picoCTF: Hidden in Metadata
Forensics | Easy
So I opened this PDF expecting to find ****something in the actual content. Nope. The text's literally like "don't bother, this is just nonsense" — which, in CTF language, basically means "the flag's definitely NOT here."
Classic bait. Flag was somewhere else the whole time.
What I Did
Opened exiftools.com, dragged the PDF in, and scrolled through all the metadata fields. Nothing sus until I hit the Author field. It just had this wall of gibberish:
cGljb0NURntwdXp6bDNkX20zdGFkYXRhX2YwdW5kIV8zNTc4NzM5YX0=
Not a name. Obviously encoded.
Looked at it for a second — random letters, numbers, ends in =. That's the Base64 fingerprint. Copied it, pasted it into base64decode.org, hit decode, and boom:
picoCTF{puzzl3d_m3tadata_f0und!_3578739a}
Flag. Done.
The Trick
If you see gibberish that ends in =, it's almost always Base64. It's not encrypted or anything — just encoded. Anyone can decode it in like 2 seconds.
The tells:
Only letters, numbers, and +/=
Ends in = (the giveaway)
Looks like someone mashed the keyboard
Once you spot it, you're halfway there.
Tools
exiftools.com — no install, just drag and drop your file
base64decode.org — paste, click decode, flag appears
Both free, both one-click. Perfect for quick CTF work.
Flag: picoCTF{puzzl3d_m3tadata_f0und!_3578739a}
GitHub: krovix-1902
LinkedIn: rohan-khatri18
For further actions, you may consider blocking this person and/or reporting abuse
Top comments (0)