s3://crabby-images/45b63/45b63cfda8c0fcb24292919281cb6f7034b7137c" alt="get the flag"