my ctf writeups

Apoorva Saurav | about

Alpine 2 - 50

steg - BYUCTF

Challenge description:

What was the IP address of the attacker? (Note: Matt Johnson never logged in remotely.)

Flag format - byuctf{ip_address}

Mirror download:


We again have the Alpine image and are told to find the IP address of the attacker. Our best bet is likely the log files in /var/log/.

localhost:~# ls /var/log/
acpid.log  chrony   dmesg   messages   wtmp

Reading them all with less, the messages file was the jackpot. Screenshot of messages file

We see the IP address of the connection.

Flag byuctf{}