Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
හොඳ, දැන්වීම්-රහිත (ad-free) ආයුර්වේද ඇප් එකක් සොයා ගැනීමට නොහැකි වූ නිසා, මමම එකක් නිර්මාණය කළා
kitchen_discussions
Updated:
Today at 2:34 AM
Ad icon
Iptv
musicking
Updated:
Sunday at 9:52 AM
Ad icon
ZTE MF283U 4G Unlocked Router (Used)
ayanthamaxi
Updated:
Jul 19, 2026
ලංකාවේ හොඳම උපකාරක පන්ති සහ ගුරුවරුන් එකම තැනකින් - TopTuition.lk
dulithapathum
Updated:
Jul 18, 2026
Colombo
RidhMathraa ’26 🎶✨
Tmadhusanka
Updated:
Jul 15, 2026
Electronics
Vehicles
Property
Search
Reply to thread
Forums
General
ElaKiri Talk!
[THM] Advent of Cyber 2022 ALL FLAGS AND ANSWERS
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="Sweet_Johnson" data-source="post: 28410425" data-attributes="member: 582370"><p>DAY 1 : </p><p>The Bandit Yeti</p><p>THM{IT'S A Y3T1 CHR1$TMA$}</p><p></p><p>Use the ls command to list the files present in the current directory. How many log files are present?</p><p></p><p>2</p><p></p><p>Elf McSkidy managed to capture the logs generated by the web server. What is the name of this log file?</p><p></p><p>webserver.log</p><p></p><p>On what day was Santa's naughty and nice list stolen?</p><p></p><p>Friday</p><p></p><p>What is the IP address of the attacker?</p><p></p><p>10.10.249.191</p><p></p><p>What is the name of the important list that the attacker stole from Santa?</p><p></p><p>santaslist.txt</p><p></p><p>Look through the log files for the flag. The format of the flag is: THM{}</p><p></p><p>THM{STOLENSANTASLIST}</p><p></p><p></p><p>=====DAY 3 =====</p><p></p><p>What is the name of the Registrar for the domain santagift.shop?</p><p></p><p>NAMECHEAP INC</p><p></p><p>Find the website's source code (repository) on github.com and open the file containing sensitive credentials. Can you find the flag?</p><p></p><p>{THM_OSINT_WORKS}</p><p></p><p>What is the name of the file containing passwords?</p><p></p><p>config.php</p><p></p><p>What is the name of the QA server associated with the website?</p><p></p><p>qa.santagift.shop</p><p></p><p>What is the DB_PASSWORD that is being reused between the QA and PROD environments?</p><p></p><p>S@nta2022</p><p></p><p></p><p>===== DAY 4 =====</p><p></p><p>What is the name of the HTTP server running on the remote host?</p><p></p><p>apache</p><p></p><p>What is the name of the service running on port 22 on the QA server?</p><p></p><p>ssh</p><p></p><p>What flag can you find after successfully accessing the Samba service?</p><p></p><p>{THM_SANTA_SMB_SERVER}</p><p></p><p>What is the password for the username santahr?</p><p></p><p>santa25</p><p></p><p></p><p>===== DAY 5 =====</p><p></p><p></p><p>Use Hydra to find the VNC password of the target with IP address 10.10.208.109. What is the password?</p><p></p><p>1q2w3e4r</p><p></p><p>Using a VNC client on the AttackBox, connect to the target of IP address 10.10.208.109. What is the flag written on the target’s screen?</p><p></p><p>THM{I_SEE_YOUR_SCREEN}</p><p></p><p></p><p>===== DAY 6 =====</p><p></p><p>What is the email address of the sender?</p><p></p><p><a href="mailto:chief.elf@santaclaus.thm">chief.elf@santaclaus.thm</a></p><p></p><p>What is the return address?</p><p></p><p><a href="mailto:murphy.evident@bandityeti.thm">murphy.evident@bandityeti.thm</a></p><p></p><p>On whose behalf was the email sent?</p><p></p><p>chief elf</p><p></p><p>What is the X-spam score?</p><p></p><p>3</p><p></p><p>What is hidden in the value of the Message-ID field?</p><p></p><p>AoC2022_Email_Analysis</p><p></p><p>Visit the email reputation check website provided in the task. What is the reputation result of the sender's email address?</p><p></p><p>risky</p><p></p><p>Check the attachments. What is the filename of the attachment?#</p><p></p><p>Division_of_labour-Load_share_plan.doc</p><p></p><p>What is the hash value of the attachment?</p><p></p><p>0827bb9a2e7c0628b82256759f0f888ca1abd6a2d903acdb8e44aca6a1a03467</p><p></p><p>Visit the Virus Total website and use the hash value to search. Navigate to the behaviour section. What is the second tactic marked in the Mitre ATT&CK section?</p><p></p><p>Defense Evasion</p><p></p><p>Visit the InQuest website and use the hash value to search. What is the subcategory of the file?</p><p></p><p>macro_hunter</p><p></p><p></p><p>===== DAY 7 =====</p><p></p><p>What is the version of CyberChef found in the attached VM?</p><p></p><p>9.49.0</p><p></p><p>How many recipes were used to extract URLs from the malicious doc?</p><p></p><p>10</p><p></p><p>We found a URL that was downloading a suspicious file; what is the name of that malware?</p><p></p><p>mysterygift.exe</p><p></p><p>What is the last defanged URL of the bandityeti domain found in the last step?</p><p></p><p>hxxps[://]cdn[.]bandityeti[.]THM/files/index</p><p></p><p>What is the ticket found in one of the domains? (Format: Domain/<GOLDEN_FLAG>)</p><p></p><p>THM_MYSTERY_FLAG</p><p></p><p></p><p>===== DAY 8 =====</p><p></p><p>What flag is found after attacking the provided EtherStore Contract?</p><p></p><p>flag{411_ur_37h_15_m1n3}</p><p></p><p><img src="/styles/default/xenforo/smilies/default/happy.gif" class="smilie" loading="lazy" alt=":)" title="Happy :)" data-shortname=":)" /></p></blockquote><p></p>
[QUOTE="Sweet_Johnson, post: 28410425, member: 582370"] DAY 1 : The Bandit Yeti THM{IT'S A Y3T1 CHR1$TMA$} Use the ls command to list the files present in the current directory. How many log files are present? 2 Elf McSkidy managed to capture the logs generated by the web server. What is the name of this log file? webserver.log On what day was Santa's naughty and nice list stolen? Friday What is the IP address of the attacker? 10.10.249.191 What is the name of the important list that the attacker stole from Santa? santaslist.txt Look through the log files for the flag. The format of the flag is: THM{} THM{STOLENSANTASLIST} =====DAY 3 ===== What is the name of the Registrar for the domain santagift.shop? NAMECHEAP INC Find the website's source code (repository) on github.com and open the file containing sensitive credentials. Can you find the flag? {THM_OSINT_WORKS} What is the name of the file containing passwords? config.php What is the name of the QA server associated with the website? qa.santagift.shop What is the DB_PASSWORD that is being reused between the QA and PROD environments? S@nta2022 ===== DAY 4 ===== What is the name of the HTTP server running on the remote host? apache What is the name of the service running on port 22 on the QA server? ssh What flag can you find after successfully accessing the Samba service? {THM_SANTA_SMB_SERVER} What is the password for the username santahr? santa25 ===== DAY 5 ===== Use Hydra to find the VNC password of the target with IP address 10.10.208.109. What is the password? 1q2w3e4r Using a VNC client on the AttackBox, connect to the target of IP address 10.10.208.109. What is the flag written on the target’s screen? THM{I_SEE_YOUR_SCREEN} ===== DAY 6 ===== What is the email address of the sender? [email]chief.elf@santaclaus.thm[/email] What is the return address? [email]murphy.evident@bandityeti.thm[/email] On whose behalf was the email sent? chief elf What is the X-spam score? 3 What is hidden in the value of the Message-ID field? AoC2022_Email_Analysis Visit the email reputation check website provided in the task. What is the reputation result of the sender's email address? risky Check the attachments. What is the filename of the attachment?# Division_of_labour-Load_share_plan.doc What is the hash value of the attachment? 0827bb9a2e7c0628b82256759f0f888ca1abd6a2d903acdb8e44aca6a1a03467 Visit the Virus Total website and use the hash value to search. Navigate to the behaviour section. What is the second tactic marked in the Mitre ATT&CK section? Defense Evasion Visit the InQuest website and use the hash value to search. What is the subcategory of the file? macro_hunter ===== DAY 7 ===== What is the version of CyberChef found in the attached VM? 9.49.0 How many recipes were used to extract URLs from the malicious doc? 10 We found a URL that was downloading a suspicious file; what is the name of that malware? mysterygift.exe What is the last defanged URL of the bandityeti domain found in the last step? hxxps[://]cdn[.]bandityeti[.]THM/files/index What is the ticket found in one of the domains? (Format: Domain/<GOLDEN_FLAG>) THM_MYSTERY_FLAG ===== DAY 8 ===== What flag is found after attacking the provided EtherStore Contract? flag{411_ur_37h_15_m1n3} :) [/QUOTE]
Insert quotes…
Verification
Dahaya deken beduwama keeyada?
Post reply
Top
Bottom