forensicsmedium

Obscure

hackthebox

Task: Analyze a PCAP and obfuscated PHP webshell to reconstruct attacker commands and find the flag. Solution: Deobfuscate a Weevely3 webshell to extract XOR key and markers, decrypt captured HTTP traffic to reveal attacker exfiltrated a KeePass database, crack it with John the Ripper, and read the flag from the database entry.

$ ls tags/ techniques/

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]