{"id":174,"date":"2019-01-17T04:02:14","date_gmt":"2019-01-17T04:02:14","guid":{"rendered":"https:\/\/mrjsec.co.uk\/blog\/?p=174"},"modified":"2019-01-17T04:02:20","modified_gmt":"2019-01-17T04:02:20","slug":"tangle-coalbox-lethal-forensicelfication-cranberry-pi-terminal","status":"publish","type":"post","link":"https:\/\/mrjsec.co.uk\/blog\/tangle-coalbox-lethal-forensicelfication-cranberry-pi-terminal\/","title":{"rendered":"<center>Tangle Coalbox &#8211; Lethal ForensicELFication Cranberry Pi terminal<\/center>"},"content":{"rendered":"\n<p style=\"text-align:center\">As we speak to Tangle Coalbox, they ask if we can help them with an investigation.<br> &#8220;Elf Resources assigned me to look into a case, but it seems to require digital forensic skills.<br> Do you know anything about Linux terminal editors and digital traces they leave behind?<br> Editors can leave traces of data behind, but where and how escapes me!&#8221;<\/p>\n\n\n\n<p style=\"text-align:center\">Were given a hint to check out this <a href=\"https:\/\/tm4n6.com\/2017\/11\/15\/forensic-relevance-of-vim-artifacts\/\">website<\/a> and to be honest, that&#8217;s the only hint we need.<\/p>\n\n\n\n<p style=\"text-align:center\">When we start the terminal, we see this.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"638\" height=\"499\" data-attachment-id=\"175\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/tangle-coalbox-lethal-forensicelfication-cranberry-pi-terminal\/capture1\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture1.png?fit=638%2C499&amp;ssl=1\" data-orig-size=\"638,499\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture1\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture1.png?fit=638%2C499&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture1.png?resize=638%2C499&#038;ssl=1\" alt=\"\" class=\"wp-image-175\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture1.png?w=638&amp;ssl=1 638w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture1.png?resize=300%2C235&amp;ssl=1 300w\" sizes=\"auto, (max-width: 638px) 100vw, 638px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">So the task here is too &#8220;Find the first name of the elf of whom a love poem was written.  Complete this challenge by submitting that name to run to answer.&#8221;<\/p>\n\n\n\n<p style=\"text-align:center\">First thing I did, as I checked the .bash_history, and we can see there was a folder created called .secrets\/her\/<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"519\" height=\"438\" data-attachment-id=\"176\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/tangle-coalbox-lethal-forensicelfication-cranberry-pi-terminal\/capture2\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture2.png?fit=519%2C438&amp;ssl=1\" data-orig-size=\"519,438\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture2\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture2.png?fit=519%2C438&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture2.png?resize=519%2C438&#038;ssl=1\" alt=\"\" class=\"wp-image-176\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture2.png?w=519&amp;ssl=1 519w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture2.png?resize=300%2C253&amp;ssl=1 300w\" sizes=\"auto, (max-width: 519px) 100vw, 519px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Also, if we cd to .secrets\/her\/ we find a file called <a href=\"https:\/\/pastebin.com\/raw\/07hBuD0S\">&#8220;poem.txt&#8221;<\/a> which is the love poem we need to find out who created it.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"610\" height=\"678\" data-attachment-id=\"177\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/tangle-coalbox-lethal-forensicelfication-cranberry-pi-terminal\/capture3\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3.png?fit=610%2C678&amp;ssl=1\" data-orig-size=\"610,678\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture3\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3.png?fit=610%2C678&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3.png?resize=610%2C678&#038;ssl=1\" alt=\"\" class=\"wp-image-177\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3.png?w=610&amp;ssl=1 610w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3.png?resize=270%2C300&amp;ssl=1 270w\" sizes=\"auto, (max-width: 610px) 100vw, 610px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">&#8220;How sweet\u2026\u2026\u2026\u2026&#8221; Let&#8217;s get back to the challenge here. Using the hint URL given if we use the command &#8220;cat .viminfo&#8221;, we get tons of information, but one thing that stands out is this.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"396\" height=\"710\" data-attachment-id=\"178\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/tangle-coalbox-lethal-forensicelfication-cranberry-pi-terminal\/capture4\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4.png?fit=396%2C710&amp;ssl=1\" data-orig-size=\"396,710\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture4\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4.png?fit=396%2C710&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4.png?resize=396%2C710&#038;ssl=1\" alt=\"\" class=\"wp-image-178\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4.png?w=396&amp;ssl=1 396w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4.png?resize=167%2C300&amp;ssl=1 167w\" sizes=\"auto, (max-width: 396px) 100vw, 396px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">&#8220;# Command Line History (newest to oldest):<br> :wq<br> |2,0,1536607231,,&#8221;wq&#8221;<br> :%s\/Elinore\/NEVERMORE\/g<br> |2,0,1536607217,,&#8221;%s\/Elinore\/NEVERMORE\/g&#8221;<br> :r .secrets\/her\/poem.txt<br> |2,0,1536607201,,&#8221;r .secrets\/her\/poem.txt&#8221;<br> :q&#8221;<\/p>\n\n\n\n<p style=\"text-align:center\">Which shows Elinore created the poem.txt. So, the answer is &#8220;Elinore&#8221; and if we use Elinore with the run to answer\u2026 We get the congratulations!<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"590\" height=\"547\" data-attachment-id=\"179\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/tangle-coalbox-lethal-forensicelfication-cranberry-pi-terminal\/capture5\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5.png?fit=590%2C547&amp;ssl=1\" data-orig-size=\"590,547\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture5\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5.png?fit=590%2C547&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5.png?resize=590%2C547&#038;ssl=1\" alt=\"\" class=\"wp-image-179\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5.png?w=590&amp;ssl=1 590w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5.png?resize=300%2C278&amp;ssl=1 300w\" sizes=\"auto, (max-width: 590px) 100vw, 590px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Thank you for solving this mystery, Slick.<br>\nReading the .viminfo sure did the trick.<br>\nLeave it to me; I will handle the rest.<br>\nThank you for giving this challenge your best.<br>\n-Tangle Coalbox<br>\n-ER Investigator<br>\nCongratulations!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As we speak to Tangle Coalbox, they ask if we can help them with an investigation. &#8220;Elf Resources assigned me to look into a case, but it seems to require digital forensic skills. Do you&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[10],"tags":[13,14,12],"class_list":["post-174","post","type-post","status-publish","format-standard","hentry","category-kringlecon-2018","tag-13","tag-ctf","tag-kringlecon"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paD3U6-2O","_links":{"self":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/174","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=174"}],"version-history":[{"count":1,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/174\/revisions"}],"predecessor-version":[{"id":180,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/174\/revisions\/180"}],"wp:attachment":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=174"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=174"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=174"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}