Challenge Description
A Jordanian traveler named YakoobYousefAlKadeer set out to explore the world, capturing a photo in each continent he visited. Along his journey, he concealed seven secrets each one tied to a location. To unlock these secrets, we must uncover either the town name, the geographic coordinates, or even a full name linked to each spot. Once all seven secrets are found, we’ll need to combine them in the order they were posted. This final combination will allow us to decode and retrieve the original flag, based on this, you must connect to the provided socket and correctly answer questions to retrieve the flag.
Important Note
During the competition, Pastebin
was blocked due to participants accessing it from the same IP, and after multiple attempts, it was restricted. To work around this, I created a Docker environment that players can connect to using the provided nc
command. Once connected, they'll receive the questions posted on the Twitter account. However, before continuing, players must first find the Twitter account themselves to proceed with answering the questions, ... since the full question isn't entirely shown through the nc
command, I will also proceed to answer using both the Pastebin
solution and the one accessed through the nc
command.
Challenge Solution
First we need to check existence of the provided username within social media platforms using this tool https://www.idcrawl.com
Going to the upper twitter link https://x.com/YakoobAlKadeer we can see that there is 7 posts that where presented, same as the number that was presented within the upper post, picture related to different continents and the same username, based on that we need to begin solving the questions, from the first posted post continuing to the upper one, also we will solve the question based on the text and the picture that we have then, the answer that we have got, it will be the password for the link that is provided within each post.
First Post
This is one of the best stadiums I've ever visited in Senegal. I'm so excited to watch the match but I forgot which town I'm in. Can you help me figure that out?
Based on the picture that we have, if we went to google maps and search for the Senegal Stadiums, we can see that there is multi Stadiums, but checking the first one we can see that it have the same edges that where presented within the picture, based on that we can check the Town name Diamniadio
that is presented and based on that we can use it as a password in order to open the link
Using Pastebin
Using nc
nc 127.0.0.1 5467
Connecting...
----|\----------------- **--------------------
----|/-----------------**---****---*****------
---/|-----------------**---**--**----**-------
--/-|_-------------****---******---**---------
-|--|-\------------****---**--**--*****-------
_|__|_|
\_|_/
[x] YakoobYousefAlKadeer traveled the world, hiding seven secrets tied to locations. Uncover towns, coordinates, or names to reveal them and decode the final flag.
(1/7) This is one of the best stadiums ....
Answer: Diamniadio
Correct!
Code: TkNTQ3tUaDNfN19IMWQzM25fQ
TkNTQ3tUaDNfN19IMWQzM25fQ
Diamniadio
https://pastebin.com/Z5NjZ657
first
Second Post
Amman my hometown. What can I say? The food is amazing, Absolutely unforgettable. There's one spot I always love visiting when I'm hungry. But you know what? I need the Plus Code for it so I can keep going back again and again. Can you help me find it?
Based on the upper question, we can see that it is related to a restaurant as the banner have a burger logo, same question mentioned food, and the souses that are presented, also the question have mentioned the location as Amman, so based on that we will search for restaurant that have the 99 keyword as the one that is presented within the upper picture, the Burger keyword and Amman, based on that we can see that the real name is 99Grill
So we will check this Restaurant in Jordan and check place that is related based on the white wall that is presented outside the restaurant within google maps, so they are lower than 10 restaurants, then we will take the plus code WW94+HH Amman
as the password for the link that was provided
Using Pastebin
Using nc
(2/7) Amman my hometown. What can I say? ....
Answer: WW94+HH Amman
Correct!
Code: zBudDFuM250c19BZnIxY0BfYW
zBudDFuM250c19BZnIxY0BfYW
WW94+HH Amman
https://pastebin.com/KAqC10UH
second
Third Post
I visited the land of kangaroos, One location stood out, though I can’t recall its name. My friend wants to see that view too and asked for its exact coordinates. Can you help us find it?
From the upper question we can see that it mentioned kangaroos, as it’s the country of Australia, you can check that, but the main point is the check the exact location, one of the things that stood by, is the cafe name, but we don’t have the full name of that cafe, so we can write the text that we have in Instagram as huge amount restaurants have accounts there, so once we search we can see that there is one that may be related as the logo color is same as the cafe color theme
Another thing to consider is that some places are named based on what they have. For example, if a street is called 60 Street, a café nearby might be named Café 60 Street. Regarding the roundabout in the picture, it may be called roundabout or round.
Once we open that profile and check the location that is presented we can see that it have the same view, we need to check the same exact location, and that can be done, by having the DMC
keyword inside the tree view and then we can take the exact coordinates from the URL and use that as the password to access the link
Using Pastebin
Using nc
(3/7) I visited the land of kangaroos, One location stood out ....
Answer: -33.85598,151.1522212
Correct!
Code: 50QHJjdDFjYV9BczFAX2F1c3R
50QHJjdDFjYV9BczFAX2F1c3R
-33.85598,151.1522212
https://pastebin.com/rH6PLDcH
third
Forth Post
I visited a medical center for a quick checkup and snapped a photo of the area, including nearby shops. I noticed a nice brown car to my right and got curious about the keyword on its back can you check that for me?
If we see the banner on the header of the medical center it is related to La Colonia
we know that based on the question mentioning the medical center keyword and within the same banner we can see that it is long and have 4 sections, searching for La Colonia medical center
in google maps and searching for one that have the green roof we can see that we have founded one
based on that we will use the google street view and check the right car that is brown color and see the text carrera
presented on the back of it, so we will use carrera
as a password and retrieve the flag
Using Pastebin
Using nc
(4/7) I visited a medical center for a quick checkup and snapped ....
Answer: carrera
Correct!
Code: yQGwxQF9FdXIwcDNfTk9ydGhA
yQGwxQF9FdXIwcDNfTk9ydGhA
carrera
https://pastebin.com/ZtSp7vLi
forth
Fifth Post
I went to this place but didn’t have enough battery to charge my phone and take pictures. However, I found a photo online from a copyright-free website. Can you tell me the exact profile where the picture came from? I’d love to find more photos.
This will be an easy question, we will just make a reverse image search and check the origin of that picture within one of the non copy-right websites by going to https://phys.org/news/2020-09-experts-future-ice-loss-sea-level.html#google_vignette and check the exact profile name that it have came from, then using that profile name to retrieve the flag
Using Pastebin
Using nc
(5/7) I went to this place but didn’t have enough battery ....
Answer: Pixabay
Correct!
Code: bTNyMWNAX1NvdXRoQG0zcjFjQ
bTNyMWNAX1NvdXRoQG0zcjFjQ
Pixabay
https://pastebin.com/98m0j15c
fifth
Sixth Post
I went to a café and absolutely loved the vibe the atmosphere was so cool. What I’m looking for now is the country name, but I need help identifying the right café since there are several with the same name. Can you help me figure out which one it was?
We will check cafe that have the TOSTO
keyword in google maps as that was displayed within the upper picture, we can see that we have many cafe with that name as less that 5, so we will check each one of them and based on that select the correct one based on the exact picture and use the answer, the country name as the secret to retrieve the flag
Using Pastebin
Using nc
(6/7) I went to a café and absolutely loved the vibe ....
Answer: Brazil
Correct!
Code: F9IQHYzX2IzM25fZDFzYzB2M3
F9IQHYzX2IzM25fZDFzYzB2M3
Brazil
https://pastebin.com/U3u0YshR
sixth
Seventh Post
In 2012, I toured Europe one of my best trips. Now I'm curious if anything's changed in the spot I visited, shown in the photo. Has something new appeared on the left side of the wall? Can you help identify it?
As we see we have a paint within the wall, we will make reverse search on it, then we will check the provided picture and go to this link https://www.telegraph.co.uk/travel/galleries/Amazing-murals-around-the-world/ and take the location name
Based on that we will check within google maps, search for Stravinsky Square, near the Pompidou Centre
then we need to check the position form where is picture is took, after that we will use street view to check the left side of the wall by walking based on the position the picture is took from and then use the cafe name myCowork
as the answer to retrieve the flag
Using Pastebin
Using nc
(7/7) In 2012, I toured Europe one of my ....
Answer: myCowork
Correct!
Code: JlZF9ZYTNrb29iS2FkZWVyfQ==
All questions completed. Now combine the codes based on the Twitter order to reconstruct the final FLAG, don't forget to decode.
JlZF9ZYTNrb29iS2FkZWVyfQ==
myCowork
https://pastebin.com/nFmDhMTx
seventh
Then we will combine all these values based on the tag that each one have in the pastebin
link and go to CyberChef
https://gchq.github.io to decode it, as the magic feature have detect it is a base64
and based on that we will retrieve the flag
TkNTQ3tUaDNfN19IMWQzM25fQ
zBudDFuM250c19BZnIxY0BfYW
50QHJjdDFjYV9BczFAX2F1c3R
yQGwxQF9FdXIwcDNfTk9ydGhA
bTNyMWNAX1NvdXRoQG0zcjFjQ
F9IQHYzX2IzM25fZDFzYzB2M3
JlZF9ZYTNrb29iS2FkZWVyfQ==
TkNTQ3tUaDNfN19IMWQzM25fQzBudDFuM250c19BZnIxY0BfYW50QHJjdDFjYV9BczFAX2F1c3RyQGwxQF9FdXIwcDNfTk9ydGhAbTNyMWNAX1NvdXRoQG0zcjFjQF9IQHYzX2IzM25fZDFzYzB2M3JlZF9ZYTNrb29iS2FkZWVyfQ==
NCSC{Th3_7_H1d33n_C0nt1n3nts_Afr1c@_ant@rct1ca_As1@_austr@l1@_Eur0p3_NOrth@m3r1c@_South@m3r1c@_H@v3_b33n_d1sc0v3red_Ya3koobKadeer}
Challenge Idea
This challenge involves discovering seven secrets by answering questions shared on social media. Each correct answer acts as a key to unlock a Pastebin
link containing one of the secrets. Once all seven secrets are collected, you’ll combine them to form the final flag. The tags in each post will guide you on how to piece them together, and the final flag will be decoded using Base64.