An unusual sighting
Dernière mise à jour
Cet article vous a-t-il Γ©tΓ© utile ?
Dernière mise à jour
Cet article vous a-t-il Γ©tΓ© utile ?
CatΓ©gorie: Forensics DifficultΓ©: very-easy Flag: HTB{B3sT_0f_luck_1n_th3_Fr4y!!}
As the preparations come to an end, and The Fray draws near each day, our newly established team has started work on refactoring the new CMS application for the competition. However, after some time we noticed that a lot of our work mysteriously has been disappearing! We managed to extract the SSH Logs and the Bash History from our dev server in question. The faction that manages to uncover the perpetrator will have a massive bonus come the competition! Note: Operating Hours of Korp: 0900 - 1900
On a 2 fichiers :
sshd.log
: contient toutes les connexions et tentaives en SSH
bash_history.txt
: contient lβhistorique des commandes exΓ©cutΓ©es
Il faut se connecter Γ lβinstance du challenge (un simple socket brut) et rΓ©pondre au questions :
A 4h du matin, Γ©trange
Il faut aller voir dans le fichier bash_history.txt