Homemade CTF Challenge: 06 "A Brisk Stroll"

John Hammond · Intermediate ·🔐 Cybersecurity ·9y ago

Key Takeaways

The video demonstrates a homemade CTF challenge called 'A Brisk Stroll' where participants have to find a hidden flag in an image file using tools like binwalk and Google reverse image search. The challenge creator, John Hammond, explains how he designed the challenge and provides a walkthrough of the solution.

Full Transcript

welcome back everyone I wanted to Showcase more of the local CTF or Capture the Flag competition that I put together as practice as like a local exercise for my uh my my school and at Cyber team so this challenge I want to show off is the brisk stroll or uh a Brisk stroll and the prompt is have you seen this image before there is no hint for this one but the file name is a walk with the numbers St PNG so you would go ahead and download this and I'll zoom out here you'll see that is a picture and the ploy or the hope is that they'd go ahead and save this picture and the hint that uh have you seen this before is hey if you haven't already if you if you haven't seen it you can do a Google reverse image search to go ahead and find where it comes from so uh obviously you I guess if you wanted to not knowing you would want to do a little bit of stenography on the thing you can you could run a exf tool on a with the numbers you could run strings on it um but it is it is just a regular image file I didn't I didn't try to pull any tricks with that however what I did do is I added more to it so if we did that Google image search Total fail um we could upload that walk with the numbers that we just uploaded and then it will keep looking for us and it will note that that oh it looks like atmosphere okay there's a there's a red herring there but pages that include this image oh it says binwalk for mac and Linux oh binwalk comments oh binwalk for more analysis tool very clearly I would hope binwalk is uh what they would be pointed to if they had not seen this or or have known of this tool before so at that point you would end up installing or working with binwalk and I would recommend running binwalk on that file and hey it notices there the image of course the ZB compress data is a fault that benok tends to do and it also sees a program in there which is interesting so uh we can run binw walk- e to extract stuff out of it and we would run it on the walk with the numbers and now we see that extracted folder so we can CD into that and it sees this elf file so that's got to be executable so we could run could run that thing and there it is we get our flag cool uscga binwalk is a good tool to know so we'll submit that and get our points and I'll show off how I actually put that together so it's real simple um what I ended up doing for one thing was writing out the source code for this program which is again insanely simple it literally just prints out the flag um and then I think I put together a create. sh where I would compile the file make it 32-bit compile that source code and then I'd include the image the original image which is just that simple picture and then I'd include that who put this here executable that I just compiled and I just created and then I put it in that I walk with the numbers uh then I I put it in that image that I would upload and use for the CTF challenge so that's really all it is that that executable who put this here was that source code that I would print out the flag and the way that you can include that inside of the image is by actually catting it one after the other because cat will look will output these files in sequence and typically an image viewer once it sees the end of an image it just goes oh that's that's really all that the image is it just displays the image no problem at all but you can use binwalk to see are is there anything more inside this file in which case we had a complete Program stuck inside the image so that's why I wanted to introduce binwalk as a tool if they hadn't seen it before if they if they if they have not heard of it so that's how you ended up solving and creating that one that's a Brisk stroll and we'll move on to some more of these challenges in a future video so thanks for watching guys

Original Description

If you would like to support me, please like, comment & subscribe, and check me out on Patreon: https://patreon.com/johnhammond010 E-mail: johnhammond010@gmail.com PayPal: http://paypal.me/johnhammond010 GitHub: https://github.com/JohnHammond Site: http://www.johnhammond.org Twitter: https://twitter.com/_johnhammond
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from John Hammond · John Hammond · 38 of 60

1 Code Commentaries? PHP to JavaScript in Bash and PHP!
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
2 Tutorials? MySQL connection with PHP and Bash!
Tutorials? MySQL connection with PHP and Bash!
John Hammond
3 Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
4 JavaScript Splits The URL!
JavaScript Splits The URL!
John Hammond
5 HTML Tables in Python!
HTML Tables in Python!
John Hammond
6 HTML, Net Shares, GML!
HTML, Net Shares, GML!
John Hammond
7 Python 08 Programming Style and Comments
Python 08 Programming Style and Comments
John Hammond
8 Python 26 Object Oriented Programming
Python 26 Object Oriented Programming
John Hammond
9 75 Python Tutorials, Out Now!
75 Python Tutorials, Out Now!
John Hammond
10 Batch 14 Mathematical Expressions
Batch 14 Mathematical Expressions
John Hammond
11 Batch 85 Array Append
Batch 85 Array Append
John Hammond
12 Batch 86 Array Count
Batch 86 Array Count
John Hammond
13 Batch 87 Array Index
Batch 87 Array Index
John Hammond
14 Batch 88 Array Insert
Batch 88 Array Insert
John Hammond
15 Batch 89 Array Remove
Batch 89 Array Remove
John Hammond
16 Batch 90 Array Reverse
Batch 90 Array Reverse
John Hammond
17 Python [colorama] 00 Installing on Linux
Python [colorama] 00 Installing on Linux
John Hammond
18 Python [colorama] 09 Cursor Position
Python [colorama] 09 Cursor Position
John Hammond
19 Python [hashlib] 02 Algorithms
Python [hashlib] 02 Algorithms
John Hammond
20 Python 00 Installing IDLE on Linux
Python 00 Installing IDLE on Linux
John Hammond
21 Python [pygame] 11 Rectangular Collision Detection
Python [pygame] 11 Rectangular Collision Detection
John Hammond
22 Python [pygame] 12 Platforming Rectangular Collision Resolution
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
23 Python [XML-RPC] 01 Research
Python [XML-RPC] 01 Research
John Hammond
24 Python [pyenchant] 03 Personal Word Lists
Python [pyenchant] 03 Personal Word Lists
John Hammond
25 FancyURLopener Authentication and User-Agent [urllib] 03
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
26 Python 04: PEP8 Coding
Python 04: PEP8 Coding
John Hammond
27 Python Challenge! 17 COOKIES
Python Challenge! 17 COOKIES
John Hammond
28 Google CTF 2016: Ernst Echidna
Google CTF 2016: Ernst Echidna
John Hammond
29 Google CTF 2016: Spotted Quoll
Google CTF 2016: Spotted Quoll
John Hammond
30 Google CTF 2016: Can you Repo It?
Google CTF 2016: Can you Repo It?
John Hammond
31 Google CTF 2016: No Big Deal
Google CTF 2016: No Big Deal
John Hammond
32 Google CTF 2016: In Recorded Conversation
Google CTF 2016: In Recorded Conversation
John Hammond
33 Homemade CTF Challenge: 01 "Orchestra"
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
34 Homemade CTF Challenge: 02 "Bae's Base"
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
35 Homemade CTF Challenge: 03 "Web Hunt"
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
36 Homemade CTF Challenge: 04 "UPX"
Homemade CTF Challenge: 04 "UPX"
John Hammond
37 Homemade CTF Challenge: 05 "The Assumption Song"
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
Homemade CTF Challenge: 06 "A Brisk Stroll"
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
39 Homemade CTF Challenge: 06 "I lost my password!"
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
40 web25 :: Mr. Robot : EKOPARTY CTF 2016
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
41 web50 : RFC 7230 :: EKOPARTY CTF 2016
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
42 misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
43 Hack The Vote 2016 CTF: Sander's Fan Club [web100]
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
44 Hack The Vote 2016 CTF Warpspeed [forensics150]
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
45 Juniors CTF 2016 :: Black Suprematic Square
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
46 Juniors CTF 2016 :: Six Strange Tales
Juniors CTF 2016 :: Six Strange Tales
John Hammond
47 Juniors CTF 2016 :: Lost Code
Juniors CTF 2016 :: Lost Code
John Hammond
48 Juniors CTF 2016 :: Here Goes!
Juniors CTF 2016 :: Here Goes!
John Hammond
49 Juniors CTF 2016 :: Southern Cross
Juniors CTF 2016 :: Southern Cross
John Hammond
50 Juniors CTF 2016 :: Clone Attack
Juniors CTF 2016 :: Clone Attack
John Hammond
51 Juniors CTF 2016 :: Dirty Repo
Juniors CTF 2016 :: Dirty Repo
John Hammond
52 Juniors CTF 2016 :: Hackers Blog
Juniors CTF 2016 :: Hackers Blog
John Hammond
53 Juniors CTF 2016 :: Voting!!!
Juniors CTF 2016 :: Voting!!!
John Hammond
54 Juniors CTF 2016 :: The Good, The Bad and The Junkman
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
55 Juniors CTF 2016 :: Stop Thief!
Juniors CTF 2016 :: Stop Thief!
John Hammond
56 Juniors CTF 2016 :: ROFL
Juniors CTF 2016 :: ROFL
John Hammond
57 Juniors CTF 2016 :: Restriced Area
Juniors CTF 2016 :: Restriced Area
John Hammond
58 Juniors CTF 2016 :: Oh SSH!
Juniors CTF 2016 :: Oh SSH!
John Hammond
59 HackCon CTF 2017 TRIVIA and BONUS Challenges
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
60 HackCon CTF 2017 "Bacche" Challenges
HackCon CTF 2017 "Bacche" Challenges
John Hammond

This video teaches how to solve a CTF challenge by using binwalk to extract a hidden executable from an image file. The challenge creator explains how he designed the challenge and provides a walkthrough of the solution. The video introduces the concept of steganography and the use of tools like binwalk and Google reverse image search.

Key Takeaways
  1. Download the image file
  2. Use Google reverse image search to find the source of the image
  3. Use binwalk to extract the hidden executable
  4. Run the executable to find the flag
  5. Use exiftool and strings to analyze the image file
💡 Binwalk can be used to extract hidden files and executables from image files

Related Reads

📰
My Rate Limiter Only Checked IP Addresses. One VPN Bypassed It and Took Down My API.
Learn how relying solely on IP address-based rate limiting can be bypassed by VPNs and take down your API, and why more robust security measures are necessary
Medium · Machine Learning
📰
My Rate Limiter Only Checked IP Addresses. One VPN Bypassed It and Took Down My API.
Learn how a simple rate limiter can be bypassed by a VPN and take down an API, highlighting the importance of robust security measures
Medium · Programming
📰
20 Certificate Transparency Tricks for Recon: Master Advanced Asset Discovery for Ethical Hacking
Master advanced asset discovery for ethical hacking using Certificate Transparency tricks
Medium · Cybersecurity
📰
TryHackMe: Linux Fundamentals Part 3
Learn Linux fundamentals through hands-on labs on TryHackMe, improving cybersecurity skills
Medium · Cybersecurity
Up next
Google Did The Impossible
Boot dev
Watch →