forensicsmedium

The Trilogy of Death Volume I: Corel

srdnlen

Task: QCOW2 disk image of CorelLinux (dead 1999-2000 distro). Solution: Extract partitions, find .wcm WordPerfect macro with anomalous timestamp in /var/log/, bypass FAKE decoy XOR keys via known-plaintext attack on flag prefix.

$ ls tags/ techniques/
qcow2_to_raw_conversionpartition_extractiontimestamp_anomaly_detectionwordperfect_macro_analysisknown_plaintext_xor_attackred_herring_identification

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]