728x90

[๋ฌธ์ œ]

https://blueteamlabs.online/home/challenge/meta-b976cec9e2

 

BTLO

 

blueteamlabs.online


[๋ฌธ์ œ ํ’€์ด]

Q1. What it the camera model?

https://hackingstudypad.tistory.com/263

 

[CTFlearn] Exif - ํฌ๋ Œ์‹ / ExifTool

CTFlearn์˜ ์Šค๋ฌผ๋‘๋ฒˆ์งธ ๋ฌธ์ œ ์ด๋ฒˆ๋ฌธ์ œ๋Š” ์–ผ๋งˆ์ „์— CTFlearn ์—์„œ ํ’€์–ด๋ณธ ๋ฌธ์ œ์™€ ๋˜‘๊ฐ™์ด ํ’€ ์ˆ˜ ์žˆ๋‹ค. (https://hackingstudypad.tistory.com/232) ๋งค๋ฒˆ ๋‹ค๋ฅธ ์œ ํ˜•์˜ ๋ฌธ์ œ๋งŒ ์ œ๊ณต๋˜๋Š”์ค„ ์•Œ์•˜๋Š”๋ฐ ๊ผญ ๊ทธ๋ ‡์ง„ ์•Š์€๊ฐ€

hackingstudypad.tistory.com

  • ์ด๋ฒˆ ๋ฌธ์ œ๋Š” ExifTool์„ ์‚ฌ์šฉํ•ด์„œ ๊ฐ ํŒŒ์ผ ์ด๋ฏธ์ง€๋ฅผ ๋ถ„์„ํ•  ๊ฒƒ์ž…๋‹ˆ๋‹ค.
  • ExitTool ์‚ฌ์šฉ๋ฒ•์€ ์œ„ ๋งํฌ๋ฅผ ์ฐธ๊ณ ํ–ˆ์Šต๋‹ˆ๋‹ค.

  • ํด๋” ์•ˆ์— exitftool ๋„๊ตฌ์™€ ๋ฌธ์ œ ํŒŒ์ผ์„ ๊ฐ™์ด ๋„ฃ์–ด๋†“๊ณ  ํด๋”์ด๋ฆ„ ์žˆ๋Š” ๊ณณ์— cmd๋ฅผ ์ž…๋ ฅํ•ด์„œ cmd์ฐฝ์„ ์‹คํ–‰ํ–ˆ์Šต๋‹ˆ๋‹ค.
  • ๊ทธ๋‹ค์Œ, exiftool ํŒŒ์ผ๋ช…์„ ์ž…๋ ฅํ•˜๋ฉด ์ด๋ฏธ์ง€์˜ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ๋ฅผ ์ถ”์ถœํ•ด ์ฃผ๋Š”๋ฐ ๊ทธ ๋ฐ์ดํ„ฐ ์†์— camera model ์ •๋ณด๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

๋‹ต: Canon EOS 550D


Q2. When was the picture taken?

  • ์งˆ๋ฌธ์— ๋‹ต์„ ์ฐพ๊ธฐ ์œ„ํ•ด ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์—์„œ Date/Time Original๊ณผ Create Date ์ •๋ณด๋ฅผ ์ฐพ์•˜๊ณ  ๊ทธ ๊ฒฐ๊ณผ ๋‹ต์„ ์–ป์„ ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

๋‹ต: 2021:11:02 13:20:23


Q3. What does the comment on the fitst image says?

  • ์ด๋ฒˆ์—๋„ ์ฒซ ๋ฒˆ์งธ ์ด๋ฏธ์ง€์˜ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์—์„œ ์ •๋ณด๋ฅผ ์ฐพ๊ธฐ ์œ„ํ•ด Comment ์„น์…˜์„ ์ฐพ์•˜์Šต๋‹ˆ๋‹ค.
  • Comment ์„น์…˜์—์„œ ๋‹ต์„ ๋ฐ”๋กœ ๋ฐœ๊ฒฌํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

๋‹ต: relying on altered metadata to catch me?


Q4. Where could the ciminal be?

  • ์ด ๋ฌธ์ œ๋Š” ๋ฆฌ๋ฒ„์Šค ์ด๋ฏธ์ง€ ๊ฒ€์ƒ‰์„ ํ†ตํ•ด ๋ฒ”์ธ์˜ ์œ„์น˜๋ฅผ ์ฐพ์•„๋‚ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  • ๊ทธ๋ž˜์„œ ๊ตฌ๊ธ€ ์ด๋ฏธ์ง€ ๊ฒ€์ƒ‰ ์—”์ง„์„ ํ†ตํ•ด ์ด๋ฏธ์ง€๋“ค์„ ๋„ฃ์–ด์„œ ์ •๋ณด๋ฅผ ์•Œ์•„๋‚ด๋ ค๊ณ  ํ–ˆ๋Š”๋ฐ ์ฒซ ๋ฒˆ์งธ ์ด๋ฏธ์ง€๋Š” ๋ถ€์ •ํ™•ํ•˜๊ฒŒ ๋‚˜์™€์„œ ๋‘ ๋ฒˆ์งธ ์ด๋ฏธ์ง€๋ฅผ ๋„ฃ์—ˆ๋”๋‹ˆ ๋„์‹œ๊ฐ€ ์นดํŠธ๋งŒ๋‘์ž„์„ ์•Œ์•„๋ƒˆ์Šต๋‹ˆ๋‹ค.

๋‹ต: Kathmandu

'๋ณด์•ˆ > CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[์›นํ•ดํ‚น] | [LOS] Cobolt write up  (0) 2024.12.01
[Tryhackme] OhSINT  (0) 2024.11.24
[ํฌ๋ Œ์‹] | [BTLO] Browser Forensics - Cryptominer  (0) 2024.11.24
[ํฌ๋ Œ์‹] OlympicDestroyer - Volatility Contest 2018  (1) 2024.11.19
[ํฌ๋ Œ์‹] cridex  (0) 2024.11.18

+ Recent posts