<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" 
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
>
<channel xml:lang="fr">
<title>Root Me : plateforme d'apprentissage d&#233;di&#233;e au Hacking et &#224; la S&#233;curit&#233; de l'Information</title>
<link>https://www.root-me.org/</link>
<description>Root Me est une plateforme permettant &#224; chacun de tester et d'am&#233;liorer ses connaissances dans le domaine de la s&#233;curit&#233; informatique et du hacking &#224; travers la publication de challenges, de solutions, d'articles.</description>
<language>fr</language>
<generator>SPIP - www.spip.net</generator>
<image>
<title>Root Me : plateforme d'apprentissage d&#233;di&#233;e au Hacking et &#224; la S&#233;curit&#233; de l'Information</title>
<url>https://www.root-me.org/local/cache-vignettes/L144xH144/siteon0-9a1b1.svg?1757799377</url>
<link>https://www.root-me.org/</link>
<height>144</height>
<width>144</width>
</image>
<item xml:lang="es">
<title>Trusted</title>
<link>https://www.root-me.org/es/Desafios/Forense/Trusted</link>
<guid isPermaLink="true">https://www.root-me.org/es/Desafios/Forense/Trusted</guid>
<dc:date>2026-04-21T10:11:53Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>es</dc:language>
<dc:creator>
BoBNewz
</dc:creator>
<dc:subject>Moyen</dc:subject>
<description>
&lt;p&gt;You are called to investigate an employee's machine. For some time now, strange things have been happening on his computer, and the employee has lost access to his passwords.&lt;br class=&#034;autobr&#034; /&gt;
An initial investigation has confirmed the presence of a malicious individual on the machine.&lt;/p&gt;
&lt;p&gt;We ask you to find&#160;:&lt;/p&gt;
&lt;p&gt; - The CVE used by the attacker to gain initial access.&lt;br class=&#034;autobr&#034; /&gt; - The password of the employee's e-mail account.&lt;br class=&#034;autobr&#034; /&gt; - The attacker's IP address.&lt;br class=&#034;autobr&#034; /&gt; - The C2 used by the attacker (e.g. Havoc).&lt;br class=&#034;autobr&#034; /&gt; - The ID of the persistence sub-technique according to MITRE ATT&amp;CK.&lt;/p&gt;
&lt;p&gt;The flag is as folllows&#160;: RM{CVE-XXXX-XXXXX_password_attacker-IP_attacker-C2_MITRE-ATT&amp;CK-ID}&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;sha256sum&lt;/strong&gt;&#160;: 29cade26d102e12191f49a72da235b0eeca8953725c85a090beb0b81a95d45ff&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/es/Desafios/Forense/" rel="directory"&gt;Forense&lt;/a&gt;
</description>
</item>
<item xml:lang="es">
<title>Invocation</title>
<link>https://www.root-me.org/es/Desafios/Forense/Invocation</link>
<guid isPermaLink="true">https://www.root-me.org/es/Desafios/Forense/Invocation</guid>
<dc:date>2026-04-21T10:11:48Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>es</dc:language>
<dc:creator>
BoBNewz
</dc:creator>
<dc:subject>Difficile</dc:subject>
<description>
&lt;p&gt;A hacker infiltrated a company's system and encrypted an essential file.&lt;br class=&#034;autobr&#034; /&gt;
Fortunately, a memory dump of the victim machine was carried out, along with the recovery of some network traces.&lt;/p&gt;
&lt;p&gt;Analyze events and retrieve the contents of this file&#160;!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;sha256sum&lt;/strong&gt;&#160;: aaba88eb944aaf65af1c261a291be20a2e1a34e09a7575a8362767cb389be6a2&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/es/Desafios/Forense/" rel="directory"&gt;Forense&lt;/a&gt;
</description>
</item>
<item xml:lang="es">
<title>ICMP exfiltration</title>
<link>https://www.root-me.org/es/Desafios/Forense/ICMP-exfiltration</link>
<guid isPermaLink="true">https://www.root-me.org/es/Desafios/Forense/ICMP-exfiltration</guid>
<dc:date>2026-04-21T10:11:43Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>es</dc:language>
<dc:creator>
M4tou
</dc:creator>
<dc:subject>Moyen</dc:subject>
<description>
&lt;p&gt;Your SOC has detected a successful intrusion on an administration server. The intrusion was carried out from the outside using the administrator's password, although he was not present at the time. We suspect that his password had been previously compromised ,but there is no trace of this on the IDS.&lt;/p&gt;
&lt;p&gt;However, N1 SOC analysts isolated suspicious ICMP traffic the previous day. The alert criterion was the length and shape of the load, which was inconsistent with Linux.&lt;br class=&#034;autobr&#034; /&gt;
The CSIRT team deployed on site succeeded in recovering a suspicious binary, whose name seems to be directly linked to the SOC detection.&lt;/p&gt;
&lt;p&gt;Find the exfiltrated data&#160;!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;sha256sum&lt;/strong&gt;&#160;: c5d9abda3504725a90fed54c27fc4ccea8510315dbc1daac7934f0e5841986e3&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/es/Desafios/Forense/" rel="directory"&gt;Forense&lt;/a&gt;
</description>
</item>
<item xml:lang="es">
<title>Heist of the century</title>
<link>https://www.root-me.org/es/Desafios/Forense/Heist-of-the-century</link>
<guid isPermaLink="true">https://www.root-me.org/es/Desafios/Forense/Heist-of-the-century</guid>
<dc:date>2026-04-21T10:11:33Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>es</dc:language>
<dc:creator>
Ayweth20
</dc:creator>
<dc:subject>Moyen</dc:subject>
<description>
&lt;p&gt;Two young criminals have carried out a robbery at the town's bank.&lt;/p&gt;
&lt;p&gt;The police managed to arrest them as they left the bank, but they need your help. It seems they have seized the two criminals' phones but have been unable to unlock them. They are counting on you to help them unlock these phones by providing the PIN (apparently an 8-digit code) and the password.&lt;/p&gt;
&lt;p&gt;Format : RM{PIN:PASSWORD}&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;sha256sum&lt;/strong&gt; : 2400EEAA80A0D59A780A912D6739B9B8E8274E1B5C1EFAF891B872AA83B6BDDF&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/es/Desafios/Forense/" rel="directory"&gt;Forense&lt;/a&gt;
</description>
</item>
<item xml:lang="es">
<title>Remote Support</title>
<link>https://www.root-me.org/es/Desafios/Forense/Remote-Support</link>
<guid isPermaLink="true">https://www.root-me.org/es/Desafios/Forense/Remote-Support</guid>
<dc:date>2024-11-08T11:00:40Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>es</dc:language>
<dc:creator>
makhno
</dc:creator>
<dc:subject>Difficile</dc:subject>
<description>
&lt;p&gt;Tu administrador de sistemas te pide que le ayudes a endurecer su m&#225;quina utilizando las herramientas que tiene instaladas.&lt;br class=&#034;autobr&#034; /&gt;
Has hecho una captura de red y un volcado de memoria, &#161;demu&#233;strale que a&#250;n le queda mucho&#160;!&lt;/p&gt;
&lt;p&gt;La bandera es de la forma sha256(parte1+parte2+parte3+parte4+parte5)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;sha256sum&lt;/strong&gt;&#160;: 857193e8e203c02b53da645b59dcf88790f0cc5763941ddf1dd1a3f195ec1486&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/es/Desafios/Forense/" rel="directory"&gt;Forense&lt;/a&gt;
</description>
</item>
<item xml:lang="es">
<title>MasterKee</title>
<link>https://www.root-me.org/es/Desafios/Forense/MasterKee</link>
<guid isPermaLink="true">https://www.root-me.org/es/Desafios/Forense/MasterKee</guid>
<dc:date>2024-11-08T11:00:33Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>es</dc:language>
<dc:creator>
Ayweth20
</dc:creator>
<dc:subject>Facile</dc:subject>
<description>
&lt;p&gt;Un colega ha montado un sistema muy &#250;til en su nueva m&#225;quina.&lt;br class=&#034;autobr&#034; /&gt;
Insiste en que &#233;l es el &#250;nico que puede acceder a &#233;l con lo que sabe, pero t&#250; quieres demostrarle que cualquiera podr&#237;a acceder sin que &#233;l estuviera all&#237;.&lt;br class=&#034;autobr&#034; /&gt;
Tu reto es demostrarle que eres capaz de mucho m&#225;s de lo que imagina.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;sha256sum&lt;/strong&gt;&#160;: 5c8777a28a0ef8b1f438a143bfe13772ab60770ec350d9475b69c2fb5ab01577&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/es/Desafios/Forense/" rel="directory"&gt;Forense&lt;/a&gt;
</description>
</item>
<item xml:lang="es">
<title>Air-gap exfiltration</title>
<link>https://www.root-me.org/es/Desafios/Forense/Air-gap-exfiltration</link>
<guid isPermaLink="true">https://www.root-me.org/es/Desafios/Forense/Air-gap-exfiltration</guid>
<dc:date>2023-10-20T09:49:03Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>es</dc:language>
<dc:creator>
Yorf
</dc:creator>
<dc:subject>Moyen</dc:subject>
<description>
&lt;p&gt;En su ronda, el guardia encontr&#243; un dron sentado en el alf&#233;izar de una ventana.&lt;br class=&#034;autobr&#034; /&gt;
Curiosamente, estaba orientado hacia una oficina situada en una &#034;&lt;i&gt;zona protegida&lt;/i&gt;&#034; cuya red est&#225; aislada por un &#034;cortafuegos&#034;.&lt;br class=&#034;autobr&#034; /&gt;
Su responsable de seguridad le pide que compruebe que no se ha filtrado ning&#250;n dato.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt; sha256sum&#160;: &lt;/strong&gt; 7f73bdc8a1227621d98180af9a41ab1656075abd93ecfc3f780bc7b2ec1c59b6&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/es/Desafios/Forense/" rel="directory"&gt;Forense&lt;/a&gt;
</description>
</item>
<item xml:lang="es">
<title>Capture this</title>
<link>https://www.root-me.org/es/Desafios/Forense/Capture-this</link>
<guid isPermaLink="true">https://www.root-me.org/es/Desafios/Forense/Capture-this</guid>
<dc:date>2023-10-20T09:48:59Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>es</dc:language>
<dc:creator>
Zey_Roxx
</dc:creator>
<dc:subject>Moyen</dc:subject>
<description>
&lt;p&gt;Un empleado ha perdido su contrase&#241;a Keepass. No la recordaba y no encontraba su archivo de contrase&#241;as. Tras horas de b&#250;squeda, resulta que ha enviado una pantalla con sus contrase&#241;as a uno de sus compa&#241;eros, pero sigue sin encontrarla.&lt;/p&gt;
&lt;p&gt;Te pide ayuda para encontrarlo.&lt;br class=&#034;autobr&#034; /&gt;
Depende de ti&lt;/p&gt;
&lt;p&gt;&lt;strong&gt; sha256sum&#160;: &lt;/strong&gt; 028c8561f087da873b08968d55141dcfc8f10a47e787f79c35b2da611a5e07ce&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/es/Desafios/Forense/" rel="directory"&gt;Forense&lt;/a&gt;
</description>
</item>
<item xml:lang="es">
<title>Web3 - Put on your mask - Step 2</title>
<link>https://www.root-me.org/es/Desafios/Forense/Web3-Put-on-your-mask-Step-2</link>
<guid isPermaLink="true">https://www.root-me.org/es/Desafios/Forense/Web3-Put-on-your-mask-Step-2</guid>
<dc:date>2023-10-20T09:48:56Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>es</dc:language>
<dc:creator>
Dridri
</dc:creator>
<dc:subject>Difficile</dc:subject>
<description>
&lt;p&gt;Estimado investigador,&lt;/p&gt;
&lt;p&gt;Despu&#233;s de identificar a los sospechosos y los v&#237;nculos entre las personas, ya es hora de recuperar los fondos de la cartera Ethereum donde se recibe el dinero de las v&#237;ctimas. Nos gustar&#237;a recuperar el par de claves p&#250;blica/privada para que nuestros ingenieros puedan proceder a la incautaci&#243;n del bot&#237;n.&lt;/p&gt;
&lt;p&gt;La bandera de validaci&#243;n es el resultado de&#160;: &lt;strong&gt;sha256(claveprivada:clavep&#250;blica)&lt;/strong&gt;&lt;br class=&#034;autobr&#034; /&gt;
con &lt;i&gt;publickey&lt;/i&gt; en formato &#034;checksummed&#034; (may&#250;sculas y min&#250;sculas)&lt;br class=&#034;autobr&#034; /&gt;
y &lt;i&gt;privatekey&lt;/i&gt; con el aspecto &lt;i&gt; 4fb9[...]09af&lt;/i&gt; (sin el 0x)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt; sha256sum&#160;: &lt;/strong&gt; bc5b352dff02e898592433b7fa56224ccefd4557404f678d0167a1fd8fba62ed&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/es/Desafios/Forense/" rel="directory"&gt;Forense&lt;/a&gt;
</description>
</item>
<item xml:lang="es">
<title>Web3 - Put on your mask - Step 1</title>
<link>https://www.root-me.org/es/Desafios/Forense/Web3-Put-on-your-mask-Step-1</link>
<guid isPermaLink="true">https://www.root-me.org/es/Desafios/Forense/Web3-Put-on-your-mask-Step-1</guid>
<dc:date>2023-10-20T09:48:53Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>es</dc:language>
<dc:creator>
Dridri
</dc:creator>
<dc:subject>Moyen</dc:subject>
<description>
&lt;p&gt;Estimado investigador,&lt;br class=&#034;autobr&#034; /&gt;
nuestros servicios de inteligencia est&#225;n a punto de acabar con una gran red de delincuentes que operan en la dark web. El 12 de noviembre de 2022, conseguimos instalar una puerta trasera en la m&#225;quina host del posible cabecilla y pudimos recuperar un volcado de memoria de la m&#225;quina virtual que se estaba ejecutando.&lt;/p&gt;
&lt;p&gt;Necesitamos conocer alguna informaci&#243;n sobre la cadena para analizar mejor la organizaci&#243;n de la estafa.&lt;/p&gt;
&lt;p&gt;&#191;Podr&#237;as buscar en la red&#160;:&lt;/p&gt;
&lt;ul class=&#034;spip&#034;&gt;&lt;li&gt; la direcci&#243;n Ethereum de la v&#237;ctima extorsionada de fondos ether que alimentaba la cuenta del jefe de la banda&lt;/li&gt;&lt;li&gt; la direcci&#243;n Ethereum del comprador de una tarjeta de cr&#233;dito robada&lt;/li&gt;&lt;li&gt; el nombre/usuario del comprador de la tarjeta&lt;/li&gt;&lt;li&gt; el n&#250;mero de la tarjeta&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;La bandera es el sha256 condensado(addrVictim:addrBuyer:BuyerName:CardNumber)&lt;/p&gt;
&lt;p&gt;Cuidado&#160;: las direcciones est&#225;n en formato checksummed (may&#250;sculas y min&#250;sculas)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt; sha256sum&#160;: &lt;/strong&gt; bc5b352dff02e898592433b7fa56224ccefd4557404f678d0167a1fd8fba62ed&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/es/Desafios/Forense/" rel="directory"&gt;Forense&lt;/a&gt;
</description>
</item>
</channel>
</rss>
