<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Challenges</title><link>http://pandalabs.pandasecurity.com/archive/tags/Challenges/default.aspx</link><description>Tags: Challenges</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Panda Challenge: Medium Level</title><link>http://pandalabs.pandasecurity.com/archive/Panda-Challenge_3A00_-Medium-Level.aspx</link><pubDate>Mon, 13 Jul 2009 10:47:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1019</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1019.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1019</wfw:commentRss><description>&lt;p&gt;&lt;img height="140" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/PandaChallenge/challenge2.jpg" width="700" /&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Welcome to the 2nd Panda Challenge. As promised, this will be harder. In the previous one we had more than 1 thousand downloads and just 44 right answers, let&amp;#39;s see how this goes. Joxean has been the creator of this challenge. This are the &amp;quot;instructions&amp;quot;&amp;nbsp;that Joxean wants you to know before starting:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="Tahoma"&gt;&amp;quot;&lt;/font&gt;&lt;font face="Tahoma"&gt;To create a program which automatically solves the problem posed by the program by communicating with it using the protocol this program understands.&amp;quot;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;The file can be downloaded &lt;/font&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;a href="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/07/14/level.exe.patch.exe.zip"&gt;here&lt;/a&gt;&lt;/font&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;. Enjoy yourselves and don&amp;rsquo;t forget to send the challenge solution (the created program) to pandachallenge at pandasecurity dot com&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;I will be publishing updates on&amp;nbsp;&lt;/font&gt;&lt;a href="http://twitter.com/luis_corrons" title="Twitter" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Twitter&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;, and next Monday I&amp;#39;ll let you know the final results.&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;The terms and conditions of the competition can be downloaded from &lt;/font&gt;&lt;a href="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/PandaChallenge/Terms.pdf"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;here&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;.&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img height="140" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/PandaChallenge/challengesp.jpg" width="700" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Bienvenidos al 2&amp;ordm; reto Panda. Tal y como promet&amp;iacute;, este ser&amp;aacute; m&amp;aacute;s complicado. En el anterior tuvimos m&amp;aacute;s de mil descargas y 44 respuestas correctas, vamos a ver qu&amp;eacute; tal va este. Joxean ha sido el creador de este reto. Estas son las &amp;quot;instrucciones&amp;quot; que Joxean quiere que sep&amp;aacute;is antes de comenzar:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&amp;ldquo;Hacer un programa que resuelva autom&amp;aacute;ticamente el problema planteado por el programa comunic&amp;aacute;ndose con &amp;eacute;l por el protocolo que dicho programa entienda&amp;rdquo;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;El fichero puede ser descargado desde &lt;/font&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;a href="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/07/14/level.exe.patch.exe.zip"&gt;aqu&amp;iacute;&lt;/a&gt;&lt;/font&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;. Disfrutad&amp;nbsp;y no olvid&amp;eacute;is enviar la soluci&amp;oacute;n al reto (el programa creado) a pandachallenge arroba pandasecurity punto com&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Ir&amp;eacute; actualizando informaci&amp;oacute;n desde &lt;/font&gt;&lt;a href="http://twitter.com/luis_corrons" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Twitter&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;, y el pr&amp;oacute;ximo lunes publicar&amp;eacute; los resultados finales.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Los t&amp;eacute;rminos y condiciones del reto las pod&amp;eacute;is descargar &lt;/font&gt;&lt;a href="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/PandaChallenge/Bases.pdf"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;aqu&amp;iacute;&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;.&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1019" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Contest/default.aspx">Contest</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Challenges/default.aspx">Challenges</category></item><item><title>June's Crypto Challenge Results</title><link>http://pandalabs.pandasecurity.com/archive/June_2700_s-Crypto-Challenge-Results.aspx</link><pubDate>Wed, 17 Jun 2009 21:45:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1008</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1008.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1008</wfw:commentRss><description>
&lt;p&gt;June&amp;#39;s &lt;a href="http://pandalabs.pandasecurity.com/archive/Crypto-Challenge.aspx"&gt;Crypto Challenge&lt;/a&gt; has now came to a close and I&amp;#39;m glad to report that several participants were able to complete the challenge successfully. I&amp;#39;ve posted the solution below for everyone to see, so &lt;a href="http://pandalabs.pandasecurity.com/archive/Crypto-Challenge.aspx"&gt;click here&lt;/a&gt; if you want to try and solve the challenge without looking at the answer first.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;&lt;br /&gt; &lt;strong&gt;Winners&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
1st - &lt;a href="http://twitter.com/apolkosnik"&gt;@apolkosnik&amp;nbsp;&lt;/a&gt;&lt;br /&gt;
2nd - &lt;a href="http://www.twitter.com/alecrwaters"&gt;@alecrwaters&lt;/a&gt;&lt;br /&gt;
3rd - &lt;a href="http://twitter.com/shftleft"&gt;@shftleft&lt;/a&gt;&lt;br /&gt;
4th - &lt;a href="http://twitter.com/RavenBlackthorn"&gt;@RavenBlackthorn&lt;/a&gt;&lt;br /&gt;
5th - &lt;a href="http://twitter.com/schuetzdj"&gt;@schuetzdj&lt;/a&gt;&lt;br /&gt;
6th - &lt;a href="http://twitter.com/SecShoggoth"&gt;@SecShoggoth&lt;/a&gt;&lt;br /&gt;
7th - &lt;a href="http://twitter.com/DuncanGilmore"&gt;@DuncanGilmore&lt;/a&gt;&lt;br /&gt;
8th - &lt;a href="http://twitter.com/thornmaker"&gt;@thornmaker&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;/p&gt;


&lt;p&gt;&lt;strong&gt;Solution&lt;/strong&gt;&lt;br /&gt; &lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 1&lt;/strong&gt;: Decode Base64&lt;br /&gt;
&lt;br /&gt;
NjggNzQgNzQgNzAgNzMgNjMgNnMgNnAgNnMgNnIgNzMgNnAgNjEgNzMgNjggNzMgNnAgNjEgNzMg&lt;br /&gt;
NjggNjQgNnAgNjQgNnMgNzQgNjcgNjUgNzQgNjQgNzIgNnMgNzAgNjIgNnMgNzggNjQgNnMgNzQg&lt;br /&gt;
NjMgNnMgNnEgNzMgNnAgNjEgNzMgNjggNzUgNzMgNnAgNjEgNzMgNjggMzIgMzIgMzAgMzggMzAg&lt;br /&gt;
NzMgNnAgNjEgNzMgNjggNjggNjkgNnIgNzQgNjQgNnMgNzQgNjggNzQgNnEgNnA=&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 2&lt;/strong&gt;: Decode ROT13&lt;br /&gt;
&lt;br /&gt;
68 74 74 70 73 63 6s 6p 6s 6r 73 6p 61 73 68 73 6p 61 73 68 64 6p 64 6s 74 67 65 74 64 72 6s 70 62 6s 78 64 6s 74 63 6s 6q 73 6p 61 73 68 75 73 6p 61 73 68 32 32 30 38 30 73 6p 61 73 68 68 69 6r 74 64 6s 74 68 74 6q 6p&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Step 3&lt;/strong&gt;: Decode Hex&lt;br /&gt;
&lt;br /&gt;
68 74 74 70 73 63 6f 6c 6f 6e 73 6c 61 73 68 73 6c 61 73 68 64 6c 64 6f 74 67 65 74 64 72 6f 70 62 6f 78 64 6f 74 63 6f 6d 73 6c 61 73 68 75 73 6c 61 73 68 32 32 30 38 30 73 6c 61 73 68 68 69 6e 74 64 6f 74 68 74 6d 6c&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Step 4&lt;/strong&gt;: Form URL&lt;br /&gt;
&lt;br /&gt;
httpscolonslashslashdldotgetdropboxdotcomslashuslash22080slashhintdothtml&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Step 5&lt;/strong&gt;: View URL&lt;br /&gt;
&lt;br /&gt;
http://dl.getdropbox.com/u/22080/hint.html&lt;br /&gt;
&lt;br /&gt;
&lt;img src="http://farm4.static.flickr.com/3359/3637157780_256fa5a2ee.jpg" /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Step 6&lt;/strong&gt;: Decode ASCII art using link at bottom of hint.html&lt;br /&gt;
&lt;br /&gt;
&lt;img src="http://farm4.static.flickr.com/3329/3637157810_848f2501e2.jpg" /&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 7&lt;/strong&gt;: ASCII decodes to an image of a link (&lt;a href="http://bit.ly/ciph3r"&gt;http://bit.ly/ciph3r&lt;/a&gt;).&amp;nbsp; Access the link to retrieve the ancient alphabet.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 8&lt;/strong&gt;: Revisit hint.html and decode the AES encrypted string.&amp;nbsp; Key and other hints are hidden in CSS.&lt;/p&gt;

&lt;p&gt;
&lt;br /&gt;
&lt;img src="http://farm4.static.flickr.com/3659/3636401667_88d830f05c.jpg" /&gt;
&lt;/p&gt;


&lt;p&gt;&lt;strong&gt;Decoded&lt;/strong&gt;: httpscolonslashslashdldotgetdropboxdotcomslashuslash22080slashfiledotzip &lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Step 8&lt;/strong&gt;: Fix URL&lt;br /&gt;
&lt;br /&gt;
https://dl.getdropbox.com/slash/u/22080/file.zip&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Step 9: &lt;/strong&gt;Download and Unzip the file&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Step 10&lt;/strong&gt;: Use Spectrogram 16 (hint from CSS) to analyze the WAV file&lt;br /&gt;
&lt;br /&gt;
&lt;img src="http://farm3.static.flickr.com/2463/3636408333_7fa2413b05_o.png" /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Step 10&lt;/strong&gt;: Decode the image from the spectral analysis with the legend found in Step 7&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Step 11&lt;/strong&gt;: Decode&amp;nbsp; ROT13&lt;br /&gt;
&lt;br /&gt;
&lt;span class="status-body"&gt;&lt;span class="entry-content"&gt;graroebhf&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Final Solution&lt;/strong&gt;: Tenebrous (It was the word of the day) :)&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;I&amp;#39;m going to start working on creating the next challenge soon, so feel free to &lt;a href="http://twitter.com/lithium"&gt;send me&lt;/a&gt; your suggestions and I will factor them in next round.&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1008" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Cryptography/default.aspx">Cryptography</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Challenges/default.aspx">Challenges</category></item></channel></rss>