Author Archives: littlefater

FLARE On Challenge (2015) #5

This challenge is an easy one. It contains two files, one is a Windows Portable Executable file and another one is a PCAP file. Let’s look at the PCAP file at first: In the PCAP file we can see a … Continue reading

Posted in CTF | Tagged , , , | Comments Off on FLARE On Challenge (2015) #5

FLARE On Challenge (2015) #4

File youPecks is a 32 bit Windows Portable Executable file packed with UPX (according to the section name). And it can be unpacked with the UPX utility: When executes the unpacked file, it only prints out a strange expression “2 … Continue reading

Posted in CTF | Tagged , , , | Comments Off on FLARE On Challenge (2015) #4

FLARE On Challenge (2015) #3

The first thing you may noticed for this challenge is that the file size is much larger than the previous challenges, it is about 12 MB! However, from the section table we can find that the size of the PE image … Continue reading

Posted in CTF | Tagged , , , | Comments Off on FLARE On Challenge (2015) #3

FLARE On Challenge (2015) #2

The file of challenge 2 named very_success, it is a 32 bit Windows Portable Executable file which probably written in Assembly Language. The workflow of this program is very similar to the i_am_happy_you_are_to_playing_the_flareon_challenge.exe in challenge 1. It will read a … Continue reading

Posted in CTF | Tagged , , , | Comments Off on FLARE On Challenge (2015) #2

FLARE On Challenge (2015) #1

When you analyze a file, the first thing is probably to understand the type of the file. If you are familiar with Windows, I believe you can recognize the file type of the first challenge just by looking at its icon: Yes, … Continue reading

Posted in CTF | Tagged , , , | Comments Off on FLARE On Challenge (2015) #1