avatar
Cyscom
Cybersecurity Student Community of VIT Chennai
  • CTF EVENTS
  • CATEGORIES
  • TAGS
  • ARCHIVES
  • POSTS
  • ABOUT
Home FinalTrace 2025 The Watcher's Gaze
Writeup
Cancel

The Watcher's Gaze

The Watcher’s Gaze

  • Category: [OSINT]
  • Author: [Akshitha]

Challenge Description

Go through a variety of open source data and find out the observer’s den. Follow lyra’s trail but beware do not get caught. All you need is right infront of your eyes, just know where to look.

Solution

Initial Analysis

Build up a narrative, look at various social media platforms, come up with a cohesive plot that built on the story.

Tools Used

  • Metadat2go
  • Instagram
  • Github
  • Google docs

Step-by-Step Solution

Step 1: The Image

image

The binary numbers are decoys, they dont point to anything important

Things to dedue:

i. Bottom right: Instagram account (hinted by the purple/ blue colour scheme) @LC_HOURGLASS

ii. Extracting meta data

image

We see a hex value (6B011D)

It is a part of the flag, to be noted and kept

Step 2: The Instagram account

image

The bio points to a username (Caellum-Archivist)

image

Upon inspection of the post caption, the last line has weird capitalization

In the word gift notice only capital letters (GIT)

Step 3: The github

image

In the old haven archive

image

90210 points to a famous los angeles pincode

The reset attempts are dummies

Shes-gone-and-its-just-me-repo:-

image

Multiple access_gate decoys so even if we want to get password from code it takes a little bit of time

image

README points to a link

image

Enter the CITY NAME

Code- losangles/la

image

Step 4: The Google Doc

The information is all filler

image

Location coordinates of the picture point to

Griffith Observatory : 34.1184° N, 118.3004° W

Rest of the text is white and revealed when selected

image

Time: 12:47 + 3mins+ 1 sec 12:50:01

Piece together final flag from “VITAL DATA”

Flag

1
CYS{341184_125001_6B011D}

Flag

CYS{341184_125001_6B011D}
Edit on GitHub
Trending Tags
authentication idor sql-injection ssti xss

© 2025 Cyscom. Some rights reserved.

Using the Jekyll theme Chirpy.

A new version of content is available.