#forensics CTF

27 messages · Page 1 of 1 (latest)

fading swift
#

you using linux or windows?

short niche
#

macos

#

what i opeing the file with VM

#

(windows)

fading swift
#

I think on macos you can run stat <filename>

short niche
fading swift
short niche
fading swift
short niche
#

ohhh my bad

fading swift
#

ls -l file shows modification time

short niche
#

it is

#

sorry

short niche
#

i was thinking that IDA can help me but nothing

fading swift
#

IDA is an overkill and I don't think it can be used for this case since modification date and stuff are considered shadow data or whatever it's called and is stored on something called Inode (at least on Ext4)

short niche
fading swift
#

I don't understand much in binaries but I don't think it'd make sense to hide modification date in data...

#

maybe we're a bit confused about the objective

#

run strings <filename>

short niche
fading swift
#

can you send the link of the ctf?

short niche
#

pls

fading swift
#

sure