[OSINT] Easy Phish

G’day all,

I’ve found a flag but it was missing the close ‘}’ and won’t work. Did anyone else come across this? Am I missing part of the flag?

Yes, you’re missing the second half of the flag. The first half that you have gives you the name/acronym of something. Research alternatives to that something and then try to query/enumerate those. Although subtle, the text you have so far hints at this.

I’m going to slap myself upside the head for missing that one, thanks!

ok i also got the 2th part but missing the the 1th part. research about **F alternative but did not got anything special. pm me some hints.

I’m very lost on this one, I’ve been looking at the site and can’t find anything. Can anyone give me a nudge? I feel like I’m completely on the wrong track.

Thanks

Type your comment> @Fyerguy said:

I’m very lost on this one, I’ve been looking at the site and can’t find anything. Can anyone give me a nudge? I feel like I’m completely on the wrong track.

Thanks

Think about the challenges description, and how you would go about trying to prevent that type of attack.

@n2lus said:

Think about the challenges description, and how you would go about trying to prevent that type of attack.

AH hah! Thank you so much, you got my head out of my ■■■ and now I’m on the right track.

Thanks!

Very interesting challenge. If you know what to do it doesn’t take a long time. :slight_smile:

Type your comment> @Wolfstorm said:

Very interesting challenge. If you know what to do it doesn’t take a long time. :slight_smile:

How do you know what to do? Are there articles available for example?

@TheGrayMan said:
How do you know what to do? Are there articles available for example?

No; there are online tools that can help you. PM me and I’ll tell you.

The majority of the time was figuring out what to look for with what tools. After finding the first half it was quite easy with some googling.

Anyone want to PM Me a hint to get started, I have an idea at a high level whats happened, and I’ve tried some basic searches around the domain name but I’m clutching at straws and randomly googling rather than having a focused plan.

Never mind, ran enough tools foing on my initial theory and it became obvious…

I see the first part of the flag but the rest is missing… is this part of the puzzle or is it messed up?

Update: part of the puzzle

Any tips on what tool to use/start with for this? Nothing I’ve been doing has produced anything useful.

Type your comment> @bitL8ByteShort said:

Any tips on what tool to use/start with for this? Nothing I’ve been doing has produced anything useful.

Dig or nslookup and google

1 Like

Hello everyone, found the first part of the flag. any suggestions for the second part?

EDIT: Found second part. Nice challenge. I learned so many things

Type your comment> @nemen said:

Hello everyone, found the first part of the flag. any suggestions for the second part?

EDIT: Found second part. Nice challenge. I learned so many things

i have second part but cant locate the first part, any hint pleas pm.

I got the first half but don’t really understand why I got it – does anyone have any hints for the second part of the challenge?

I got up to HTB{xxx_xxx_ any help solving 2nd part?? :smile:

Edit: Done. I overlooked the 2nd part. This looks ■■■■ easy after solving.