Given the capture file chall.pcap, find the flag. The file was modified to hide it.

Opening the capture in Wireshark, almost every packet is Modbus. Filtering with not modbus leaves a few TCP packets that appear unimportant. The packet contents include jumbled ASCII, and several packets are malformed. One field changes consistently: Register Value.

Apply the register value as a column and sort by it. The values have the same shape as ASCII codes: for example, the common value 32 is a space. Extract all packets with register values using tshark:

tshark -r chall.pcap -Y "mbtcp.len==5" -T fields -e modbus.regval_uint16 > out.txt
python3 -c "for line in open('out.txt', 'r'): print(chr(int(line)), end='')"

The output is scrambled but partly readable, suggesting several interleaved streams. Wireshark’s Statistics > Conversations > IPv4 shows three TCP streams, so extract them individually:

tshark -r chall.pcap -Y "tcp.stream==0 and mbtcp.len==5" -T fields -e modbus.regval_uint16 > out.txt

The first stream is legible. The other streams reveal that the flag is cut off where the packets become malformed.

The malformed packets all travel from 238.0.0.6 to 238.0.0.5. Filtering on those addresses shows flag{ in the register values before the corruption starts. In intact packets, offset 0x37 contains the byte 0xe8; malformed packets instead contain the four ASCII bytes for \\xe8, increasing their length by three bytes.

Intact:     ... 00 00 03 e8 00 00 00 05 64 03 02 00 7b
Malformed:  ... 00 00 03 5c 78 65 38 00 00 00 05 64 03 02 00 55

Replacing \\xe8 with the actual byte 0xe8 repairs the packets. This Scapy script modifies the affected raw payloads:

from scapy.all import IP, Raw, rdpcap, wrpcap

packets = rdpcap("chall.pcap")
pattern = b"\\x5c\\x78\\x65\\x38"
replacement = b"\\xe8"

for packet in packets:
    if IP in packet and packet[IP].src == "238.0.0.6" and packet[IP].dst == "238.0.0.5":
        if Raw in packet:
            packet[Raw].load = bytes(packet[Raw]).replace(pattern, replacement)

wrpcap("chall_modified.pcap", packets)

After loading the repaired capture into Wireshark, the conversion script reveals:

flag{UND3r_TH3_M40G1C4L_M0DBU55555

Replacing flag with roo and adding the closing brace seems promising, but it is still incorrect.

Packet 118 was not malformed, but appears among the repaired packets. Its register value is ASCII 0, producing M40G1C4L instead of M4G1C4L. Remove that zero to get the flag:

roo{UND3r_TH3_M4G1C4L_M0DBU55555}