๐Ÿณ๏ธ
Bag of Flags
  • Home
  • 2023
    • ๐Ÿ…ฟ๏ธpicoCTF 2023
      • money-ware
      • repetitions
      • two-sum
      • ReadMyCert
      • rotation
      • hideme
      • PcapPoisoning
      • who is it
      • Reverse
      • timer
      • Safe Opener 2
      • findme
      • MatchTheRegex
      • SOAP
    • ๐ŸฆmagpieCTF 2023
      • Space Plan
      • Space Exploration
      • So Meta
      • There is no flag
      • Momma says to play fair
      • Rubis
      • What is the password?
      • Eavesdropper
      • Shredded
      • Missing Flag
      • This outta be large enough right?
      • No Password Here
      • Chocolate Chips with Zero-G
      • Education Comes First
    • ๐ŸŒดISSessions CTF 2023
      • Basic Permissions
      • Crack Me
      • File Detective
      • Word Vomit
      • Fileception
      • Coding Time
      • Ghost File
      • CryptoTools1
      • CryptoTools2
      • 1337
      • ROT++
      • RunedMyDay
      • RSA_2
      • The Man Who Sold the World
      • VaultChallenge
      • Lost Media
      • Decontamination
      • Decade Capsule
      • Password in A Haystack
  • 2022
    • ๐ŸUW CTF S22
      • 0s and 1s
      • simple image
      • Helikopter
      • Meow
      • Google Form
      • Strings, literally
      • WASM
      • Audio
      • Pwn0
      • YATD
      • steg
      • Passwords
      • Vitalik
  • Practice
    • ๐Ÿง CryptoHack
      • Introduction
        • Finding Flags
        • Great Snakes
      • General
        • ASCII
        • Hex
        • Base64
        • Bytes and Big Integers
        • XOR Starter
        • XOR Properties
        • Favourite byte
        • You either know, XOR you don't
        • Greatest Common Divisor
Powered by GitBook
On this page
  • Description
  • Stegosaurus Rex
  • Flag
  1. 2022
  2. UW CTF S22

steg

PreviousYATDNextPasswords

Last updated 2 years ago

Description

Yes, it's been there on the homepage all this time.

Stegosaurus Rex

From the title "steg" I automatically think of steganography

Steganography - Method of hiding information within seemingly ordinary mediums, such as images, to avoid detection

We go to the website and play around, inspecting elements for potential hidden flags. Eventually, something catches my eye:

This houses all the code for the UW CTF website. We can see a very telling commit name

"Chall"? "Background"? Oho!

Checking out the commit, we can see an image file change

I would use Photoshop if I had it. Unfortunately, the only image software I know how to use is MS Paint. Instead, let's try some online websites

One of the images produced shows the flag, albeit very hard to read

Flag

uwctf{stegfrthistime_9b0a89e16a81af67}

There must be something very peculiar about the new image

๐Ÿ
๐Ÿค”
https://ctf.uwaterloo.ca/
UW CTF Club ยท GitLabGitLab
Their GitLab is linked
๐Ÿ‘€
Aperi'Solve
Logo
Logo