Category: Network forensic

Level: medium - 35 points

35 points if your team submits the flag. If you publish the associated source code/decoding tools-techniques to solve the challenge on GitHub along with the write-up it’s 5 additional points.

Challenge

Johnny has a friend called Warrior Pride working at the Navy. His friend, a network administrator, designed new protocols and especially unidirectional protocols. Warrior Pride recently joined the netwarcom team but remains a very active member of the internet community and participating to the IETF. Johnny doesn’t know what the exact role of his friend is at the Navy. Sometime Johnny received network packet captures from his friend but he had a strange feeling with a recent capture. You are here to know if Warrior Pride is betraying his friend…​ Take a look at his network capture:

SHA1

filename

555e57d38452fdcfe2bbea1a724b8228658ed3c6

network_capture.cap