Skip to content

The Secret Brunsviger

Forensics

I have intercepted encrypted HTTPS traffic from the secret brunsviger baking forum, but I need help decrypting it.

points: 50

solves: 242

author: Ha1fdan


traffic.pcap and keys.log given:

Open Wireshark to observe the pcap file:

image

In Preferences, set TLS keys using the log file given. Now Application Data is visible:

image

The JSON packets seem interesting...

image

Decode (base64) the secret recipe to get the flag