Clear it in 3 steps
-
Start the environment
-
Investigate the target
-
Submit the flag
Perform encrypted-iOS-backup password verification with a safe iTunes metadata fixture. No real iPhone or backup is used. Match candidate passwords to the Manifest.plist digest, then recover the recorded message payload.
Candidate passwords are in evidence/wordlist.txt
Match them against PasswordSHA256 in ios_backup/Manifest.plist
Decode message_payload_b64 in Messages.db.enc