OhSINT
Feb 7, 2023
Hello friend. In this writeup, we will uncover the power of OSINT
(Open-Source Intelligence) by solving the OhSINT
challenge.
We are only given an old Windows XP wallpaper. But there is more to the story.
Images contain metadata, the story behind the data. They can give us some juicy information.
To uncover them we will be using ExifTool
.
We can see there is a copyright from OWoodflint
. By googling the username, we find his Twitter, GitHub, and blog.
Social Media Twitter: https://twitter.com/OWoodflint Blog: https://oliverwoodflint.wordpress.com/author/owoodflint/ Github: https://github.com/OWoodfl1nt/people_finder
Looking at his tweet we can see that he is kind enough to share his BSSID (Router ID). We can now answer the first question since we clearly see his avatar is a cat.
From my house I can get free wifi ;D Bssid: B4:5D:50:AA:86:41 - Go nuts!
There is no better way to thank him than to track him down ;) To do that we will be using WiGLE. After you register your account head over to View
-> Advanced Search
.
We obtain the SSID
. The next question asks us for the personal email of the user. Twitter does not give out the email in the profile. But since he has a GitHub account maybe he included contact details for one of his repositories.
Great! Now we need to know where OWoodflint's gone on holiday. People love to brag about it in their blogs and this guy has one.
Now we need his password. Perhaps he stored it in the blog's source. Do not dare to say this is stupid. The guy posted his BSSID
on Twitter :P. Let's press Ctrl + A
to highlight everything inside the page's body.
And here it is! Congrats, you can now call yourself an "osinter" :D
Last updated