In Level08 we are given a network capture file: capture.pcap. If we open it with Wireshark we will only find one TCP Stream. We will use Follow TCP Stream to visualize it:

{% img /images/tcpstream.png 500 %}

We can see that the user was trying to login into the wwwbugs server and the login failed. We can assume that it was the flag08 user trying to log in and sending his flag08 password by mistake… Yep, I know it is assuming too much, but anyway, that all we got.

In the password we can see some non printable ASCII characters, if we switch to the Hex view, we can see they are 7B characters that correspond with the delete key:

{% img /images/tcpstreamhex.png 500 %}

So we can fix the password to: backd00Rmate

Let’s try it:

[email protected] ~/Desktop> ssh [email protected]

