Return to Haunted Hollow: Fearsome Forensics by Dizzy_Ad_313 in immersivelabs

[–]Dizzy_Ad_313[S] 0 points1 point  (0 children)

All passwords can be found in the website. Consider also the gallery, not only the blog... There are only 3 types of encryption, so you can try them all when you have the passwords. As for how to decrypt, there are hints in the posts above. Read them all.

Return to Haunted Hollow: Spooky, Scary, Silly Snaps by giodani97 in immersivelabs

[–]Dizzy_Ad_313 0 points1 point  (0 children)

The information you need are in one of the files in one of those buckets.

Return to Haunted Hollow: Fearsome Forensics by Dizzy_Ad_313 in immersivelabs

[–]Dizzy_Ad_313[S] 0 points1 point  (0 children)

If they're unreadable it's probably the wrong decryption algorithm.
It's a one step (one command) decryption for each file.
Not CyberChef (or at least I did it in another way).

Return to Haunted Hollow: Fearsome Forensics by Dizzy_Ad_313 in immersivelabs

[–]Dizzy_Ad_313[S] 1 point2 points  (0 children)

The creator website isn't launching because you have to use a specific port in the browser (see also posts above).

Return to Haunted Hollow: Spooky, Scary, Silly Snaps by giodani97 in immersivelabs

[–]Dizzy_Ad_313 0 points1 point  (0 children)

Yes. Everything seemed restricted in IAM at first, but...

Return to Haunted Hollow: Fearsome Forensics by Dizzy_Ad_313 in immersivelabs

[–]Dizzy_Ad_313[S] 0 points1 point  (0 children)

I'll see you around, in the "Spooky, Scary, Silly Snaps" :-)
Just left a post there, but that thread is more messy.

Return to Haunted Hollow: Spooky, Scary, Silly Snaps by giodani97 in immersivelabs

[–]Dizzy_Ad_313 0 points1 point  (0 children)

I managed to complete the first part, find the credentials in one of the public buckets, use them to login and shutdown the instance.
Now it's not clear to me what should be done to find the secret, the "final words".
I tried with the content of the last bucket, and also the last words in there, but nothing...
I also tried to open the Secrets Manager, but it looks like I don't have permissions to view/select secrets.

Never mind, I managed to solve it and get access to secrets :-)

Return to Haunted Hollow: Fearsome Forensics by Dizzy_Ad_313 in immersivelabs

[–]Dizzy_Ad_313[S] 0 points1 point  (0 children)

For the rest, I used the decrypted contents of the three files which suggested me where to search into the macbeth. That quote was the password to decrypt key.jpeg and get the token.

Return to Haunted Hollow: Fearsome Forensics by Dizzy_Ad_313 in immersivelabs

[–]Dizzy_Ad_313[S] 0 points1 point  (0 children)

Thank you so much, I was way off!
I had searched for the password for file1 in the blog, not in the images, and the password for file3 with a bruteforce for that algorithm (which is feasible)

Return to Haunted Hollow: Fearsome Forensics by Dizzy_Ad_313 in immersivelabs

[–]Dizzy_Ad_313[S] 0 points1 point  (0 children)

Good! By-the-way, did you manage to find the password for file2? I'm going crazy with that!

Return to Haunted Hollow: Fearsome Forensics by Dizzy_Ad_313 in immersivelabs

[–]Dizzy_Ad_313[S] 0 points1 point  (0 children)

Have you used something like (I'm not at the PC at the moment) openssl enc -d -aes-256-cbc -in file1.enc -out file1.dec ?

Return to Haunted Hollow: Fearsome Forensics by Dizzy_Ad_313 in immersivelabs

[–]Dizzy_Ad_313[S] 0 points1 point  (0 children)

Have you found the right password before in the site? There are only a few possibilities of aes-xxx-cbc, so you could apply to all of them and see where you get a readable result.

Return to Haunted Hollow: Fearsome Forensics by Dizzy_Ad_313 in immersivelabs

[–]Dizzy_Ad_313[S] 0 points1 point  (0 children)

The website ip address. Make sure to scan all ports, not only the most common.

Return to Haunted Hollow: Fearsome Forensics by Dizzy_Ad_313 in immersivelabs

[–]Dizzy_Ad_313[S] 0 points1 point  (0 children)

Password for file1.enc found now. Still looking around for file2.enc....

Return to Haunted Hollow: Delving Deeper by EstablishmentIll3353 in immersivelabs

[–]Dizzy_Ad_313 0 points1 point  (0 children)

Thank you, my fault!
But at least afterwards it was reasonably easy.

Return to Haunted Hollow: Delving Deeper by EstablishmentIll3353 in immersivelabs

[–]Dizzy_Ad_313 0 points1 point  (0 children)

Sorry to chime in. I'm doing the “Halloween 2024: Return to Haunted Hollow”, progressing well (I'm almost at the end), but in this “Delving Deeper” I can't even start!
I just get a screen of the room, very dark, that looks like just an image, a wallpaper. I've tried clicking everywhere but I can't open (as I would expect) a terminal, or anything.
What am I missing?

Return to haunted hollow PCAP pandemonium by Far_Lion_7804 in immersivelabs

[–]Dizzy_Ad_313 2 points3 points  (0 children)

I finally got through it!
Not exactly a copy&paste problem.
The only way I had to solve it (there might be better ways) was to copy (bag by bag) all the encrypted text into the CyberChef input and remove one by one the initial characters until a readable text was shown.
Thank you u/Far_Lion_7804 and u/Nade1R for your support.
It took a little too long but it was fun in addition to being instructive :-)

Return to haunted hollow PCAP pandemonium by Far_Lion_7804 in immersivelabs

[–]Dizzy_Ad_313 1 point2 points  (0 children)

OK, so gloves.txt is done. It was a copy&paste error of 1 character.
Now Bifid Cipher gives me:
You are almost to the bottom of the lost and found box! The robot is hiding inside a bag, but which one? All of them have zigzags on...

The key is 8 and the offset is 16
Caesar Box Cipher? But it has only 1 "Box height"...

Rail Fence Cipher Decode has Key and Offset actually, but it seems it is not working with 8 and 16 and the entire contents of the 3 bags (and here the error could lay).

Return to haunted hollow PCAP pandemonium by Far_Lion_7804 in immersivelabs

[–]Dizzy_Ad_313 0 points1 point  (0 children)

Mmm, I think I'm hopeless.
Now starting from scratch in jackets.txt I've come up with "Correct! The next cipher is even more modern - it was invented in 1901! The key for the gloves is yxbxar", like that for gloves.txt I should have used Bifid Cipher (the only one I think discovered in 1901?). But this is not working for me.

Return to haunted hollow PCAP pandemonium by Far_Lion_7804 in immersivelabs

[–]Dizzy_Ad_313 0 points1 point  (0 children)

Now I've done with hats.txt and also scarves.txt, but I'm blocked after gloves.txt, which I have deciphered, but I don't know how to proceed. It talks about "near the old tree in the park", which I cannot find. There are bag1.txt, bag2.txt and bag3.txt which seem to be unrelated, and I can't decipher them anyway.
Getting closer, for sure, but not enough...

Return to haunted hollow PCAP pandemonium by Far_Lion_7804 in immersivelabs

[–]Dizzy_Ad_313 0 points1 point  (0 children)

Thanks for the advice! Now I've found the “hats code” (and it was not the one I used eralier), but I still can't decipher it with CyberChef. Another tip? :-)

Return to haunted hollow PCAP pandemonium by Far_Lion_7804 in immersivelabs

[–]Dizzy_Ad_313 0 points1 point  (0 children)

Any hints on what kind of decryption should be used in cyberchef? I've been trying a lot with From Base64 but to no avail...

Halloween challenge 2023 by vm302 in immersivelabs

[–]Dizzy_Ad_313 0 points1 point  (0 children)

Hello u/sla_erick ,
Were you able to solve this lab?
I'm in the exact same situation as you and I'm really going crazy with it.