GandalfTheWise - ctflearn.com
2025-03-04
Author: Aaron 'theHastyOne' Hasty
Download the file. In the exif data find a clue/false flag comment field.
Q1RGbGVhcm57eG9yX2lzX3lvdXJfZnJpZW5kfQo=
from base64 is CTFlearn{xor_is_your_friend}
Looking into strings you will find
+Q1RGbGVhcm57eG9yX2lzX3lvdXJfZnJpZW5kfQo= +xD6kfO2UrE5SnLQ6WgESK4kvD/Y/rDJPXNU45k/p +h2riEIj13iAp29VUPmB+TadtZppdw3AuO7JRiDyU
Convert the two strings following the base64 hint from base64 and into hex this will yeild
c4 3e a4 7c ed 94 ac 4e 52 9c b4 3a 5a 01 12 2b 89 2f 0f f6 3f ac 32 4f 5c d5 38 e6 4f e9
and
87 6a e2 10 88 f5 de 20 29 db d5 54 3e 60 7e 4d a7 6d 66 9a 5d c3 70 2e 3b b2 51 88 3c 94
xor these two hex values and convert to string.
CTFlearn{Gandalf.BilboBaggins}