stegomedium

Careful with Trust

hackerlab

Task: a cropped PNG screenshot contains hidden data after the IEND chunk due to Windows Snipping Tool not truncating the file (aCropalypse / CVE-2023-28303). Solution: extract trailing IDAT chunks, recover the deflate stream at the correct bit offset, and reconstruct the original full-screen image to reveal a bank card with the flag.

$ ls tags/ techniques/
acropalypse_exploitationpng_chunk_analysisdeflate_stream_recoverytrailing_data_extraction

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub to get started.

$ssh [email protected]