Forensic

Sunday 9 August 2020, 15:54  #1
Forensics - DNS Exfiltration
trtd
  • 1 posts

Hi.

So I know how the data is being transmitted in this challenge and I know what is being transmitted too. However seeing as there’s a lot of different ’DNS Queries’ how am I supposed to know which ones are right. I can get the basic obvious ones, like the beginning part of it (trying not to spoil as much as I can here!) but the rest is unclear. I’ve tried tools to try and fix stuff but they didn’t work.

Thanks in advance.

Friday 14 August 2020, 09:24  #2
Forensics - DNS Exfiltration
geronimo-ooo
  • 32 posts

Maybe you need to clear some data...if you know what sort of file it is, you should search if these files have a common signature at the beginin

Monday 15 March 2021, 09:37  #3
Forensics - DNS Exfiltration
joel7
  • 2 posts

Hello am kinda stuck on this one for days((. Perhaps you can give me additional hint. Got a script in the wild that analyses DNScat traffic and writes out a png file. but i cant find anything in the PNG file


flag-2.png
flag-2.png
 (PNG, 15.6 kb)