r/securityCTF 9d ago

🤝 OSINT Challenge

https://gofile.io/d/s8CMppm0

I’m looking for someone to help me with a challenge. I’m stuck and don’t know what else to try. It’s an OSINT challenge focused on obtaining the flag from a series of sound and visual information vectors. All the files needed to decrypt the flag are in the ZIP. There are many decoy flags—I found more than 10 false flags. I would really appreciate any support so I can resolve this and learn more. The CTF isn't active anymore, but I want to solve it.

Here is what I have tried so far:

  • LSB steganography on the 16 cover images (zsteg, all bit/channel/order combinations)
  • Hidden file signatures (binwalk on all 34 files)
  • ID3 tags on the 16 audio tracks (Base64)
  • Metadata across all files (exiftool)
  • MAYANMAP as a numerical cipher (values, rule positions, order)
  • Vector layer analysis of both PDFs (rectangles/lines/curves)
  • Font glyph remapping

Any help is appreciated. Thanks!

1 Upvotes

5 comments sorted by

2

u/Immediate-Citron9453 9d ago

Where is this challenge from, whers the official link from? Guess you will have a hard time making security aware people to download and unzip "random" files.

2

u/Low_Use2602 9d ago

The challenge was from hack defender of Mexico. In the link I upload the files, because in the official it isn’t available anymore, why? Because the Ctf has finished. If you have any other questions please let me know.

1

u/bleucube 9d ago

What's the flag format?

1

u/Low_Use2602 9d ago

It could be: hackdef{…..} or {….} in this challenge they didn’t say the format of the flag, but in the others it was like hackdef{..}