Writeup FTP - authentication ROOT-ME

Pagi ini saya akan berbagi cara bagaimana menjawab challenges dari http://www.root-me.org/en/Challenges/Network/FTP-authentication

Statement

An authenticated file exchange achieved through FTP. Recover the password used by the user.

1. Cek file challenges
root@MasIcal:~/Downloads# file ch1.pcap 
ch1.pcap: Little-endian UTF-16 Unicode text, with CRLF line terminators

2. Formatnya pcap, namun kok unciode text ? hmm kita rubah dulu ke pcap
root@MasIcal:~/Downloads# tshark -r ch1.pcap -w ftp.pcap

3. Cek lagi file challengesnya yang direwrite ke ftp.pcap
root@MasIcal:~/Downloads# file ftp.pcap 
ftp.pcap: pcap-ng capture file - version 1.0

4. Pengecekan user dan password dengan menggunakan strings
root@MasIcal:~/Downloads# strings ftp.pcap | grep -P "USER|PASS"
USER cdts3500
PPASS cdts3500


Jadi jawaban dari challenges kali ini adalah cdts3500

Related Posts:

0 Response to "Writeup FTP - authentication ROOT-ME"

Post a Comment