Forensic
Last updated
Last updated
Challenge | Link |
---|---|
Is this a FileSystem? Identify the file and make the necessary adjustments to solve the challenge. Note: The challenge file size is 16GB after extraction.
During the competition, my friend found an interesting file without header using r-studio
Because it is a free edition of r-studio we cant dump the file, so looking at some hex value i tried to search the file. First, i use autopsy to load Chall.img file and export the unallocated space partition. Because if we search on 16gb files it will take a long time. Because i know some hex value and know what should the end of PNG file we can just parse the png and get the flag.
Flag: BHFlagY{8bd8dc3ea7636c5fb8aeb}
NotFS (180 pts)