Torrent Analyze
Description
SOS, someone is torrenting on our network.
One of your colleagues has been using torrent to download some files on the company’s network. Can you identify the file(s) that were downloaded? The file name will be the flag, like picoCTF{filename}
. Captured traffic.
Solving
- Loading the pcap file into wireshark and started looking at it.
- At the beginning it does some dns resolution for ubuntu.com
- Then I activated the DHT Protocoll and looked for
info_hash
keys (because of the title of the chall). - I found some info_hashes and searched in google 🙂
- One of the hashes points to the ISO from ubuntu server. I tried that one.