No Comment

Writeup for No Comment (OSINT) - 1337UP LIVE CTF (2024) πŸ’œ

Video walkthrough

VIDEO

Challenge Description

Or is there? πŸ€”

Solution

Players download this cool image 😎

Could check for embedded files or stego, or perhaps do a reverse image lookup on Google or TinEye.

In fact, the title and description is a hint! If we check the image metadata (EXIF), we'll see a comment.

Recognise the comment format? It's from Imgur, where URLs are formatted like imgur.com/a/{alphanumeric} (albums) and imgur.com/g/{alphanumeric} (galleries).

Let's visit the imgur link and see the same image, along with a comment.

We base64 decode it..

Visit the pastebin link and find a password protected note. Enter long_strange_trip to uncover a hex string.

Converting from hex doesn't work, so we check the users public pastes and find this one..

Quite a hint, but at the last minute I worried this part was too guessy. We XOR the data with the same password and get the flag πŸ™‚

Flag: INTIGRITI{instagram.com/reel/C7xYShjMcV0}

Fun fact: the insta reel is from a concert I saw in the Las Vegas sphere and I will never stop talking about it πŸ˜‚

Last updated