Anantya ByteMe CTF Writeup Series: Raven's Whisper

 

Welcome Back to the Official Write-Up Series of ByteMe CTF!

The OWASP PCCOE Student Chapter is taking you on a journey across the Narrow Sea for our 8th write-up. This challenge, Raven’s Whisper, is a masterclass in OSINT Reconnaissance, requiring participants to track a digital identity across platforms and bridge the gap between fiction and reality.

Category: OSINT / Recon

Difficulty: Easy–Medium

Author: Arnav Khadke

Theme: Game of Thrones / Real-world Locations


Step 1: The Identity Hunt (Sherlock Holmes of the Realm)

The challenge started with a single lead: a GitHub username, gore-htm975.

Standard social media searches often turn up empty for such specific handles. To solve this, participants were expected to use Sherlock, a powerful command-line tool that hunts for usernames across hundreds of social networks.

The Result: Sherlock confirmed the identity on GitHub. Navigating to the profile, participants found a repository containing a single, mysterious image of a massive fortress.


Step 2: Reverse Image Searching

With the image in hand, the next logical step was a Reverse Image Search (using Google Lens, Yandex, or TinEye).

The search identified the image as a real-world structure: Lovrijenac Fortress.

However, the challenge lore specifically mentioned "The Red Keep."


Step 3: Digging into the "Depth of Commits"

Hint 2 was the key: "The Stronghold name may be the fictional identity... whose location is found depth of commits."

While the current image showed the real-world fort, OSINT experts know that GitHub Commit History often hides previous versions or additional data. By checking the commit logs of the repository, participants found mentions of the "Stronghold" and confirmed its location.

The Correlation:

  • Real-world Fortress: Lovrijenac Fortress

  • City: Dubrovnik, Croatia

  • Fictional Identity: In the Game of Thrones universe, this specific fortress serves as the Red Keep in King's Landing.

Final Answer (Flag)

Combining the fictional stronghold name mentioned in the prompt with the real-world city identified through reconnaissance:

Flag: Byteme{redkeep_dubrovnik}


Key Takeaways

  • Tooling: Automated tools like Sherlock save hours of manual searching when tracking identities.

  • Version Control Forensics: GitHub isn't just a place for code; its history is a chronological record of everything a user tried to hide or change.

  • The OSINT Pivot: Moving from a username $\rightarrow$ a platform $\rightarrow$ an image $\rightarrow$ a real-world location is the core "pivot" skill of a reconnaissance expert.

Comments

Popular posts from this blog

CyberKavach QuestCon Series: Upside-Down Vault

From Open Networks to Safe Systems: How Firewalls Block the Hacker’s Doorway

CyberKavach QuestCon Series: VecNet