diff --git a/OSINT/Commitment/Flag.png b/OSINT/Commitment/Flag.png new file mode 100644 index 0000000..8cba0bd Binary files /dev/null and b/OSINT/Commitment/Flag.png differ diff --git a/OSINT/Commitment/README.md b/OSINT/Commitment/README.md new file mode 100644 index 0000000..68a74ea --- /dev/null +++ b/OSINT/Commitment/README.md @@ -0,0 +1,16 @@ +## Commitment +The main idea finding the flag is just basic Github commit search. + +#### Step-1: +When I searched for `hoshimaseok` alias, I got a Reddit and a GitHub profile. Nothing interesting in Reddit profile, so I went directly for Github profile and entered the repo: [SomethingFishy](https://github.com/hoshimaseok/SomethingFishy) + +#### Step-2: +However, I found nothing there, but in the `dev` branch, I got many [commits](https://github.com/hoshimaseok/SomethingFishy/commits/dev). So, there I searched for all commits and luckily I got the flag [here](https://github.com/hoshimaseok/SomethingFishy/commit/5e750ab0de940e25b56aa82ff7738c859a8c2b92). + + + +#### Step-3: +Finally the flag becomes: +`csictf{sc4r3d_0f_c0mm1tm3nt}` + +##### Note: This might be easy if we cloned the repo and search in .git/logs by Regex. Haven't given a try though xP. Just a thought. \ No newline at end of file diff --git a/OSINT/Flying Places/Comment.png b/OSINT/Flying Places/Comment.png new file mode 100644 index 0000000..dc474f5 Binary files /dev/null and b/OSINT/Flying Places/Comment.png differ diff --git a/OSINT/Flying Places/Flight.jpg b/OSINT/Flying Places/Flight.jpg new file mode 100644 index 0000000..15ad20d Binary files /dev/null and b/OSINT/Flying Places/Flight.jpg differ diff --git a/OSINT/Flying Places/README.md b/OSINT/Flying Places/README.md new file mode 100644 index 0000000..0693029 --- /dev/null +++ b/OSINT/Flying Places/README.md @@ -0,0 +1,23 @@ +## Flying Places +The main idea finding the flag is just basic Internet Search. + +#### Step-1: +After I downloaded `Flight.jpg`, I tried basic `strings`, `exiftool`, `binwalk`, but couldn't find any info. + + + +#### Step-2: +After that, I directly searched it on Google Images and got a [Twitter](https://twitter.com/JackMa/status/1239388330405449728) thread, I tried to search for the reporter. + + + +#### Step-3: +I got the destination in the comments. + + + +Voila! I got the flag in comments! + +#### Step-4: +Finally the flag becomes: +`csictf{san_francisco}` \ No newline at end of file diff --git a/OSINT/Flying Places/Tweet.png b/OSINT/Flying Places/Tweet.png new file mode 100644 index 0000000..fc4933f Binary files /dev/null and b/OSINT/Flying Places/Tweet.png differ diff --git a/OSINT/LO SCAMPO/Flag.png b/OSINT/LO SCAMPO/Flag.png new file mode 100644 index 0000000..a58ccca Binary files /dev/null and b/OSINT/LO SCAMPO/Flag.png differ diff --git a/OSINT/LO SCAMPO/Profile.png b/OSINT/LO SCAMPO/Profile.png new file mode 100644 index 0000000..7f0ec52 Binary files /dev/null and b/OSINT/LO SCAMPO/Profile.png differ diff --git a/OSINT/LO SCAMPO/README.md b/OSINT/LO SCAMPO/README.md new file mode 100644 index 0000000..004663e --- /dev/null +++ b/OSINT/LO SCAMPO/README.md @@ -0,0 +1,25 @@ +## LO SCAMPO +The main idea finding the flag is just basic Internet Search. + +#### Step-1: +After I read the content, I searched for `Broiestevane` alias on Instagram. + +` +'Malcolm X took Broiestevane to a Day of the Dead themed party but she never returned. Her only friends, Mr Bean and the Pink Panther realised that she was missing when she didn't show up for an exam. Broiestevane liked posting pictures, where was the party held? +` + +#### Step-2: +I got a profile on [Instagram Profile](https://www.instagram.com/broiestevane/) + + + +#### Step-3: +There I got the link to the post: https://www.instagram.com/p/B3pJE1CgMvI/ + + + +I got the flag there in the location of the post! + +#### Step-4: +Finally the flag becomes: +`csictf{liberty_hotel_boston}` \ No newline at end of file diff --git a/OSINT/Pirates of the Memorial/Instagram.png b/OSINT/Pirates of the Memorial/Instagram.png new file mode 100644 index 0000000..15b0f34 Binary files /dev/null and b/OSINT/Pirates of the Memorial/Instagram.png differ diff --git a/OSINT/Pirates of the Memorial/README.md b/OSINT/Pirates of the Memorial/README.md new file mode 100644 index 0000000..6acd0f5 --- /dev/null +++ b/OSINT/Pirates of the Memorial/README.md @@ -0,0 +1,25 @@ +## Pirates of the Memorial +The main idea finding the flag is just basic Internet Search. + +#### Step-1: +After I downloaded `storm.jpeg`, I tried basic `strings`, `exiftool`, `binwalk`, but couldn't find any info. + + + +#### Step-2: +After that, I directly searched it on Google Images and got a [Twitter](https://twitter.com/rishibagree/status/1016932954143158274) thread, where the original photographer was mentioned subtly. + + + +#### Step-3: +I searched for `Arunopal Banerjee` on Google and searched for top links and in his [Instagram Profile](https://www.instagram.com/arunopal17/), I found our `storm.jpeg`. + +[Post](https://www.instagram.com/p/B3oKrLQgpko/): + + + +Voila! I got the flag in comments! + +#### Step-4: +Finally the flag becomes: +`csictf{m1ch34l_sc0fi3ld_fr0m_pr1s0n_br34k}` diff --git a/OSINT/Pirates of the Memorial/Twitter.png b/OSINT/Pirates of the Memorial/Twitter.png new file mode 100644 index 0000000..cae00b8 Binary files /dev/null and b/OSINT/Pirates of the Memorial/Twitter.png differ diff --git a/OSINT/Pirates of the Memorial/storm.jpeg b/OSINT/Pirates of the Memorial/storm.jpeg new file mode 100644 index 0000000..a27d408 Binary files /dev/null and b/OSINT/Pirates of the Memorial/storm.jpeg differ diff --git a/OSINT/Shaken/README.md b/OSINT/Shaken/README.md new file mode 100644 index 0000000..fd46960 --- /dev/null +++ b/OSINT/Shaken/README.md @@ -0,0 +1,9 @@ +## Shaken +The main idea finding the flag is watching James Bond movies. + +#### Step-1: +I am no fan of 007, so I had no idea of what was the question. I had to look upon the writeup here: https://noob-atbash.github.io/writeups/csictf-20/osint/osint#flyong-places + +#### Step-2: +Finally the flag becomes: +`csictf{gareth_mallory}`