$ cat writeup.md…
$ cat writeup.md…
hackthebox
Task: Analyze network traffic with Modbus/TCP packets. Solution: Filter for custom function code 102, extract hex data from Modbus Data field, decode to ASCII to get the flag.
Analysis of network traffic containing standard Modbus/TCP packets and unusual transactions with a custom function code.
In the provided traffic.pcapng file, Modbus/TCP traffic is observed. Standard Modbus functions (e.g., 1 — Read Coils, 3 — Read Holding Registers) are used for legitimate activity, however packets with function code 102 (0x66) stand out among them.
Using tshark or Wireshark filters allows quick isolation of these packets:
tshark -r traffic.pcapng -Y "mbtcp.func_code == 102"
Upon detailed examination of packets with code 102, it was noticed that they contain data in the Modbus Data field. In particular, frame 35 contains a long hexadecimal string.
tshark to extract data from frame 35.4854427b35306d3337316d33355f63753537306d5f70323037306330315f3432335f6e30375f336e30753968377d.hex_data = "4854427b35306d3337316d33355f63753537306d5f70323037306330315f3432335f6e30375f336e30753968377d" flag = bytes.fromhex(hex_data).decode('utf-8') print(flag)
Result: HTB{REDACTED}
$ cat /etc/motd
Liked this one?
Pro unlocks every complete writeup and expanded API access. $9/mo.
$ cat pricing.md$ grep --similar