forensicsPromedium
Time Capsule
tamuctf
Task: ext4 disk image with 17 image files, flag hidden somewhere. Solution: timestamps encode ASCII via minutes×60+seconds formula, reading files in order spells the flag.
$ ls tags/ techniques/
ascii_decodingfilesystem_forensicstimestamp_analysisinode_metadata_extraction
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [forensics][Pro]Reincarnation— duckerz
- [forensics][Pro]Скрытый след (Hidden Trail)— hackerlab
- [forensics][Pro]SlackSpace— hackerlab
- [stego][Pro]Kitty— taipanbyte
- [forensics][Pro]🔴👂ing— bluehensctf