Rating: 1.0

This was a classic Wireshark forensics challenge. The description mentioned some traffic but the flag isn't in plaintext. There was a big dump of packets, but we can whittle it down massively by filtering for HTTP (34 packets out of 7,941).

The last few packets are the most interesting. It is the only request with a 200 (OK) response. If we follow the TCP stream, we get the web page requested. The page contains some obfuscated Javascript.


<button type="button"
Click to display the flag!</button>


This can be easily deobfuscated to easy-to-read javascript, that contains the flag.
