forensicsPromedium
The Trilogy of Death Volume I: Corel
srdnlen
Task: QCOW2 disk image of CorelLinux (dead 1999-2000 distro). Solution: Extract partitions, find .wcm WordPerfect macro with anomalous timestamp in /var/log/, bypass FAKE decoy XOR keys via known-plaintext attack on flag prefix.
$ ls tags/ techniques/
qcow2_to_raw_conversionpartition_extractiontimestamp_anomaly_detectionwordperfect_macro_analysisknown_plaintext_xor_attackred_herring_identification
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [forensics][Pro]The Trilogy of Death Volume III: The Poisoned Apple— srdnlen
- [misc][Pro]Who4reu— TaipanByte
- [forensics][Pro]Colonel— tamuctf
- [forensics][Pro]Time Capsule— tamuctf
- [forensics][free]Lavender— alfactf