CTF huntress 2 Oct - 31 Oct 2023

The web been archived at https://web.archive.org/web/20231002152434/https://huntress.ctf.games/

Reference:

https://www.huntress.com/blog/the-hackers-in-the-arena-the-huntress-ctf-retrospective

# Backdoored Splunk (Forensics)

Untitled

Once the instance started, I click the url given

Untitled

I explored the given file Splunk_TA_Windows.zip and study what kind of information available and I saw there’s bin folder contains script. Read a few line of the script, seem like we can use the script to connect to the server.

I use grep command to do search for info and I stumble an url similar to the challenge URL. It looks like a authorization header I saw earlier.

Untitled