DEV Community

CTFDojo
CTFDojo

Posted on Originally published at ctfdojo.com

PicoCTF First Grep Writeup — Find a Flag with grep

A large text file containing a huge amount of noise lines is provided. The grep command lets us search directly for the pattern picoCTF{ across all this content in a single command, without having to read the file manually.

  • Platform: picoGym
  • Category: General Skills / Misc
  • Points: 50 pts
  • Difficulty: Beginner
  • Technique: Text search with grep

Challenge description

The challenge provides an archive containing a large text file, file.txt, with several thousand lines of randomly generated content. The challenge's name — "First Grep" — clearly hints at the tool expected to solve it.

Step 1 — Observe the problem

We download and open the file in a text editor to get a sense of it:

$ wc -l file.txt
118421 file.txt
Enter fullscreen mode Exit fullscreen mode

Over 118,000 lines. Scanning it manually, line by line, to spot a specific string is simply impractical. We need a search tool.

Step 2 — Use grep

The grep command (Global Regular Expression Print) searches for a pattern in a text file and only displays the lines that contain it. We search directly for the characteristic prefix of all picoCTF flags:

$ grep "picoCTF{" file.txt
Enter fullscreen mode Exit fullscreen mode

The command returns almost instantly the one relevant line out of the 118,000:

a8f3k2j9x... picoCTF{***************************} ...m3n5p8q1
Enter fullscreen mode Exit fullscreen mode

Step 3 — The case of a whole folder

If the provided archive contains several files spread across subfolders rather than a single large file, the -r (recursive) option lets us apply the same search to the entire tree:

$ grep -r "picoCTF{" .
./data/part_042/chunk_17.txt:...picoCTF{***************************}...
Enter fullscreen mode Exit fullscreen mode

This option is extremely useful outside of CTFs too — for example to quickly find a string across an entire codebase or a folder of logs.

Useful variants

A few grep options that come up constantly:

  • grep -o "picoCTF{.*}" — only prints the matching pattern (the part matched by the regular expression), not the whole line. Handy when the line has a lot of noise around the flag
  • grep -i — ignores case (upper/lowercase), useful when unsure of the exact format
  • grep -n — prints the matching line number, handy for finding the context back in the original file
$ grep -o "picoCTF{[^}]*}" file.txt
picoCTF{***************************}
Enter fullscreen mode Exit fullscreen mode

🚩 picoCTF{ flag intentionally hidden }

The flag is deliberately hidden — follow the method, you've earned it. 💪

Key takeaways

grep is probably the most used tool day-to-day in CTFs as well as system administration. Knowing how to search for a precise pattern in a large volume of text — logs, memory dumps, source code, network captures — is a non-negotiable base skill.

  • grep "pattern" file remains the fastest command to find a needle in a haystack of text
  • grep -r extends the search to entire folders, very useful when facing large archives
  • grep -o and regular expressions let you extract exactly what you're looking for rather than the whole line

Originally published on CTFdojo — join the CTFdojo Discord to discuss writeups and get notified about new ones.

Top comments (0)