STUG-REFERENCE

Proof of flag

ctf{32849dd9d7e7b313c214a7b1d004b776b4af0cedd9730e6ca05ef725a18e38e1}

Summary of the vulnerabilities identified

Use steghide to extract the flag from stug.jpg with password stug.

Proof of solving

My teammates tried a lot of stuff, including brute forcing it with rockyou and a lot of stegano stuff. I tried some “obvious” passwords like “dctf”, “dctf2020” and “stug”. And stug ended up working out.

steghide extract -sf stug.jpg -p stug