[OSINT] Breach

Hi guys, I’ve been able to get the content of the key.docx file. Any hint on the next step?
tnx!

Type your comment> @fr4c1d0 said:

Hi guys, I’ve been able to get the content of the key.docx file. Any hint on the next step?
tnx!

never mind

In case someone else didn’t take the previous guy’s warning seriously… try your passwords with Microsoft Word. I wasted a good few hours trying with Calligra which just denies access, even with the correct password. A sanity check with office2john saved me eventually… If anyone needs any help, PM me :slight_smile:

Stuck on Key.docx file. Can anyone give me an Nudge?

@50m30n3 Thanks for the help!! If anyone need ping me!!

Dont overthink anything, did it without twitter, all the info that you need is in the files.

Solved :slight_smile: thanks @Dethread for the help

Solved. PM me if you need help.
My suggestion:
look at doing “We Have A Leak” first, or narrow down your scope.

“We have a leak” surely helped a lot.

Not sure if this can be classified as OSINT, can be easily done without web.
It was like a “misdirection” on me.

Hack The Box

@davihack it follows OSINT procedures to some degree

Do not bruteforce, examine closely everything you are given :slight_smile:

Office2john gets me a hash which I can get a pass from the breach file but it does not work…I can’t find any other info in the files anybody got a hint?

Type your comment> @WarrenVos said:

Office2john gets me a hash which I can get a pass from the breach file but it does not work…I can’t find any other info in the files anybody got a hint?

You don’t need any tools to complete the challenge.

Type your comment> @Hellburpp said:

Type your comment> @WarrenVos said:

Office2john gets me a hash which I can get a pass from the breach file but it does not work…I can’t find any other info in the files anybody got a hint?

You don’t need any tools to complete the challenge.

I’ve searched through all the files, xml etc but can’t seem to see/find anything…I can only find 1 name but nothing else

Type your comment> @WarrenVos said:

Type your comment> @Hellburpp said:

Type your comment> @WarrenVos said:

Office2john gets me a hash which I can get a pass from the breach file but it does not work…I can’t find any other info in the files anybody got a hint?

You don’t need any tools to complete the challenge.

I’ve searched through all the files, xml etc but can’t seem to see/find anything…I can only find 1 name but nothing else

did you also try to search their company name and the name that you found on the internet?

Type your comment> @Hellburpp said:

Type your comment> @WarrenVos said:

Type your comment> @Hellburpp said:

Type your comment> @WarrenVos said:

Office2john gets me a hash which I can get a pass from the breach file but it does not work…I can’t find any other info in the files anybody got a hint?

You don’t need any tools to complete the challenge.

I’ve searched through all the files, xml etc but can’t seem to see/find anything…I can only find 1 name but nothing else

did you also try to search their company name and the name that you found on the internet?

I did…tried the 6 passwords from the file but nothing…tried all words I could find for the person on twitter and nothing…not sure what I’m missing :frowning:

Type your comment> @WarrenVos said:

Type your comment> @Hellburpp said:

Type your comment> @WarrenVos said:

Type your comment> @Hellburpp said:

Type your comment> @WarrenVos said:

Office2john gets me a hash which I can get a pass from the breach file but it does not work…I can’t find any other info in the files anybody got a hint?

You don’t need any tools to complete the challenge.

I’ve searched through all the files, xml etc but can’t seem to see/find anything…I can only find 1 name but nothing else

did you also try to search their company name and the name that you found on the internet?

I did…tried the 6 passwords from the file but nothing…tried all words I could find for the person on twitter and nothing…not sure what I’m missing :frowning:

I’ll DM

What do you do after you unlock the key.docx? I have the SSH key for root, but not sure what else to do?

Can you not open the .docx on kali? I have several passwords, and I’m pretty sure one of them is correct, but they all fail. Do I literally need to get a free trial of microsoft word to open this? I’m trying with libreoffice.

Got the password pretty quick but unsure what to do with the private key now. First attempt and pretty noobie so all help welcome.