[OSINT] Breach

■■■… I am new to htb. I tried all the passwords, email IDs, firstname, lastname to unlock the key.docs but no luck. Anyone can give a hint please?

I managed to get the key after unlocking the key.docx. Kind of lost, what to do next? any idea?

Type your comment> @nkhan95 said:

I managed to get the key after unlocking the key.docx. Kind of lost, what to do next? any idea?

Woooowwwww… I manage to complete the challenge… I am loving HTB… Long live HTB :slight_smile:

It would be better if those 6 IP addresses from the breach file were reserved instead of pointing to innocent victims of this game. Someone will attempt to breach a real system thinking it is a part of the challenge.

Type your comment> @cknu said:

I’m starting this challenge now, but i’m having problems with the password for the orginal zip file. The one in the site is not working. Checksum is ok.
Is this the password i need to find first? Or is for another file inside the zip?

Anyone?

Type your comment> @cknu said:

Type your comment> @cknu said:

I’m starting this challenge now, but i’m having problems with the password for the orginal zip file. The one in the site is not working. Checksum is ok.
Is this the password i need to find first? Or is for another file inside the zip?

Anyone?

Works for me.

can anyone give me a nudge through PM?

I’m also having trouble figuring this one out… Have narrowed it down but think I am focusing too much on the half dozen entries.
I would really appreciate some help.

Type your comment> @sl0wl0ris said:

I’m also having trouble figuring this one out… Have narrowed it down but think I am focusing too much on the half dozen entries.
I would really appreciate some help.

Never mind…

Hi guys, I’ve been able to get the content of the key.docx file. Any hint on the next step?
tnx!

Type your comment> @fr4c1d0 said:

Hi guys, I’ve been able to get the content of the key.docx file. Any hint on the next step?
tnx!

never mind

In case someone else didn’t take the previous guy’s warning seriously… try your passwords with Microsoft Word. I wasted a good few hours trying with Calligra which just denies access, even with the correct password. A sanity check with office2john saved me eventually… If anyone needs any help, PM me :slight_smile:

Stuck on Key.docx file. Can anyone give me an Nudge?

@50m30n3 Thanks for the help!! If anyone need ping me!!

Dont overthink anything, did it without twitter, all the info that you need is in the files.

Solved :slight_smile: thanks @Dethread for the help

Solved. PM me if you need help.
My suggestion:
look at doing “We Have A Leak” first, or narrow down your scope.

“We have a leak” surely helped a lot.

Not sure if this can be classified as OSINT, can be easily done without web.
It was like a “misdirection” on me.

Hack The Box

@davihack it follows OSINT procedures to some degree

Do not bruteforce, examine closely everything you are given :slight_smile: