NCS Competition 2021 Writeup
  • HHousen National Cyber Scholarship Competition 2021 Writeup
  • Forensics
    • FE02 - 100pts
    • FE03 - 100pts
    • FH01 - 500pts
    • FE04 - 100pts
    • FM01 - 250pts
    • FM02 - 250pts
    • FM03 - 250pts
    • FE01 - 100pts
  • Crypto
    • CM01 - 250pts
    • CM02 - 250pts
    • CX01 - 1000pts
    • CH01 - 500pts
    • CH02 - 500pts
  • Binary
    • BM01 - 250pts
    • BM02 - 250pts
    • BM03 - 250pts
    • BX01 - 1000pts
    • BX02 - 100pts
    • BE01 - 100pts
    • BE02 - 100pts
    • BH01 - 500pts
  • Networking
    • NM01 - 250pts
    • NE01 - 100pts
  • Web
    • WX01 - 1000pts
    • WE01 - 100pts
    • WE02 - 100pts
    • WH01 - 500pts
    • WH02 - 500pts
    • WM01 - 250pts
    • WM02 - 250pts
    • WM03 - 250pts
    • WM04 - 250pts
    • WM05 - 250pts
  • Challenge Name
Powered by GitBook
On this page
  • Briefing
  • Solution
  • Flag

Was this helpful?

Edit on Git
  1. Forensics

FE01 - 100pts

PreviousFM03 - 250ptsNextCrypto

Last updated 4 years ago

Was this helpful?

Briefing

Download the file and find a way to get the flag. Contents: fe01.ost

Challenge Files:

Solution

  1. We can run file fe01.ost to determine that fe01.ost is a Microsoft Outlook email folder.

  2. Searching online for a program that can read this identifies pffexport, which can be installed with sudo apt install pff-tools.

  3. We can extract the content with pffexport fe01.ost and cd into fe01.ost.export.

  4. Run find . -type d -empty -delete in fe01.ost.export to delete all empty directories.

  5. Searching the folder for flag shows that Root - Mailbox/IPM_SUBTREE/Inbox/Message00018/Attachments has a ZIP file called 1_flag.zip (as an attachment to the Message00018 email) that is password protected.

  6. Looking around some more reveals that the calendar contains the key. Root - Mailbox/IPM_SUBTREE/Calendar/Appointment00001/Appointment.txt has the name c]5p@S7K/z}Z!Q - 11am meeting with Chris so c]5p@S7K/z}Z!Q is the password.

  7. Extracting the 1_flag.zip with c]5p@S7K/z}Z!Q as the password shows an image flag.jpg with the flag in it.

Flag

pst_i'm_in_here!

fe01.zip