Objective:
There used to be a bunch of animals[1] here, what did Dr. Xernon do to them?
Hints:
(1) Some files have been deleted from teh disk image, but are they really gone?
Solution:
I used foremost to recover the files from the DD image.
let's mount the DD to see what is inside visible to my OS
@kali:/$ sudo mkdir /mnt/disk_image
@kali:/$ sudo mount -o loop -t auto /home/circusmonkey404/Downloads/animals.dd /mnt/disk_image
let's see whats in there
kali:/mnt/disk_image$ ls
dachshund.jpg frog.jpg music.jpg rabbit.jpg
4 files named after animals
let's through Foremost at it and see what it finds
kali:/mnt/disk_image$ ls
dachshund.jpg frog.jpg music.jpg rabbit.jpg
Let's check and see what foremost found
@kali:~/Downloads$ ls
animals.dd husky.png incidents.json output_Tue_Sep_24_10_45_31_2019 passwd
@kali:~/Downloads$ cd output_Tue_Sep_24_10_45_31_2019/
@kali:~/Downloads/output_Tue_Sep_24_10_45_31_2019$
ls
let's check audit.txt
here is the output from cat
@kali:~/Downloads/output_Tue_Sep_24_10_45_31_2019$ cat audit.txt
Foremost version 1.5.7 by Jesse Kornblum, Kris Kendall, and Nick Mikus
Audit File
Foremost started at Tue Sep 24 10:45:31 2019
Invocation: foremost -T animals.dd
Output directory: /home/*********/Downloads/output_Tue_Sep_24_10_45_31_2019
Configuration file: /etc/foremost.conf
------------------------------------------------------------------
File: animals.dd
Start: Tue Sep 24 10:45:31 2019
Length: 10 MB (10485760 bytes)
Num Name (bs=512) Size File Offset Comment
0: 00000077.jpg 617 KB 39424
1: 00001313.jpg 481 KB 672256
2: 00002277.jpg 380 KB 1165824
3: 00003041.jpg 248 KB 1556992
4: 00003541.jpg 314 KB 1812992
5: 00004173.jpg 458 KB 2136576
6: 00005093.jpg 383 KB 2607616
7: 00005861.jpg 39 KB 3000832
Finish: Tue Sep 24 10:45:31 2019
8 FILES EXTRACTED
jpg:= 8
------------------------------------------------------------------
Foremost finished at Tue Sep 24 10:45:31 2019
8 files extracted, that's more then the 4 we saw originally
lets check out the jpgs found in the jpg folder
opening it up in the GUI
Here is the picture with the flag 00005861.jpg
picoCTF{th3_5n4p_happ3n3d}
Comments
Post a Comment