|
| 1 | +--- |
| 2 | +title: Fall |
| 3 | +date: 2024-12-23 19:47:00 +/-0600 |
| 4 | +categories: [Capture The Flags, Platypawn 2024] |
| 5 | +tags: [ctf, platypawn2024, osint, writeups] |
| 6 | +description: Platypawn 2024 Fall Challenge |
| 7 | +--- |
| 8 | + |
| 9 | +> Challenge description: |
| 10 | +> |
| 11 | +> Which building can be seen in this pretty fall photo? |
| 12 | +> |
| 13 | +> The flag should be entered like `PP{nameofbuilding}`, where `nameofbuilding` is the name of the pictured building in the language of the country it is in. There are only lowercase letters and no spaces, diacritics or other special characters in the flag. |
| 14 | +{: .prompt-info } |
| 15 | + |
| 16 | + |
| 17 | + |
| 18 | +A good old regular OSINT challenge. While pretty easy they can still be very insightful into how we can properly approach finding where photos were taken. |
| 19 | + |
| 20 | +So, first step is to go over the metadata of the photo. While it might seem trivial, photos contain lots and lots of metadata about a multitude of things, inculding but not limited to the camera and its settings, the software used to edit it, the GPS location of the photo and time of day, and etc. |
| 21 | + |
| 22 | +In order to go over the metadata, we're going to be using `exiftool` |
| 23 | + |
| 24 | +```terminal |
| 25 | +
|
| 26 | +┌─[slavetomints@parrot]─[~/ctfs/platypwn-2024/osint/fall/images] |
| 27 | +└──╼ $exiftool Fall.jpg |
| 28 | +ExifTool Version Number : 12.57 |
| 29 | +File Name : Fall.jpg |
| 30 | +Directory : . |
| 31 | +File Size : 8.1 MB |
| 32 | +File Modification Date/Time : 2024:12:02 21:32:02-06:00 |
| 33 | +File Access Date/Time : 2024:12:02 21:32:02-06:00 |
| 34 | +File Inode Change Date/Time : 2024:12:07 09:11:39-06:00 |
| 35 | +File Permissions : -rw-r--r-- |
| 36 | +File Type : JPEG |
| 37 | +File Type Extension : jpg |
| 38 | +MIME Type : image/jpeg |
| 39 | +JFIF Version : 1.01 |
| 40 | +Exif Byte Order : Little-endian (Intel, II) |
| 41 | +Make : Platycam |
| 42 | +Camera Model Name : Platycam2000 |
| 43 | +Orientation : Horizontal (normal) |
| 44 | +X Resolution : 72 |
| 45 | +Y Resolution : 72 |
| 46 | +Resolution Unit : inches |
| 47 | +Software : GIMP 2.10.38 |
| 48 | +Modify Date : 2024:10:18 14:06:00 |
| 49 | +Y Cb Cr Positioning : Co-sited |
| 50 | +Exposure Time : 1/236 |
| 51 | +F Number : 1.7 |
| 52 | +Exposure Program : Not Defined |
| 53 | +ISO : 100 |
| 54 | +Sensitivity Type : Unknown |
| 55 | +Recommended Exposure Index : 0 |
| 56 | +Exif Version : 0220 |
| 57 | +Date/Time Original : 2024:12:18 21:12:00 |
| 58 | +Create Date : 2024:12:18 21:12:00 |
| 59 | +Components Configuration : Y, Cb, Cr, - |
| 60 | +Shutter Speed Value : 1/235 |
| 61 | +Brightness Value : 11.1 |
| 62 | +Exposure Compensation : 0 |
| 63 | +Max Aperture Value : 1.0 |
| 64 | +Metering Mode : Center-weighted average |
| 65 | +Light Source : Other |
| 66 | +Flash : Off, Did not fire |
| 67 | +Focal Length : 2.4 mm |
| 68 | +Sub Sec Time : 793 |
| 69 | +Sub Sec Time Original : 793 |
| 70 | +Sub Sec Time Digitized : 793 |
| 71 | +Flashpix Version : 0100 |
| 72 | +Color Space : sRGB |
| 73 | +Exif Image Width : 3696 |
| 74 | +Exif Image Height : 5731 |
| 75 | +Exposure Mode : Auto |
| 76 | +White Balance : Auto |
| 77 | +Digital Zoom Ratio : 1 |
| 78 | +Focal Length In 35mm Format : 0 mm |
| 79 | +Scene Capture Type : Standard |
| 80 | +Profile CMM Type : Little CMS |
| 81 | +Profile Version : 4.3.0 |
| 82 | +Profile Class : Display Device Profile |
| 83 | +Color Space Data : RGB |
| 84 | +Profile Connection Space : XYZ |
| 85 | +Profile Date Time : 2024:10:18 12:03:32 |
| 86 | +Profile File Signature : acsp |
| 87 | +Primary Platform : Apple Computer Inc. |
| 88 | +CMM Flags : Not Embedded, Independent |
| 89 | +Device Manufacturer : |
| 90 | +Device Model : |
| 91 | +Device Attributes : Reflective, Glossy, Positive, Color |
| 92 | +Rendering Intent : Perceptual |
| 93 | +Connection Space Illuminant : 0.9642 1 0.82491 |
| 94 | +Profile Creator : Little CMS |
| 95 | +Profile ID : 0 |
| 96 | +Profile Description : GIMP built-in sRGB |
| 97 | +Profile Copyright : Public Domain |
| 98 | +Media White Point : 0.9642 1 0.82491 |
| 99 | +Chromatic Adaptation : 1.04788 0.02292 -0.05022 0.02959 0.99048 -0.01707 -0.00925 0.01508 0.75168 |
| 100 | +Red Matrix Column : 0.43604 0.22249 0.01392 |
| 101 | +Blue Matrix Column : 0.14305 0.06061 0.71393 |
| 102 | +Green Matrix Column : 0.38512 0.7169 0.09706 |
| 103 | +Red Tone Reproduction Curve : (Binary data 32 bytes, use -b option to extract) |
| 104 | +Green Tone Reproduction Curve : (Binary data 32 bytes, use -b option to extract) |
| 105 | +Blue Tone Reproduction Curve : (Binary data 32 bytes, use -b option to extract) |
| 106 | +Chromaticity Channels : 3 |
| 107 | +Chromaticity Colorant : Unknown |
| 108 | +Chromaticity Channel 1 : 0.64 0.33002 |
| 109 | +Chromaticity Channel 2 : 0.3 0.60001 |
| 110 | +Chromaticity Channel 3 : 0.15001 0.06 |
| 111 | +Device Mfg Desc : GIMP |
| 112 | +Device Model Desc : sRGB |
| 113 | +Image Width : 3696 |
| 114 | +Image Height : 5731 |
| 115 | +Encoding Process : Progressive DCT, Huffman coding |
| 116 | +Bits Per Sample : 8 |
| 117 | +Color Components : 3 |
| 118 | +Y Cb Cr Sub Sampling : YCbCr4:2:0 (2 2) |
| 119 | +Aperture : 1.7 |
| 120 | +Image Size : 3696x5731 |
| 121 | +Megapixels : 21.2 |
| 122 | +Shutter Speed : 1/236 |
| 123 | +Create Date : 2024:12:18 21:12:00.793 |
| 124 | +Date/Time Original : 2024:12:18 21:12:00.793 |
| 125 | +Modify Date : 2024:10:18 14:06:00.793 |
| 126 | +Focal Length : 2.4 mm |
| 127 | +Light Value : 9.4 |
| 128 | +
|
| 129 | +
|
| 130 | +``` |
| 131 | + |
| 132 | +Hm, seems like they scrubbed the GPS data out of it. Unfortunate. However, we can always reverse image search it. The unique mosaic pattern in the tile is bound to show up on the internet. To do this, we're going to utilize a simple `Yandex Image Search` while we are probably not going to find the exact picture, we'll hopefully find something simlar to it. |
| 133 | + |
| 134 | +The first result I found send me to [https://www.flickr.com/photos/31599232@N07/4142304144/](https://www.flickr.com/photos/31599232@N07/4142304144/), where there was a photo of the Orangery Palace in Potsdam, Germany. After some more searching I was able to match the tile using [Google Maps](https://www.google.com/maps/@52.405056,13.0287733,3a,90y,233.9h,79.65t/data=!3m11!1e1!3m9!1sAF1QipOrf6e2d1C5ibz-3DDIjcT6mDKArbHEN96_d7_Y!2e10!3e11!6shttps:%2F%2Flh5.googleusercontent.com%2Fp%2FAF1QipOrf6e2d1C5ibz-3DDIjcT6mDKArbHEN96_d7_Y%3Dw900-h600-k-no-pi10.351935903734187-ya126.90023591295241-ro0-fo100!7i8704!8i4352!9m2!1b1!2i37?entry=ttu&g_ep=EgoyMDI0MTIwNC4wIKXMDSoASAFQAw%3D%3D). |
| 135 | + |
| 136 | +Last thing to do, translate the name. Wikipedia is always good for that, and we now know the locals call it the Orangerieschloss, lets lowercase it and call this a success! |
| 137 | + |
| 138 | +FLAG: `PP{orangerieschloss}` |
0 commit comments