this-file-hides-something
Last updated
Last updated
There is an emergency regarding this file. We need to extract the password ASAP. It's a crash dump, but our tools are not working. Please help us, time is not on our side.
PS: Flag format is not standard.
First let's download the zip file and extract the content inside the archive. Inside, there's a file that holds temporary memory information, meaning it's not permanently stored. Volatility helps us investigate volatile memory, which is memory that disappears when the computer is turned off. For this challenge I used volatility 3 on a windows machine (I had some issues using on a linux environment).
Lsadump plugin is used to dump LSA secrets from the registry. In volatility3 use lsadump to get the flag.
Flag