HackTheBox: Forest
This is an easy stego challenge from HackTheBox. It is very straight forward.
Download and extract the image of the forest from the zip file forest.zip.
The image is 2.8 MB so there’s definitely something hiding inside it.
Using my favorite tool stegoveritas, which automates a lot of stuff for you.
stegoveritas forest.jpg
Stegoveritas not only looks for hidden files, and gets exif data but it also applies different filters to the image to reveal hidden text.
We find:
We use IsJuS1Af0r3sTbR0
as the password for steghide:
crazyeights@es-base:~/Downloads$ steghide extract -sf forest.jpg
Enter passphrase:
wrote extracted data to "nothinghere.txt".
crazyeights@es-base:~/Downloads$
We get the text file nothing here containing some encoded text.
Use cyberchef with ROT13 to decode it.
FIN. 🥳