SU-CTF Forensics 100 Whom are they speaking about

They gave a traffic packet and we were asked to find out the name of the person from the conversation. When I opened the packet in the wireshark sniffer, I found RTP and SIP protocols, which are designed to control and deliver audio,video files over IP networks. Without any confusions, I suspected that, there should be VoIP call entries embedded inside the traffic packet. When I checked for the presence of those files, I found 2 VoIP calls which was transmitted in 9 fragments.

suctffor100whom

When I started listening to the conversation, I heard them talking about a Iranian Poet from 14th Century. They used the poet’s name at the very beginning of the conversation, but it was not quite clear. I heard the ending word of the poet’s name as “z”. So I made quick google search for the iranian poets from the 14th century. The only poet’s name ends with ‘z’ in the list is “Hafez”.

So we got the name of the person whom they were discussing over the VoIP call and it was the flag for the challenge.

Flag : Hafez

Leave a comment