T_1000 ECTF Recon-120 writeup

Screenshot from 2014-10-23 16:23:30

This is the toughest recon that I have ever seen (or in other words the worst one :P)

First result that you find when you search for T_1000 is the terminator so I tried all the names related to the movie such as the director, the producer, the actor who acted as the T_1000 but no result ๐Ÿ˜ฆ I have also tried skynet which is considered to make the terminator in the film ๐Ÿ˜› my team mate was kidding saying to enter the flag as Rajinikanth ๐Ÿ˜€

After asking admins about the challenge, I have concluded that T_1000 was not related to movies ๐Ÿ™‚

My team mate solved the forensics-500 which relates to the channel #nitk-maliciousbots which contain the bot named T_1000 , so I thought this was end of the recon so I tried to get the flag by asking the bot in private message, but this was only the half of the challenge ๐Ÿ™‚

Again from the clue whois T_1000, the output of the whois command in irc is as follows

@31337_h4X0R (cinch@2a01:7e00::f03c:91ff:fe56:df09)

BOT_T_1000 is connected via holmes.freenode.net (London, UK)

Operator in:


so we got a new thing to google for ๐Ÿ™‚ ie.. 31337_h4X0R, it seems that 31337_h4X0R has a twitter account here is the account https://twitter.com/31337_h4X0R

This account has very few tweets and it contain this photo


And finally if you grep for the strings in the photo we get the flag as follows

Screenshot from 2014-10-23 18:14:40



Feel free to comment

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.