<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CyberPatriot on Matin Sadeghian</title><link>https://www.andrew.cmu.edu/user/msadeghi/tags/cyberpatriot/</link><description>Recent content in CyberPatriot on Matin Sadeghian</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 31 Jan 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://www.andrew.cmu.edu/user/msadeghi/tags/cyberpatriot/index.xml" rel="self" type="application/rss+xml"/><item><title>Baldi's Basics Answer Key</title><link>https://www.andrew.cmu.edu/user/msadeghi/posts/baldis-basics-answer-key/</link><pubDate>Wed, 31 Jan 2024 00:00:00 +0000</pubDate><guid>https://www.andrew.cmu.edu/user/msadeghi/posts/baldis-basics-answer-key/</guid><description>&lt;h2 id="forensics"&gt;Forensics&lt;/h2&gt;&#10;&lt;h3 id="forensics-1"&gt;Forensics 1&lt;/h3&gt;&#10;&lt;p&gt;For forensics 1, you had to decrypt the packets in the given pcap file using the ssl keys on the desktop. Through that, you would notice a &lt;code&gt;mdns poisoning&lt;/code&gt; (2nd answer) attack that began with the url &lt;code&gt;http://youtube/&lt;/code&gt; (1st answer). Searching through the packets for YouTube video links, you would come across &lt;code&gt;https://www.youtube.com/watch?v=IFERaX0EwDU&lt;/code&gt; and &lt;code&gt;https://www.youtube.com/watch?v=f6hmHgenVQg&lt;/code&gt; (3rd answer).&lt;/p&gt;&#10;&lt;h3 id="forensics-2"&gt;Forensics 2&lt;/h3&gt;&#10;&lt;p&gt;Searching the system for common auto-run areas, you would find a visual basic script at &lt;code&gt;C:\Windows\SYSVOL\domain\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Scripts\Startup\startup.vbs&lt;/code&gt; (1st answer), which added the &lt;code&gt;Administrator&lt;/code&gt; user with the password &lt;code&gt;Sup3rS3cu4eP@ssw0rd!&lt;/code&gt; (2nd answer).&lt;/p&gt;</description></item><item><title>My Little Pony Walkthrough</title><link>https://www.andrew.cmu.edu/user/msadeghi/posts/my-little-pony-walkthrough/</link><pubDate>Wed, 15 Nov 2023 00:00:00 +0000</pubDate><guid>https://www.andrew.cmu.edu/user/msadeghi/posts/my-little-pony-walkthrough/</guid><description>&lt;h2 id="forensics"&gt;Forensics&lt;/h2&gt;&#10;&lt;h3 id="forensics-1"&gt;Forensics 1&lt;/h3&gt;&#10;&lt;p&gt;Question:&lt;/p&gt;&#10;&lt;p&gt;They are at it again. The users keep on sending each other these stupid secret notes.&#10;This goes against our policies so please figure out what their secret notes say and&#10;report them here.&lt;/p&gt;&#10;&lt;p&gt;For this report please figure out the full plain-text and key used in the “xor” file.&#10;We also know that part of the plaintext is &amp;ldquo;For honesty no pony can deny&amp;rdquo;.&lt;/p&gt;&#10;&lt;p&gt;EXAMPLE KEY: Il0v3P0n1es&lt;/p&gt;</description></item><item><title>CyberDiscord Open 2023 Windows Server Writeup</title><link>https://www.andrew.cmu.edu/user/msadeghi/posts/cyberdiscord-open-2023-windows-server-writeup/</link><pubDate>Sat, 10 Jun 2023 00:00:00 +0000</pubDate><guid>https://www.andrew.cmu.edu/user/msadeghi/posts/cyberdiscord-open-2023-windows-server-writeup/</guid><description>&lt;h1 id="forensics"&gt;Forensics&lt;/h1&gt;&#10;&lt;h2 id="forensics-1"&gt;Forensics 1&lt;/h2&gt;&#10;&lt;p&gt;Question:&lt;/p&gt;&#10;&lt;p&gt;Hash functions are one-way functions. Secure hash functions have several properties such as collision resistance, preimage resistance, and second preimage resistance. Hashes are the output of hash functions and are typically displayed to the user in hex.&lt;/p&gt;&#10;&lt;p&gt;There is a file somewhere on this machine named &amp;ldquo;cain.zip&amp;rdquo;.&lt;/p&gt;&#10;&lt;p&gt;What is the MD5 hash of this file?&lt;/p&gt;&#10;&lt;p&gt;This question is pretty straightforward. The first step is to find this &amp;ldquo;cain.zip&amp;rdquo; file. For this, I simply installed the &lt;a href="https://www.voidtools.com/"&gt;Everything tool from voidtools&lt;/a&gt; and searched cain.zip to reveal it&amp;rsquo;s in C:\Windows. After going there with Powershell I ran&lt;/p&gt;</description></item></channel></rss>