CanYouSee (picoCTF 8)

Challenge Author: Mubarak Mikail

Difficulty: Easy

Description

How about some hide and seek?

Process / Notes

  1. wget the download
  2. zip file, unzip to reveal a jpg
  3. file and exiftool on it also show it’s a jpg
  4. display to view it through ImageMagick shows a dark, celestial room with shadowed figures
  5. Checked Hint 1
  6. Tried to hexdump
  7. Checked hint 2
  8. I’ve got a feeling it’s about using a tool or recognizing something I don’t know, checking a walk-through at 12:03
  9. The “Attribution URL” seen in the meta-data is in base64!
  10. Decoding with base64 -d reveals the flag

14 minutes 33 seconds to complete

Hints

  1. How can you view the information about the picture?
  2. If something isn’t in the expected form, maybe it deserves attention?

Core Lessons

  1. Look carefully at all the pieces you have access to. I saw the metadata with exiftool but did not recognize that there was something there to decode