> For the complete documentation index, see [llms.txt](https://l33t-en0ugh.gitbook.io/infosec/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://l33t-en0ugh.gitbook.io/infosec/capture-the-flag-ctf/forensics-htb.md).

# Forensics - HTB

This is all retired forensic challenges from hackthebox

## Took the Byte

<details>

<summary>Challenge Description</summary>

Someone took my bytes! Can you recover my password for me?

</details>

We will get a file called `password` when we unzip the given file.

```
$ file password 
password: data
$ cat password 
(cы$j

U36U7(c7[~ы$j
```

I uploaded to [CyberChef](https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force\(1,100,0,'Standard',false,true,false,''\)) and analyse with `XOR Bruteforce` .

![](https://3759110756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVvHHLY2mrxd5y4e2vVYL%2Fuploads%2FoEfecTD7PoHqoi8e6JUy%2Fimage.png?alt=media\&token=7df653a5-c893-4fee-8adb-6450e0628ed6)

Now we can see keys is `ff` and this file must be `zip` file with `password.txt` inside of it.

![](https://3759110756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVvHHLY2mrxd5y4e2vVYL%2Fuploads%2FAJJSxzwq0nz6csuVmEnb%2Fimage.png?alt=media\&token=1d957c87-184f-4024-96e1-92385a507032)

Save the file as zip and unzip it. We will get the flag in `password.txt` file.

```
$ cat password.txt 
HTB{27AjFDkqi1wJ}
```

> HTB{27AjFDkqi1wJ}

## S3cr3t\_R3c1p3

<details>

<summary>Challenge Description</summary>

This damn Meth-Cook encrypted his Recipe. But we found his RSA-Key. For some reason, it is not working. Can you help us?

</details>

We will get these two file when we unzip the downloaded file.

`how_to_make_meth.txt` and `rsa_private.key`

```
$ ls
 how_to_make_meth.txt   rsa_private.key
```

{% hint style="warning" %}
Comming Soon....
{% endhint %}
