tags:
forensics
whysw@PLUS
Find the version of the hacker's default browser!
using FTK imager, found
/Users/secre/NTUSER.DAT
using registry viewer, found that
/Software/Microsoft/Windows/Shell/Associations/UrlAssociations/http/UserChoice/ProgId
is ChromeHTML
.
using FTK imager, found
/Program Files (x86)/Google/Chrome/Application/83.0.4103.61
folder.
send 83.0.4103.61
to server and got the flag.
FLAG : Defenit{Th1s_15_Chr0m3_Br0w53r!!}