Meta | Blue Team Labs Online -Writeup [English]
— — — — — — — — — — — — — — — — — — — —— — — — — — — — — — — —
Blue Teams Labs Online is the perfect place for established cyber defenders to practice in realistic scenarios and showcase their skills in a gamified and competitive environment. Paired with external training or self-study BTLO can develop your technical capability to investigate and defend against cyber-attacks and intrusions.
Meta
An attached images were posted by a criminal on the run, with the caption “I’m roaming free. You will never catch me.”
And as a Cyber Defender it's your job to find details about the crime. Let's assist the team in proving him wrong.
Exiftool and Reverse Image Search can be used to solve the Lab.
Challenge Submission
1. What is the camera model? (2 points)
We will be using exiftool to extract the Metadata of the image. Extracting the Metadata of an image can be a good starting point for this investigation.
Usage: exiftool image_file
Answer: Canon EOS 550D
2. When was the picture taken? (2 points)
This can be answered from the Metadata that we have extracted from the previous question. We just need to search the original time and date when the picture was taken.
Answer: 2021:11:02 13:20:23
3. What does the comment on the first image says? (3 points)
The comment on the first image can be found in the same metadata which we have extracted for the first question, you just need to scroll down and found the comment section.
Answer: relying on altered metadata to catch me?
4. Where could the criminal be? (3 points)
For the final challenge, we need to do a reverse image search. You can find many reverse images search engines, but I personally prefer Yandex. For the first image I couldn't find a particular place but for the second one I found Kathmandu, the exact location of the criminal.
Answer: Kathmandu
Conclusion:
This is a beginner level challenge for Blue Teamers. It gives you a basic understanding about Steganography. You should google it and find more about Steganography. Personally, I believe it that you can gain more knowledge through self-learning and failures.
Author:
The author is a Cybersecurity student who is also practicing Digital Forensics. He likes and enjoys solving CTFs and Challenges with continuous learning about new things and topics.
The socials are Twitter , LinkedIn
Happy Learning!! Good Luck Defenders!!