POSTAL (Misc Challenge Writeup) -- CTF GDG Algiers 2022
October 09, 2022 | 5 Minute Read
The GDG Algiers one of the largest community of developers and tech enthusiasts in Algeria and MENA region, has organized the first edition of the GDG Algiers CTF. Competition started October 7 and finish 48 hours later. Was a very fun and hard CTF, with some medium challenges. Very good infra and support. We chose the "misc" category challenge called "POSTAL" because its solution involves a number of specific techniques related to osint, forensics and cryptography.
We notice some strange barcodes in the upper left part of the image that catches our attention
So, after rereading the challenge, we do the search again but this time focusing on barcodes in Australia and looking for the challenge “Going Postal” from “DaVinciCTF 2022” (hint from the challenge description) we knew that the estrange barcode it’s indeed an Australia Post 4 state barcode.
We find this page AusPost very usefull to solve this part of the challenge
Using the instructions to decode the barcode with the online tool we have this:
Ok, know we have some info, but what could we do whit that?
We inspect our original image (msg.jpg) looking for some embedded file:
And we find that inside the image has a encrypted file encoded by steghide
Using the information we obtained from the AusPost page, specifically the “Classification Code” (K4N64r00zz) as passphrase, we are able to extract the file hidden inside the image
Now we have a zip file (Treasure.zip)
When inspecting the file we notice that it is encrypted.
We need to crack it, for that we will use Jhon the Ripper
But we must first get the hash of the zip file
and then proceed whit the crack
Now we have the zip password (baltimore), open the zip and we have two files
Inside the file call “findme” we have a hint
Checking the information we obtained from the AusPost page, we have the “Sorting Code” (78475110) that its the password for the gpg file
We have the flag!!
CyberErudites{4U57r4114_P057_4_57473}
Thanks GDG Algiers, Shellmates Club and CyberErudites team for the excellent job. Kudos to everyone who put the event together
For fun and knowledge, always think out of the box! :)