DEV Community

Cover image for Overheard at Breakfast: TryHackMe Room Write-up & OSINT Walkthrough
 Mohammad ali
Mohammad ali

Posted on • Edited on

Overheard at Breakfast: TryHackMe Room Write-up & OSINT Walkthrough

Two strangers. One conversation. One profile they never meant to reveal.

Open Source Intelligence (OSINT) is one of the most exciting and dynamic fields in cybersecurity. It demonstrates how seemingly innocuous snippets of information shared online can expose a complete digital profile. In this write-up, we explore the TryHackMe room “Overheard at Breakfast”, breaking down how a casual conversation between two resort guests at “Byte Lotus” leads to uncovering a hidden identity and capturing the flag.

  1. The Scenario & Reconnaissance The room drops us into a simulated chat transcript between two users: Ponzi — Influencer and Lambo!. They are chatting late at night about their stay at the Byte Lotus resort:

Key Conversation Excerpt:

Lambo!: “Absolutely, Byte Lotus is treating me nice, love the food, weather and overall vibes. Will probably come back next year too.”

Lambo! (regarding social media): “Yeah nowadays I don’t really use much social media… Though I’m still out there, I used to use this free tool that let me upload my profile and link other media accounts was neat, until I wiped everything. Started with a G if I remember correctly.”

Contact Email: lambobytelotushotel@gmail.com

From this conversation, we extract critical intelligence:

The target’s handle/name is Lambo.
They used a profile-linking tool starting with “G” where they previously uploaded a profile picture.
Their email address is explicitly provided: lambobytelotushotel@gmail.com.

  1. Connecting the Clues: Gravatar OSINT The clue pointing towards a free tool starting with “G” used for hosting avatars and linking profiles immediately directs our attention to Gravatar (Globally Recognized Avatar), a service tied directly to email addresses using cryptographic hashing.

By checking the target email address on Gravatar (https://gravatar.com/site/check), we uncover the associated profile URL and avatar hash:

Email: lambobytelotushotel@gmail.com
Profile URL: https://gravatar.com/d43faaf69d71056793bd037b8d6e321acad
Avatar Hash: d43faaf69d71056793bd037b8d6e321acad985c222d83775610

Visiting the Gravatar profile reveals a custom avatar and a personalized message left by the room creators:

“Funny thing about email hashes, they follow you places you didn’t expect. Glad you found the right corner of the internet! Here is your prize: VEhNe1MzY3JIVF9QcjBmaWwzX0gf0c19iMzNuX0lkZW50MWZpM2R9"

  1. Decoding the Flag with CyberChef The prize string is encoded in Base64. To decode it, we plug the string into CyberChef, apply the From Base64 recipe, and instantly reveal the plaintext flag:

Input: VEhNe1MzY3JIVF9QcjBmaWwzX0gf0c19iMzNuX0lkZW50MWZpM2R9
Output: THM{.....................................}
Flag Captured: THM{.................................}

Top comments (0)