题目提供了一个chall.pcap流量包。
用wireshark打开,可以发现只有TCP包,且源和目的IP都是相同的。
我们再看data部分,发现是A与B之间的通信。
追踪TCP流:
Hi Rain Turkey
Nice Meeting you D4663R!!
I am have secret message retrived from Russia Army which could highly help Ukraine
Ohh is it form of text or morse code or did they use any form of encryption
I have found the message but I am sharing with you inform of PNG image
Got it!
I hope you have got all checksum which I send you in mail
Yah got them.
Now I am sending
Ok
7a
Mismatch, It should be 7647966b7343c29048673252e490f736
可以知道,通信流量传输的是一张PNG图片。而且,使用明文或哈希值进行传输。
如果传输的数据是错误的,回复消息会提示“7aMismatch, It should be”。
先提取出tcp.payload字段: