Лаборатория TJCTF 2016 - May 1, 2600 [forensics 100]

delimitry
, 1 июня 2016

Sometimes I miss that land of bliss.
Outbox.zip  

We are given an archive with dbx file.

I've Installed undbx -  a tool to extract e-mails from Outlook Express .dbx files.
http://manpages.ubuntu.com/manpages/wily/man1/undbx.1.html

Performed unbase64 and got a file, with TAPE header (Microsoft tape format).

Downloaded and built mtftar - a tool for translating a MTF stream to a TAR stream.
./mtftar -v -f out.mtf | tar xfv -

Found a file flag.doc, where image with flag was inserted.

And got a flag:
tjctf{@_b1@sT_Fr0M_tH3_Pa$t}