PICOCTF 2019 • FORENSICS & REVERSING

PicoCTF

Detailed step-by-step writeups for all 13 forensics challenges from PicoCTF 2019. Every guide includes manual hex/Wireshark steps, Python scripts, and clean cheat sheets.

Forensics 2019

All 13 Solved Challenges

13 Guides
c0rrupt
File Repair250 PTS
PNG Specification & Hex Patching

c0rrupt

Fixing a broken PNG file byte-by-byte in a hex editor. Restoring missing magic headers, repairing IHDR and pHYs chunks, and calculating the exact IDAT length.

HexEd.it / HxDpngcheckPNG SpecPython Bytearray
8 min readRead Guide
What Lies Within
Steganography150 PTS
LSB Bit-Plane Extraction

What Lies Within

Extracting secret text hidden inside the least significant bits of an RGB image using zsteg, Aperi'Solve, and a quick custom Python script.

Aperi'SolvezstegLSB Bit-PlanesPython PIL
5 min readRead Guide
like1000
Automation250 PTS
Russian Doll Nested Archives

like1000

Extracting 1,000 nested TAR archives in seconds using a short Python loop with tarfile and automatic cleanup to get the flag.

Python tarfileTAR ArchivesAutomationGarbage Collection
4 min readRead Guide
Shark on Wire 2
Network Forensics300 PTS
Covert Channels & UDP Port Stego

Shark on Wire 2

Finding secret data smuggled across UDP source port numbers. We filter the packets in Wireshark and decode ASCII characters by subtracting 5000 from each port.

WiresharkUDP Stream TriagePort SteganographyPython struct
7 min readRead Guide
Investigative Reversing 0
Reverse Engineering300 PTS
Trailing Appended Byte Math

Investigative Reversing 0

Decompiling a binary that appends altered characters right after the PNG IEND marker. We pull the trailing bytes in HxD and reverse the arithmetic shifts (+5 / -3).

GhidraPNG IENDFile OverlaysReverse Math
6 min readRead Guide
Investigative Reversing 1
Reverse Engineering350 PTS
Multi-Image Overlay Jigsaw

Investigative Reversing 1

Reversing how a binary splits a 26-character flag across 3 separate PNG images. We carve the bytes past each IEND and put the jigsaw pieces back in place.

GhidraMulti-Image CarvingJigsaw AssemblyPython Solver
8 min readRead Guide
Investigative Reversing 2
Reverse Engineering350 PTS
Bitmap LSB Deconstruction

Investigative Reversing 2

Reversing a custom BMP LSB encoder. Finding offset 2000, reading 8 LSB bits per character, and undoing the binary's +5 shift to recover the flag.

GhidraBitmap LSBHexEd.itShift Inversion
7 min readRead Guide
Investigative Reversing 3
Reverse Engineering400 PTS
9-Byte Stride & Dummy Filler

Investigative Reversing 3

Overcoming interleaved dummy bytes in BMP steganography. We spot the 9-byte stride pattern in Ghidra and write a Python script that ignores the filler byte.

GhidraStride AnalysisDummy SkippingBinary Decompilation
8 min readRead Guide
So Meta
Image Metadata150 PTS
EXIF & PNG Text Chunks

So Meta

Extracting the flag hidden directly inside an image's metadata text chunks using ExifTool, strings, and Python PIL.

ExifToolstringsPNG tEXt ChunksPython PIL
3 min readRead Guide
WhitePages
Whitespace Stego250 PTS
Unicode Invisible Demodulation

WhitePages

Decoding a text file that looks completely blank. We analyze the raw bytes and map Unicode EM spaces and normal spaces into binary 0s and 1s.

Format-HexCyberChefUnicode StegoBinary Demodulation
5 min readRead Guide
Extensions
File Signatures150 PTS
Magic Bytes & Header Triage

Extensions

Inspecting raw magic bytes on a misnamed text file, verifying that it is actually a PNG image, and changing the extension to view the flag.

Magic BytesfileFormat-HexFile Signatures
3 min readRead Guide
m00nwalk
Audio Forensics250 PTS
Apollo 11 SSTV Demodulation

m00nwalk

Decoding an SSTV audio signal from the Apollo 11 moon mission. We play the audio into Robot36 or Python PySSTV to draw the secret image line-by-line.

SSTVScottie 1Audio ForensicsRobot36 / PySSTV
6 min readRead Guide
Shark on Wire 1
Network Forensics150 PTS
UDP Stream Follow & Decoy Triage

Shark on Wire 1

Following UDP conversation streams in Wireshark, avoiding fake decoy flags, and pulling the real flag from Stream 5.

WiresharkUDP Stream FollowDecoy TrappingScapy Reassembly
4 min readRead Guide
Cyber Amber
#f59e0b
PresetsClick to lock