Challenge Author: SUSIE
Category: Forensics
Difficulty: Easy
Description
Files can always be changed in a secret way. Can you find the flag?
Process / Notes
wgetthe file (cat.jpg)file,cat,strings,hexdump | grep -i 'pico'- There is a ‘picoCTF’ line or two in there!
exiftool- The ‘Current IPTC Digest’ seems like it may be hex encoded, and ‘License’ seems like it may be base64 encoded
base64 -dthe license one and it revealed the flag!- Checking the other out of curiosity – doesn’t seem like anything was there
4 minutes 25 seconds to complete
Hints
Core Lessons
- Know how to access a file’s meta-data with a tool like ’exiftool’
- Recognize base64 encoding
- Know how to decode base64 into plain-text