{"id":960,"date":"2022-09-13T16:39:47","date_gmt":"2022-09-13T16:39:47","guid":{"rendered":"https:\/\/shreyapohekar.com\/blogs\/?p=960"},"modified":"2022-09-13T16:39:50","modified_gmt":"2022-09-13T16:39:50","slug":"winja-ctf-nullcon-goa-2022-osint-challenges-writeup","status":"publish","type":"post","link":"https:\/\/shreyapohekar.com\/blogs\/winja-ctf-nullcon-goa-2022-osint-challenges-writeup\/","title":{"rendered":"Winja CTF @ Nullcon Goa 2022 &#8211; Osint Challenges Writeup"},"content":{"rendered":"\n<p>Hello CTFers! This blog contains the write-up of 3 OSINT challenges created as part of Winja CTF (Nullcon Goa 2022 Edition). You can find the solutions to Winja CTF web challenges <a href=\"https:\/\/shreyapohekar.com\/blogs\/winja-ctf-web-challenges-solutions-nullcon-goa-2022\/\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>.<\/p>\n\n\n\n<p>So Let&#8217;s get started!<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Lost in Space<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Challenge description<\/h3>\n\n\n\n<p>Our Astronomer is lost in space!!! He needs some urgent help otherwise he would run out of oxygen. The astronomer had noted the code somewhere that he could use to unlock the spare oxygen cylinder. Can you help him find the code?<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Solution<\/h3>\n\n\n\n<ol class=\"wp-block-list\"><li>Right-click on the landing page and view the page source.<\/li><li>Scrolling down to the bottom you will find the email address ie cassielayer@gmail.com and just above there is the password<\/li><\/ol>\n\n\n\n<p>Got the creds already?! Now here&#8217;s a catch!<\/p>\n\n\n\n<p>You need to find the website for which these credentials can be used.<\/p>\n\n\n\n<p>We can here use a tool named <code>holehe<\/code> which can easily do the job. The tool can be found <a href=\"https:\/\/github.com\/megadose\/holehe\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a> . <\/p>\n\n\n\n<p>Once the setup and installation are done, simply run<\/p>\n\n\n\n<pre class=\"wp-block-preformatted wpf-blue-background\">holehe cassielayer@gmail.com<\/pre>\n\n\n\n<p>This will output that <strong>cassielayer@gmail.com<\/strong> has been used on evernote.com<\/p>\n\n\n\n<p>Now go to evernote.com and login and you will find your flag in the scratch pad<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"959\" height=\"302\" src=\"https:\/\/shreyapohekar.com\/blogs\/wp-content\/uploads\/2022\/09\/flag.png\" alt=\"\" class=\"wp-image-995\" srcset=\"https:\/\/shreyapohekar.com\/blogs\/wp-content\/uploads\/2022\/09\/flag.png 959w, https:\/\/shreyapohekar.com\/blogs\/wp-content\/uploads\/2022\/09\/flag-300x94.png 300w, https:\/\/shreyapohekar.com\/blogs\/wp-content\/uploads\/2022\/09\/flag-768x242.png 768w, https:\/\/shreyapohekar.com\/blogs\/wp-content\/uploads\/2022\/09\/flag-640x202.png 640w\" sizes=\"(max-width: 959px) 100vw, 959px\" \/><\/figure>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Cern<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Challenge description<\/h3>\n\n\n\n<p>The world&#8217;s largest and highest-energy particle collider has got its 3-word unique name. Can you find it?<\/p>\n\n\n\n<p>Flag format: flag{word.word.word}<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Solution<\/h3>\n\n\n\n<p>The hint to this challenge is in the description ie a 3-word name. You would have already guessed that the 3-word name for the location of CERN has to be identified.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>go to what3words<\/li><li>search for cern Switzerland (as we know that Cern is in Switzerland)<\/li><\/ol>\n\n\n\n<p>You will find your flag ie <strong>flag{dusty.retail.hilltop}<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">theUniverse<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Challenge description<\/h3>\n\n\n\n<p>Have you ever wondered how massive the stars are?? If you are aware of the Rigel and VY cannis majoris, you might know this one too\u2026<br>You will find your answer at 2:54.<\/p>\n\n\n\n<p>Attachment image<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"88\" height=\"88\" src=\"https:\/\/shreyapohekar.com\/blogs\/wp-content\/uploads\/2022\/08\/harry.jpg\" alt=\"\" class=\"wp-image-962\"\/><figcaption>harry.jpg<\/figcaption><\/figure>\n\n\n\n<p>flag format: flag{word}<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Solution<\/h3>\n\n\n\n<p>&#8220;You will find your answer at 2:54&#8221; implies that it is a youtube video. The image is provided in the attachment to direct the players to the youtube channel that has the intended youtube video. An image reverse search on Yandex can be used to find the youtube channel. <\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<p class=\"responsive-video-wrap clr\"><iframe loading=\"lazy\" title=\"Universe Size Comparison 3D\" width=\"1200\" height=\"675\" src=\"https:\/\/www.youtube.com\/embed\/i93Z7zljQ7I?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen><\/iframe><\/p>\n<\/div><\/figure>\n\n\n\n<p>flag is <strong>flag{betelgeuse}<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p>Hope you enjoyed solving Winja CTF. If you have any feedback, do let me know in the comments. If you wish to be a part of Winja CTF team, do reach out and we will help you out with the further process.<\/p>\n\n\n\n<p>That&#8217;s all for this post. See you in the next one. <\/p>\n\n\n\n<p>Until then, Happy hunting! \ud83d\ude42<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This post contains the OSINT challenges created as part of Winja CTF, Nullcon Goa 2022.<\/p>\n","protected":false},"author":1,"featured_media":992,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ocean_post_layout":"","ocean_both_sidebars_style":"","ocean_both_sidebars_content_width":0,"ocean_both_sidebars_sidebars_width":0,"ocean_sidebar":"","ocean_second_sidebar":"","ocean_disable_margins":"enable","ocean_add_body_class":"","ocean_shortcode_before_top_bar":"","ocean_shortcode_after_top_bar":"","ocean_shortcode_before_header":"","ocean_shortcode_after_header":"","ocean_has_shortcode":"","ocean_shortcode_after_title":"","ocean_shortcode_before_footer_widgets":"","ocean_shortcode_after_footer_widgets":"","ocean_shortcode_before_footer_bottom":"","ocean_shortcode_after_footer_bottom":"","ocean_display_top_bar":"default","ocean_display_header":"default","ocean_header_style":"","ocean_center_header_left_menu":"","ocean_custom_header_template":"","ocean_custom_logo":0,"ocean_custom_retina_logo":0,"ocean_custom_logo_max_width":0,"ocean_custom_logo_tablet_max_width":0,"ocean_custom_logo_mobile_max_width":0,"ocean_custom_logo_max_height":0,"ocean_custom_logo_tablet_max_height":0,"ocean_custom_logo_mobile_max_height":0,"ocean_header_custom_menu":"","ocean_menu_typo_font_family":"","ocean_menu_typo_font_subset":"","ocean_menu_typo_font_size":0,"ocean_menu_typo_font_size_tablet":0,"ocean_menu_typo_font_size_mobile":0,"ocean_menu_typo_font_size_unit":"px","ocean_menu_typo_font_weight":"","ocean_menu_typo_font_weight_tablet":"","ocean_menu_typo_font_weight_mobile":"","ocean_menu_typo_transform":"","ocean_menu_typo_transform_tablet":"","ocean_menu_typo_transform_mobile":"","ocean_menu_typo_line_height":0,"ocean_menu_typo_line_height_tablet":0,"ocean_menu_typo_line_height_mobile":0,"ocean_menu_typo_line_height_unit":"","ocean_menu_typo_spacing":0,"ocean_menu_typo_spacing_tablet":0,"ocean_menu_typo_spacing_mobile":0,"ocean_menu_typo_spacing_unit":"","ocean_menu_link_color":"","ocean_menu_link_color_hover":"","ocean_menu_link_color_active":"","ocean_menu_link_background":"","ocean_menu_link_hover_background":"","ocean_menu_link_active_background":"","ocean_menu_social_links_bg":"","ocean_menu_social_hover_links_bg":"","ocean_menu_social_links_color":"","ocean_menu_social_hover_links_color":"","ocean_disable_title":"default","ocean_disable_heading":"default","ocean_post_title":"","ocean_post_subheading":"","ocean_post_title_style":"","ocean_post_title_background_color":"","ocean_post_title_background":0,"ocean_post_title_bg_image_position":"","ocean_post_title_bg_image_attachment":"","ocean_post_title_bg_image_repeat":"","ocean_post_title_bg_image_size":"","ocean_post_title_height":0,"ocean_post_title_bg_overlay":0.5,"ocean_post_title_bg_overlay_color":"","ocean_disable_breadcrumbs":"default","ocean_breadcrumbs_color":"","ocean_breadcrumbs_separator_color":"","ocean_breadcrumbs_links_color":"","ocean_breadcrumbs_links_hover_color":"","ocean_display_footer_widgets":"default","ocean_display_footer_bottom":"default","ocean_custom_footer_template":"","ocean_post_oembed":"","ocean_post_self_hosted_media":"","ocean_post_video_embed":"","ocean_link_format":"","ocean_link_format_target":"self","ocean_quote_format":"","ocean_quote_format_link":"post","ocean_gallery_link_images":"on","ocean_gallery_id":[],"footnotes":""},"categories":[365,280,2],"tags":[],"class_list":["post-960","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-conference","category-ctf","category-information-security","entry","has-media"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/shreyapohekar.com\/blogs\/wp-json\/wp\/v2\/posts\/960"}],"collection":[{"href":"https:\/\/shreyapohekar.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/shreyapohekar.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/shreyapohekar.com\/blogs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/shreyapohekar.com\/blogs\/wp-json\/wp\/v2\/comments?post=960"}],"version-history":[{"count":3,"href":"https:\/\/shreyapohekar.com\/blogs\/wp-json\/wp\/v2\/posts\/960\/revisions"}],"predecessor-version":[{"id":996,"href":"https:\/\/shreyapohekar.com\/blogs\/wp-json\/wp\/v2\/posts\/960\/revisions\/996"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/shreyapohekar.com\/blogs\/wp-json\/wp\/v2\/media\/992"}],"wp:attachment":[{"href":"https:\/\/shreyapohekar.com\/blogs\/wp-json\/wp\/v2\/media?parent=960"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/shreyapohekar.com\/blogs\/wp-json\/wp\/v2\/categories?post=960"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/shreyapohekar.com\/blogs\/wp-json\/wp\/v2\/tags?post=960"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}