Posts

CyberKavach QuestCon Series: The Hawkins Paradox

Image
  The Hawkins Paradox Welcome to the official CyberKavach QuestCon write-up series by PCCOE OWASP Student Chapter! We’ll explore "The Hawkins Paradox," a multi-layered OSINT (Open Source Intelligence) challenge inspired by the Stranger Things universe. Author: Jay Surana Challenge Details Category: OSINT Difficulty: Medium Points: 300 Flag Format: questCON{flag} Layer 1: Document & Archive Analysis Files provided: Hawkings Lab Report.pdf Logs.7z The journey begins with the Hawkings Lab Report PDF. Within the document, the author and their ID, "ECHOPRIME83," are prominently displayed. This ID serves as the password to unlock Logs.7z. Extracting the archive reveals a base32 encoded file, investigation.log.b32. To decode, use a Linux command: base32 -d investigation.log.b32 > decodedoutput.txt This produces a log accusing user rxal99 of malicious activity in Hawkings Lab. Layer 2: OSINT Trail & Steganography With the username rxal99 in hand, a further se...

CyberKavach QuestCon Series: The Hawkins Incident

Image
  The Hawkins Incident (OSINT) Welcome back to the PCCOE OWASP Student Chapter's official write-up series for CyberKavach QuestCon ! This time, we're diving into the multi-stage OSINT challenge "The Hawkins Incident," created by Ayush Jayatkar . This challenge was a three-round journey tracking a strange energy surge from Hawkins National Laboratory. Challenge Details Description: A strange energy surge has been detected once again at Hawkins National Laboratory. Encrypted data is spreading across digital realms — the Normal World and the Upside Down. As an investigator, your task is to track these transmissions, decode the secrets, and close the gate before the Upside Down consumes Hawkins. Flag Format: questCON{STRANGERPYERS_3DEFEAT} Walkthrough This investigation was split into three distinct rounds to find the username, password, and the final flag. Round 1 – The Labgate Goal: Find the password for Round 3. File: Round1.html Opening Round1.html showed a page...

CyberKavach QuestCon Series: The Cipher Breach

Image
  The Cipher Breach Author: Radhika Suryavanshi Welcome to the CyberKavach QuestCon write-up series by PCCOE OWASP Student Chapter! In this post, we explore a challenging three-part cryptographic puzzle designed to test your understanding of real-world vulnerabilities and cryptanalysis. Challenge Details Category: Cryptography Difficulty: Medium Description: Recover pieces of the final flag by exploiting three common cryptographic vulnerabilities, one each in ECDSA usage, PRNG state recovery, and AES encryption misuse. Flag Format: questCON{part1-part2-part3} Stage 1: ECDSA Nonce Leakage Vulnerability ECDSA relies on a secret nonce kkk per signature. This challenge provides ECDSA signatures where the top 12 bits of the nonce are leaked—a catastrophic information leak. Attack Overview Goal: Brute force the unknown bits of the nonce to recover the full nonce. Using two signatures, guess nonce bits, calculate a potential private key candidate, and verify using the second signatu...