Post

Spectrum

What time is the meeting happening? (4 points)

Seeing this file is quite strange, let’s see what it is before jumping into it 0.<

image

Ok, I know it is a file disk image

image

Thread tags mentioning a tool Photorec

1
2
photorec image.dd

Select Disk image.dd -> Proceed

image

Select FAT16 -> Search

image

Select ext2/ext3

image

Select Whole to extract the whole thing

image

Select the destination region to export

image

OK, restore is done

image

1
2
exiftool *.jpg

There are 2 things to note:

  • Location:name of the challenge
  • Artist:steghide password: cheese on toast

    Where is Spectrum?

    Password steghide but which file is it from?

image

image

I tried all .jpg image files and .zip files but it doesn’t work .-.

Ignore it for now :)), if the tags mention fcrackzip, let’s try it

In the linux machine, there is a rockyou file available, take it out and use it

Command below to decompress and download the tool

1
2
sudo gzip -d /usr/share/wordlists/rockyou.txt.gz
sudo apt install fcrackzip

Yeh, that’s all there is, now let’s get started as a hacker :)))

1
2
sudo fcrackzip -D -p /usr/share/wordlists/rockyou.txt f0000240_brown.zip

Password: garfield

Using that to decompress we have

image

Right, now that we have the file, let’s try steghide -.-

image

Ummm,…

image

After a while of trying again and again, I knew it was encoded from base 58

image

but… it must have been reversed -_-

image

00:10:51

What are the supposed coordinates for the deal? (4 points)

And then, now go back and continue with white.wav, ignoring all the others =]

Tags mentioning Audio Software, I like Audacity because I like it @.@

As usual when testing with Audacity switch to Spectrogram and miracles will happen

I bet this is a GPS map, trust me!!

I’m never wrong once, I’m wrong a lot XD

image

51.505278 0.055278

Looking into these coordinates, what is the name of this location? (2 points)

Go to GG Map and enter like me and boom

image

image

London City Airport

goodbye, thank you for reading until now //~//

This post is licensed under CC BY 4.0 by the author.