- Namespace: picoctf/examples
- ID: forensics-disk
- Type: custom
- Category: Forensics
- Points: 1
- Templatable: yes
- MaxUsers: 0
Can you find the flag in this disk image?
Download the disk image {{url_for("disk.flag.img.gz", "here")}}.
- Download the disk image and search slack space with a sleuthkit tool to find the flag!
Download the disk image and use blkls -s
to find the flag in slack space.
cpus: 0.5
memory: 128m
pidslimit: 20
ulimits:
- nofile=128:128
diskquota: 64m
init: true
Usage of sleuthkit tools
- disk
- example
- author: LT 'syreal' Jones
- organization: picoCTF
- event: picoCTF Problem Developer Training