WolvCTF - Eternally Pwned: Exfiltration
The attached file is a .pcap, so we can analyze it using wireshark.
To
get a nice summary of the traffic we look at
Statistics > Protocol Hierarchy

Hmm… file sharing. Could find some secrets there!
We’ll filter for only smb traffic.
That’s a much more managable number of packets.
Clicking through each packet we see an interesting base64 looking string.
Decoding this we
get the following: wctf{l3tS_
Definitely seems promising! Now to find the rest of it…
We can click on that packet and follow the TCP stream to find more.
