Skip to main content

Posts

Back on The SEINT's trail - 2023 OSINT Challenge

  Last year, I had a lot of fun working through The SEINT 's 2021 OSINT challenge, which you can read about here . Then, via Sector035 , I heard that The SEINT had published a new challenge, which you can find on this GitHub repo . The challenge simply involves opening a nested series of zipped files, with the password for each zip being an MD5 hash of the answer to the previous level. In order to get us going, The SEINT says that the password for the first zip is the MD5 hash of the word dive . As we are going to be hashing a number of words, it is worth keeping a browser tab open with CyberChef running in it.  SPOILER ALERT! If you want to have a go at solving The SEINT's puzzle yourself, please DON'T read on here, as this is obviously heavily spoilered.  Yes, some images still have Metadata! The first level of the zip file contains four files. One of these is the password-protected zip for the next level, and one is a hint; we will be trying not to use hints. We are the
Recent posts

OSINT: Learning by Doing. A walkthrough of The Seint's OSINT Puzzles - PART 4

This is the final part of my walkthrough of an OSINT CTF set by The Seint in a GitHub repo you can find  here . So far, each subsequent step is nested inside a zip archive that is unlocked by solving the previous step. Each layer is password protected, the password being an MD5 hash of the previous stage's answer. You can fins the beginning of the series here . WARNING: Obviously there are spoilers in this series; they are a walkthrough after all! STEP 6 - It's Over Now... Opening  step6.zip , we find the usual contents... step6.txt step6 - hint.txt step7.zip As before, we'll try getting through this without a hint, and in step6.txt  we have our clue: This is the last step of this trip around the world. The title of this quiz contains a part of the album name, recorded by a band from a Northern-European country. This band recorded a very popular song in 1990. However, this recording was a slightly changed version of the same song recorded back in 1987. In the lyrics, o

OSINT: Learning by Doing. A walkthrough of The Seint's OSINT Puzzles - PART 3

This is a walkthrough of an OSINT CTF set by The Seint in a GitHub repo you can find  here . So far, each subsequent step is nested inside a zip archive that is unlocked by solving the previous step. Each layer is password protected, the password being an MD5 hash of the previous stage's answer. You can see how we solved steps 1 to 3 in these earlier posts: Part 1 , Part 2 . WARNING   Obviously there are spoilers in this series; they are a walkthrough after all! STEP 4 - A Visit to Japan Opening step4.zip , we find two text files and the .zip for the next stage: - step4.txt - step4 - hint.txt - step5.zip As before, we'll try getting through this without a hint. Opening step4.txt , we find our clue: --- There is a housing estate somewhere in Japan with the same name as the first five letters of the resort in Hawaii from the previous task. Next to it, there is a dental clinic. The working hours have changed over the past years. What were the clinic’s afternoon working hours in t

OSINT: Learning by Doing. A walkthrough of The Seint's OSINT Puzzles - PART 2

This is a walkthrough of an OSINT CTF set by The SEINT in a GitHub repo you can find here . Unless there are any surprises later on, each stage is nested inside a zip archive that is unlocked by solving the previous stage ( like a matryoshka doll, hence the cover image ). Each layer is password protected, the password being an MD5 hash of the previous stage's answer. You can see how we solved Step 1 in my previous post .  WARNING: Obviously there are spoilers in this series; they are a walkthrough after all! STEP 2 - The Day The Music Died Opening step2.zip, we find two text files: - step2.txt - step2 - hint.txt Let's see how we get on without the hint, shall we? Opening step2.txt, we find a 'treasure hunt' style of clue: --- The name of the place from the previous task is a name of a song by American singer and songwriter. The lyrics mention something that happened several years before the song was released. In the place the lyrics refer to, there is a little structure

OSINT: Learning by Doing. A walkthrough of The Seint's OSINT Puzzles - PART 1

We all have different learning styles. I'm one of those people who learns best by looking over someone's shoulder while they're doing the thing I want to learn. I don't need to be physically looking over their shoulder; a video or written walkthrough works just as well. This is largely how I learned OSINT, by reading and watching other people do it. Over the years I've become more and more convinced that to be good at OSINT, you need a lot more that a reliance on tools. There is a seemingly infinite collection of OSINT tools on the web, and I have given up many attempts to collect and curate them ( others have done a much better job, see footnotes below ). Many tools work really well and might still be working in month or two when you need them again. On the other hand, with the endless updates to many of our favourite sources of information, especially social media sites, APIs get altered and the tools that rely on them start to to break. You can find a lot of dead