Forensics CTF Challenge Writeup
Challenge Information
- Name: USBChall
- Points: 1
- Category: Forensics
Solution
I started by running the file command on the given mysterious file.
It identified the file as a Linux file system.
I used foremost to extract the files from the system.
- Only two files were extracted: a docx file and an image.
The contents of both the docx and the image seemed empty and provided no useful information.
I then used exiftool on the image, and this revealed the flag.
Flag
FSIIECTF{XXXXXXXXXX}