forensicsmedium
Obscure
hackthebox
Task: Analyze a PCAP and obfuscated PHP webshell to reconstruct attacker commands and find the flag. Solution: Deobfuscate a Weevely3 webshell to extract XOR key and markers, decrypt captured HTTP traffic to reveal attacker exfiltrated a KeePass database, crack it with John the Ripper, and read the flag from the database entry.
$ ls tags/ techniques/
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]