masar-ctf -Day 1

Dr.kasbr
5 min readAug 18, 2024

--

Note !!! this explanation is for beginners. I will take them on a beautiful journey to hunt some flags.

Digital Forensics

Sounds exciting so let’s start hunting

first he talk about images have a lot of data

so we can see Mr.Abdulaziz with his image lets check him

btw good name lol

anyway we can serch in google just to undrstand

What data can be obtained from the image?

so we can get all this just from metadata ? that look great let’s hack NASA !!(jk)

in fact Mr.Abdulaziz left comment rally ???

you think we don’t know hex or how to encode ? lol

Anyway, when we see this, it’s easy to see that it’s a hex but let’s say you work in the media and you love challenges, there are 3 websites that will be very useful to you.

https://gchq.github.io/CyberChef/

CyberChef will find its hex and will decode it and give you the flag

another website

https://www.boxentriq.com/code-breaking/cipher-identifier

this is not the only way to solve this there is huge ways to solve that

— — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — —

that look cool soo we need find

function can calculate science <<< i hope its real

anyway lets check the website he say function so lets check src code =

ctrl +u or F12 but he say function so is there functions in html or css ?

maybe chatgpt lie but lets check js

ohh is that flag ? let’s make parts togethers

— — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — —

hola hola

if you smrat you will see the title is hex ?

soo let’s check from what we learned today

but in fact we don’t need this hint bcz its super ez

in fact there is like 3 hints told us its mores mores mores when we google for mores

now we know its code but lets find it

so lets check the image what he have

1- if we open it in txt

or

-2 if we use strings

so lets just decode it

we can by CyberChef or any website or tools do what you want

— — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — —

finally some secrets

when we check the website we can see there is comment in home page

lets check this hint.html

Who doesn’t like 01?!!! <<<< Other than me anyway lets decode it

we need to find the passwd for his secret

smart way i just try find page with name secret

but we need good way so there is a lot of tools help us to find pages

for ex dirb dirsearch gobuster feroxbuster etc ….

i will use feroxbuster

And this is the passwd for pastebin umutDT1Kf3

--

--

No responses yet