# WRITEUP HACKTODAY 2023 [IPB] by aodreamer ## Doodled [Forensic] Desc: Oh no! My cousin Gio Ferdiansyah has scribbled all over my stuff! Almost everything is covered with his doodles, including an important QR code, making it unreadable. Can you help me retrieve the lost information? Attach: ![](https://hackmd.io/_uploads/B1Mf2QuT2.jpg) There is a QRCode that has been covered so it cannot be easily scanned. After doing literacy, a QRCode can be reconstruct with the tool [QRazyBox](https://merri.cx/qrazybox/). But before that we need to add a finder on the top left side to be like this. ![](https://hackmd.io/_uploads/B1qBkEupn.png) Once the finder has been entered, it is possible to reconstruct the QRazyBox and use the observations to fill in the blanks of the covered QRCode. ![](https://hackmd.io/_uploads/BkRyeVdpn.png) After doing various trials, you get the flag from the following QRCode ![](https://hackmd.io/_uploads/SJFdeE_62.png) ``` Flag: hacktoday{g00d_70b_QR_c0d3_r3p41R_5uCC3s5fuL!} ``` ## Kuala Lumpur (OSINT) Desc: Beberapa tahun yang lalu, aku pergi ke Kuala Lumpur. Suatu sore di sana, aku naik LRT satu kali dari KL Sentral untuk menuju ke sebuah kawasan di KL. Sekeluarnya aku dari stasiun tujuanku, aku dapat melihat menara kembar Petronas dengan jelas, karena memang letak kawasan ini dekat dengan KLCC. Namun setelah itu, aku berbalik arah menuju utara dan menemukan semacam pasar malam yang menjual berbagai street food khas Malaysia. Aku melanjutkan perjalananku ke arah barat dan utara dan akhirnya sampai di suatu Masjid Jamek. - Ketika berada di masjid, aku memotret sebuah gambar yang merupakan menara utama masjid. Saat itu merupakan waktu menjelang matahari terbenam dan rupanya, aku juga memotret sebuah benda langit yang berupa sebuah titik putih dan letaknya ada di samping menara. Oh iya, satu hal yang kuingat, ketiga tempat yang kusebutkan di atas (stasiun, pasar malam, dan masjid jamek), semuanya memiliki nama yang sama dengan nama kawasan tersebut. Attach: ![1485514151327.jpg](https://hackmd.io/_uploads/BkcRbVOp3.jpg) 1485514151327.jpg Instructions: 1. Apa nama kawasan yang dimaksud pada soal? (format: NamaKawasan) 2. Kapan foto tersebut diambil? (format: YYYYMMDD) 3. Apa nama benda langit yang terdapat pada foto? 4. Pada tanggal di mana foto diambil, benda langit tersebut berada pada rasi bintang apa? (format: nama standar dalam bahasa latin) Masukkan jawaban ke dalam flag dengan format hacktoday{Answer1_Answer2_Answer3_Answer4} contoh flag: hacktoday{BukitBintang_20230923_Jupiter_Aquarius} First, we first search on Google Maps about the Jamek Mosque in Kuala Lumpur. Found the following location ![](https://hackmd.io/_uploads/H1yczEOTn.png) Answer1: KampungBaru After that we are asked to find when the photo was taken, we can find this by using the image file name which is a Unix Timestamp (src: ChatGPT). By using the following script, we can find out when the photo was taken ```python from datetime import datetime timestamp = 1485514151327 / 1000 # Mengubah miliseconds menjadi seconds formatted_time = datetime.utcfromtimestamp(timestamp).strftime('%Y-%m-%d %H:%M:%S') print(f"Timestamp: {timestamp}") print(f"Formatted Time: {formatted_time}") ``` Then we got answer2: 20170127 After that asked to look for celestial body in the photo. The method is quite easy by using the [Stellarium](https://stelrium-web.org/) web then adjusting the date and place. ![](https://hackmd.io/_uploads/B1t7EN_a2.png) The brightest visible celestial body is Venus and it is close to the star cluster Pisces Answer3: Venus Answer4: Pisces ``` Flag: hacktoday{KampungBaru_20170127_Venus_Pisces} ``` ## MUA (OSINT) Desc: Aku akhir-akhir ini sangat suka sekali make up >< aku juga menyukai salah satu make up artist asal korea. AH!! aku lupa namanya, tapi dia adalah orang yang ada di gambar ini. Aku sangat menyukai make up hasilnya. Selain jago make up dia juga jago menggambar. Aku meninggalkan komentar beberapa hari yang lalu untuk menyemangatinya di salah satu video di channel youtubenya. Video itu berisi vlog dia sedang menggambar. Attach: ![](https://hackmd.io/_uploads/HyaxHV_T3.png) The first step taken was to do a google lens but it didn't work. Finally looking for a way by reading articles about Youtuber Korean artists who like make up ![](https://hackmd.io/_uploads/rkK6HVup3.png) This PONY name is quite interesting and it turns out that the face is the same as the attachment. Now all that's left is to find the YouTube account and get the channel [PONY Syndrome](https://www.youtube.com/@PONYMakeup) The latest drawing videos and the latest comments are found ![](https://hackmd.io/_uploads/S1T5INO62.png) NB2HI4DTHIXS62LOON2GCZ3SMFWS4Y3PNUXWWYTCNE2TQP3VORWV643POVZGGZJ5OFZCM2LHONUGSZB5JV5E43COI5HGWWSXKE2E2ZZFGNCCKM2E We try to analyze the code with [CyberChef](https://gchq.github.io/CyberChef) using recipe Magic ![](https://hackmd.io/_uploads/S1LEPVup3.png) Direct to [Instagram](https://www.instagram.com/kbbi58/?utm_source=qr&igshid=MzNlNGNkZWQ4Mg%3D%3D) ![](https://hackmd.io/_uploads/HyBFDVdan.png) In each image there is a caption that we must sort in order to get the flag > h8q48nc9ZcQuqUKXGXWqwz > BQDMztdoPzy7frPxfnGSBa > 4q5XuSBsg5UL4rudvSFUW8 Correct order: > 4q5XuSBsg5UL4rudvSFUW8BQDMztdoPzy7frPxfnGSBah8q48nc9ZcQuqUKXGXWqwz ![](https://hackmd.io/_uploads/ryiTdEu62.png) ``` Flag: hacktoday{S0_y0u_f0uNd_m3_on_1nst46r4M_hwehwe11} ```