Thursday, January 5, 2017

SANS Holiday Hack 2016-Santa's Zip File

Santa’s Zip File

Browser: Firefox

Look at Santa’s business card in Josh and Jessica’s house in the quest2016.holidayhackchallenge.com game.  Note that Santa has a twitter account and an instagram account @santawclaus. 

Santa's Business Card

Image Description:  Santa’s Business Card

Visit Santa’s Instagram page and look at his images.

Unfortunately, the images weren’t properly scrubbed of sensitive information.  On this photo of Hermey’s desk, you can see a url of a website on the paper in the Violent Python book: www.northpolewonderland.com, as well as a zip file name on the computer screen: SantaGram_v4.2.zip.


Image Description:  The Instagram Image on Santa’s page that has sensitive information.

Navigate to https://www.northpolewonderland.com/SantaGram_v4.2.zip.  Depending on the browser one uses, they may be prompted to confirm that they would like to download the file.  Otherwise, the file will probably be saved to the Downloads folder by default.

No comments:

Post a Comment