Homemade CTF Challenge: 06 "A Brisk Stroll"
Skills:
Network Security70%
Key Takeaways
The video demonstrates a homemade CTF challenge called 'A Brisk Stroll' where participants have to find a hidden flag in an image file using tools like binwalk and Google reverse image search. The challenge creator, John Hammond, explains how he designed the challenge and provides a walkthrough of the solution.
Full Transcript
welcome back everyone I wanted to Showcase more of the local CTF or Capture the Flag competition that I put together as practice as like a local exercise for my uh my my school and at Cyber team so this challenge I want to show off is the brisk stroll or uh a Brisk stroll and the prompt is have you seen this image before there is no hint for this one but the file name is a walk with the numbers St PNG so you would go ahead and download this and I'll zoom out here you'll see that is a picture and the ploy or the hope is that they'd go ahead and save this picture and the hint that uh have you seen this before is hey if you haven't already if you if you haven't seen it you can do a Google reverse image search to go ahead and find where it comes from so uh obviously you I guess if you wanted to not knowing you would want to do a little bit of stenography on the thing you can you could run a exf tool on a with the numbers you could run strings on it um but it is it is just a regular image file I didn't I didn't try to pull any tricks with that however what I did do is I added more to it so if we did that Google image search Total fail um we could upload that walk with the numbers that we just uploaded and then it will keep looking for us and it will note that that oh it looks like atmosphere okay there's a there's a red herring there but pages that include this image oh it says binwalk for mac and Linux oh binwalk comments oh binwalk for more analysis tool very clearly I would hope binwalk is uh what they would be pointed to if they had not seen this or or have known of this tool before so at that point you would end up installing or working with binwalk and I would recommend running binwalk on that file and hey it notices there the image of course the ZB compress data is a fault that benok tends to do and it also sees a program in there which is interesting so uh we can run binw walk- e to extract stuff out of it and we would run it on the walk with the numbers and now we see that extracted folder so we can CD into that and it sees this elf file so that's got to be executable so we could run could run that thing and there it is we get our flag cool uscga binwalk is a good tool to know so we'll submit that and get our points and I'll show off how I actually put that together so it's real simple um what I ended up doing for one thing was writing out the source code for this program which is again insanely simple it literally just prints out the flag um and then I think I put together a create. sh where I would compile the file make it 32-bit compile that source code and then I'd include the image the original image which is just that simple picture and then I'd include that who put this here executable that I just compiled and I just created and then I put it in that I walk with the numbers uh then I I put it in that image that I would upload and use for the CTF challenge so that's really all it is that that executable who put this here was that source code that I would print out the flag and the way that you can include that inside of the image is by actually catting it one after the other because cat will look will output these files in sequence and typically an image viewer once it sees the end of an image it just goes oh that's that's really all that the image is it just displays the image no problem at all but you can use binwalk to see are is there anything more inside this file in which case we had a complete Program stuck inside the image so that's why I wanted to introduce binwalk as a tool if they hadn't seen it before if they if they if they have not heard of it so that's how you ended up solving and creating that one that's a Brisk stroll and we'll move on to some more of these challenges in a future video so thanks for watching guys
Original Description
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: https://patreon.com/johnhammond010
E-mail: johnhammond010@gmail.com
PayPal: http://paypal.me/johnhammond010
GitHub: https://github.com/JohnHammond
Site: http://www.johnhammond.org
Twitter: https://twitter.com/_johnhammond
Playlist
Uploads from John Hammond · John Hammond · 38 of 60
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
▶
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
Tutorials? MySQL connection with PHP and Bash!
John Hammond
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
JavaScript Splits The URL!
John Hammond
HTML Tables in Python!
John Hammond
HTML, Net Shares, GML!
John Hammond
Python 08 Programming Style and Comments
John Hammond
Python 26 Object Oriented Programming
John Hammond
75 Python Tutorials, Out Now!
John Hammond
Batch 14 Mathematical Expressions
John Hammond
Batch 85 Array Append
John Hammond
Batch 86 Array Count
John Hammond
Batch 87 Array Index
John Hammond
Batch 88 Array Insert
John Hammond
Batch 89 Array Remove
John Hammond
Batch 90 Array Reverse
John Hammond
Python [colorama] 00 Installing on Linux
John Hammond
Python [colorama] 09 Cursor Position
John Hammond
Python [hashlib] 02 Algorithms
John Hammond
Python 00 Installing IDLE on Linux
John Hammond
Python [pygame] 11 Rectangular Collision Detection
John Hammond
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
Python [XML-RPC] 01 Research
John Hammond
Python [pyenchant] 03 Personal Word Lists
John Hammond
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
Python 04: PEP8 Coding
John Hammond
Python Challenge! 17 COOKIES
John Hammond
Google CTF 2016: Ernst Echidna
John Hammond
Google CTF 2016: Spotted Quoll
John Hammond
Google CTF 2016: Can you Repo It?
John Hammond
Google CTF 2016: No Big Deal
John Hammond
Google CTF 2016: In Recorded Conversation
John Hammond
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
Homemade CTF Challenge: 04 "UPX"
John Hammond
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
Juniors CTF 2016 :: Six Strange Tales
John Hammond
Juniors CTF 2016 :: Lost Code
John Hammond
Juniors CTF 2016 :: Here Goes!
John Hammond
Juniors CTF 2016 :: Southern Cross
John Hammond
Juniors CTF 2016 :: Clone Attack
John Hammond
Juniors CTF 2016 :: Dirty Repo
John Hammond
Juniors CTF 2016 :: Hackers Blog
John Hammond
Juniors CTF 2016 :: Voting!!!
John Hammond
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
Juniors CTF 2016 :: Stop Thief!
John Hammond
Juniors CTF 2016 :: ROFL
John Hammond
Juniors CTF 2016 :: Restriced Area
John Hammond
Juniors CTF 2016 :: Oh SSH!
John Hammond
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
HackCon CTF 2017 "Bacche" Challenges
John Hammond
More on: Network Security
View skill →Related Reads
📰
📰
📰
📰
My Rate Limiter Only Checked IP Addresses. One VPN Bypassed It and Took Down My API.
Medium · Machine Learning
My Rate Limiter Only Checked IP Addresses. One VPN Bypassed It and Took Down My API.
Medium · Programming
20 Certificate Transparency Tricks for Recon: Master Advanced Asset Discovery for Ethical Hacking
Medium · Cybersecurity
TryHackMe: Linux Fundamentals Part 3
Medium · Cybersecurity
🎓
Tutor Explanation
DeepCamp AI