Access Granted!
Last updated
Last updated
First things first. MogamBro is so dumb that he might be using the same set of passwords everywhere, so lets try cracking his PC's password for some luck.
FILES: artifacts.ad1, memdump.mem, trace.pcap
I started with searching the memory dump first. Since we are looking for a password, we can use the windows.hashdump plugin
in Vol3 to extract the NTLM hashes and crack MogamBro's password hash.
Taking a look at MogamBro
, we can put the hash inside a password hash cracker to retrieve the flag.
Flag: BITSCTF{adlofhitlerrulesallthepeople}