Challenge : Hidden in Plain Graphic Category : Forensic Scenario : Agent Ali, who are secretly a spy from Malaysia has been communicate with others spy from all around the world using secret technique . Intelligence agencies have been monitoring his activities, but so far, no clear evidence of his communications has surfaced. Can you find any suspicious traffic in this file?

Solution

  1. Open the PCAP file using WireShark
  2. By filtering the packet length . I can see there is only one packet that are so large compare to others ../images/Pasted image 20250308111803.png
  3. Lets try follow the stream by clicking Follow>TCP Stream ../images/Pasted image 20250308111910.png
  4. I see there is a PNG inside . Maybe we should extract it
  5. By Clicking Show as and choose RAW . We can save this file as .PNG
  6. ../images/Pasted image 20250308111543.png
  7. Lets try to run zsteg to see if there any hidden message there

And we got the flag flag : umcs{h1dd3n_1n_png_st3g}