Root-Me {Network} ETHERNET — Patched transmission CTF WriteUp

Genesis
2 min readDec 31, 2021
https://www.root-me.org/?lang=en

SOLUTION

Analyze the frames to understand what’s going on

These are the Hex-dump of the packets.

Firstly we have to convert these hex-dump in such format that we can open these packets in wireshark.

To convert the text file in pcap format we will use text2pcap tool.

Our text file should be in this format mentioned bellow to be able to get recognized by text2pcap tool

After converting the packets we will open it in wireshark and we will me all packets.

To merge go to File -> Merge in Wireshark

After Analyzing all packets we got to know that these all are IMCPv6 request and reply packets

First 3 packets are request and last one is reply

We also get to know that first and third packet have bad checksum.This strongly suggests that the EGRESS frame is a reply to the second INGRESS frame.

--

--

Genesis

CTF Player | Pentester | CTF Writeups | Cyber Security Related Blogs