data:image/s3,"s3://crabby-images/0e00c/0e00cf6ce532c3146f497d990d898320cd9006fd" alt=""
As usual, start your CTF by read the question/description that indeed “very helpful” XD
Download the “evidence.zip” & extract it. You’ll get the folders like below:
data:image/s3,"s3://crabby-images/20fed/20fed2b957deeb8064192258452b6816603c2796" alt=""
So I randomly checked under the svc_wgmy folder, the most interesting folder is on Desktop
:
data:image/s3,"s3://crabby-images/85c23/85c230a2ac2e65e75ac8fa22ffd4c3d4c391fb73" alt=""
I see there’s a file named “flag.png”. But when I try to view it, it shows error:
data:image/s3,"s3://crabby-images/233a9/233a9d0caca017f6522028c773fcadae7b8d1639" alt=""
hmm. Let’s see what filetype is this:
data:image/s3,"s3://crabby-images/7db03/7db03caed9c15688aaa9e6fa249ec820852da53a" alt=""
Oh! It’s a Zip archive. Let’s open it using 7-Zip:
data:image/s3,"s3://crabby-images/7bcfe/7bcfe01cec5034e3a494824a0f4f0a41ab2098c4" alt=""
Enter password? Hmm.. But I don’t have the password. Let’s search for password in the evidence given.
I tried checked on \evidence\svc_wgmy\AppData\Local\Google\Chrome\User Data
; to see if Chrome browser history might have clue or password. But its empty.
So I go check on \evidence\svc_wgmy\AppData\Local\Microsoft\Terminal Server Client\Cache
folder:
data:image/s3,"s3://crabby-images/f997c/f997c14f65336cca597a70fb353f69495d567e11" alt=""
It contains 2 file; .bmc & .bin file.
I went to search for those 2 file extension & came across with this site – https://www.forensicfocus.com/forums/general/remote-desktop-cache-files/
hommy0 (@hommy0) Posts: 98 Trusted Member I'm not sure if this will help, available from the Guidance Software website. It mentions that it can be used to extract images from the files with *.bmc and *.bin extension. https://www.guidancesoftware.com/app/RDP-Cached-Bitmap-Extractor Regards
Hmm.. RDP Cached Bitmap Extractor. So its related to something something RDP image something something :p
So I went to use tool from here:
I use the “-b/–bitmap” option – Provide a collage bitmap aggregating all the tiles.
data:image/s3,"s3://crabby-images/85bac/85bac43d6305c962171ebf618615bc65c8174226" alt=""
After the operation complete, you’ll get a file “*_collage.bmp“. If you look carefully, you’ll see an “Enter password” image/screenshot:
data:image/s3,"s3://crabby-images/cd2cc/cd2cc56f2aaef6d97ffe274fd31604649d3e3c78" alt=""
Enter the password that you see from .bmp file to open the flag.txt inside flag.zip:
data:image/s3,"s3://crabby-images/dc9d1/dc9d1b8e47ff02282108cd723aeff672acb4b947" alt=""
Note: I guess the hint “Where aRe you?” probably want to hint about RDP? Maybe…