Handshake

d

Architect

driquet

Difficulty

4/5

ETA

20 min

Barry left a packet capture in the case folder. No note, which from Barry is itself a note: it means the file speaks for itself.

$ capinfos 05-capture.pcap
File type:           Wireshark/tcpdump - pcap
Number of packets:   87
Capture duration:    51.583 seconds

The suspect authenticated to his own vault service during the window the Bureau was watching. The service never sends a password in the clear, but it does send a hash of it during the handshake.

Reassemble the relevant stream and extract the authentication hash.

Submit the hash exactly as it appears.

◆ Files

◆ Input solution

◇ Stage cleared

Next Stage →