| my rAnd0m m1ndfl0w |
| #whoami $bl0g /script.s |
The Nixu Challenge - 2019 - Ports --------------------------------- So this one was about inspecting and analyzing a PCAP packet capture. Started by following TCP-stream in Wireshark, but the capture contained too many streams, every single line is one stream. As the name of the challenge is ports, decided to take a look at the used ports. Source ports were on the far end and quite high, but the destination ports were on the lower end: 81 86 90 76 83 72 116 109 98 72 112 118 89 110 108 109 88 50 53 104 99 86 57 104 97 72 112 118 99 109 86 109 88 50 53 108 99 108 57 122 97 71 70 102 90 50 74 102 89 51 108 117 98 70 57 113 100 109 100 49 102 81 61 61 The sequence can't be hex, looks more like decimals. Decided to convert from decimals to characters with CyberChef: QVZLSHtmbHpvYnlmX25hcV9haHpvcmVmX25lcl9zaGFfZ2JfY3lubF9qdmd1fQ== Well that's most def. base64. Let's decode:
AVKH{flzobyf_naq_ahzoref_ner_sha_gb_cynl_jvgu}
Seems to be Caesar cipher or most likely ROT13. Let's try ROT13 decrypting:
NIXU{symbols_and_numbers_are_fun_to_play_with}
|