<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>vanir's blog</title><link>https://vanirrr.tech/</link><description>Recent content on vanir's blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 22 Jun 2026 12:09:45 +0100</lastBuildDate><atom:link href="https://vanirrr.tech/index.xml" rel="self" type="application/rss+xml"/><item><title>NITCTF Breach 2</title><link>https://vanirrr.tech/writeups/nitctf_breach2/</link><pubDate>Mon, 22 Jun 2026 12:09:45 +0100</pubDate><guid>https://vanirrr.tech/writeups/nitctf_breach2/</guid><description>&lt;h1 id="nit-breach-2--memory-forensics-writeup"&gt;NIT Breach 2 — Memory Forensics Writeup&lt;/h1&gt;
&lt;p&gt;&lt;strong&gt;category:&lt;/strong&gt; forensics / memory Analysis
&lt;strong&gt;Tooling:&lt;/strong&gt; Volatility 3
&lt;strong&gt;Image:&lt;/strong&gt; &lt;code&gt;nit_breach_2.raw&lt;/code&gt; (Ubuntu Linux memory dump)
&lt;strong&gt;Flag:&lt;/strong&gt; &lt;code&gt;nmctf{num1d14n_m3m0ry_s3cr3t_7c2b8a}&lt;/code&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="first-instincts"&gt;first instincts&lt;/h2&gt;
&lt;p&gt;I ran strings on the image, grepped for &amp;ldquo;nmctf{&amp;rdquo; but found nothing, afterwards i ran strings and grepped for &amp;ldquo;classified_secrets&amp;rdquo;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;strings -t d nit_breach_2.raw | grep -iE &lt;span style="color:#e6db74"&gt;&amp;#34;classified_secrets&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;got:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#ae81ff"&gt;321038056&lt;/span&gt; ./nit_numidian_db/classified_secrets
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;next thing i did was regex scan for &amp;ldquo;classified_secrets&amp;rdquo;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;python3 vol.py -f nit_breach_2.raw linux.vmaregexscan.VmaRegExScan --pattern &lt;span style="color:#e6db74"&gt;&amp;#34;classified_secrets&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;3105 mariadbd 0x791e544ec4ac classified_secrets 63 6c 61 73 73 69 66 69 65 64 5f 73 65 63 72 65 74 73
&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="now-we-know-wassup-we-start-our-digging"&gt;aha! the process is mariadbd, with PID 3105&lt;br&gt;
now we know wassup, we start our digging.&lt;/h2&gt;
&lt;h2 id="step-1--find-the-mariadb-process-pslist"&gt;Step 1 — Find the MariaDB process (&lt;code&gt;PsList&lt;/code&gt;)&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;python3 vol.py -f nit_breach_2.raw linux.pslist.PsList | grep -iE &lt;span style="color:#e6db74"&gt;&amp;#34;maria|mysql&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;0x8b10029f5200 3105 3105 1 mariadbd ... 2026-06-18 17:50:00 UTC Disabled
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;made sure mariadb is running as: &lt;strong&gt;&lt;code&gt;mariadbd&lt;/code&gt;, PID 3105&lt;/strong&gt;.&lt;/p&gt;</description></item></channel></rss>