# osint

## Challenges

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2FEIfhJKwLFc7gH4iRjOFP%2Fimage.png?alt=media&#x26;token=42a58413-e2a2-4701-a55f-df567c107bc2" alt=""><figcaption></figcaption></figure>

### The Insider 1

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2FieFm7xCpbUNzL0ks4HbO%2Fimage.png?alt=media&#x26;token=b82df561-1197-4f00-8641-f1686aa80bfa" alt=""><figcaption></figcaption></figure>

> Someone from our support team has leaked some confidential information. Can you find out who?

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2FHcr1rroWrCTkOPDQpiz3%2Fimage.png?alt=media&#x26;token=1321c5b8-b121-43ac-ae88-0790db2d7b4b" alt=""><figcaption></figcaption></figure>

### The Insider 2

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2F7u1KqKSPt8flNYrAAjWJ%2Fimage.png?alt=media&#x26;token=81af5eb5-7a69-4a39-a390-0f1ed768f451" alt=""><figcaption></figcaption></figure>

> You found out the insider, but can you find what they leaked on GitHub and put it to use? Continue where you left off...

* Scroll down from his bio

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2FCF8Jh0BTdQkN82TyGWpR%2Fimage.png?alt=media&#x26;token=7e3df39c-43e7-4569-b9b3-5506aa845921" alt=""><figcaption></figcaption></figure>

* github/search reveal something interesting 🐧
* <https://github.com/NoobMaster9999/scriptsorcerers-creds>

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2FVWHhLfaq0zOxO2ZyHTnA%2Fimage.png?alt=media&#x26;token=d1e8bbcd-7230-4521-bf73-07667558318c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2F7BeasTuvLsbnnVL1vh9c%2Fimage.png?alt=media&#x26;token=0f8b07f0-c262-445b-96bf-3dbb10ce2b40" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2Fmwhajd1ZX35yfvAKmFTP%2Fimage.png?alt=media&#x26;token=58472fd4-aff6-46f1-b174-985ca3791e09" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2FGMTqLolx7Ex1yB89R4Uu%2Fimage.png?alt=media&#x26;token=a2e1ab02-675a-428c-9909-dcc11dcd9f3f" alt=""><figcaption></figcaption></figure>

* <mark style="color:blue;">`scriptCTF{scriptCTF_2026_leaked?!!}`</mark>

### The Insider 3

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2FJNKa3lx7Z4E5tAvWJmqx%2Fimage.png?alt=media&#x26;token=ccfd2ac4-e1d2-465b-b695-05fd902e7e61" alt=""><figcaption></figcaption></figure>

> It's a tradition at this point. Continue where you left off...

* Do another github search, click the repositories and see the repo.

{% embed url="<https://github.com/scriptCTF/scriptCTF26>" %}

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2Fmi9805T1HeLttooObCKR%2Fimage.png?alt=media&#x26;token=32a515e4-5aeb-481a-90ba-e1c874bdc99f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2Fi96UIc89ZSBnTqbgGAjb%2Fimage.png?alt=media&#x26;token=d2091e28-b5cf-4fb9-a972-7fceb9df4095" alt=""><figcaption></figcaption></figure>

* <mark style="color:blue;">`scriptCTF{2026_fl4g_f0und_1n_2025}`</mark>

### The Insider 4

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2FI0pqaByFlqwgXAmmkxh7%2Fimage.png?alt=media&#x26;token=3a22880c-12a4-406e-841d-21659ed77806" alt=""><figcaption></figcaption></figure>

> Good luck! Note: max flag limit is 6 for a reason, you should be able to get it in less than that. If not, open a ticket. Flag is case insensitive
>
> * **Flag Format:** scriptCTF{HOTEL\_ADDRESS\_ROOMNUMBER}

* The embargo has been lifted, lets go...💨💨🏃‍♂️‍➡️

{% hint style="info" %}
This is again, an **upsolve** due to I couldn't find the room number in time, and I was going crazy over a different challenge (modulo) so when I woke up from my slumber, the ctf is already ended 😭, so lets go...
{% endhint %}

{% embed url="<https://github.com/scriptCTF/scriptCTF26/tree/main/OSINT/.insider-4>" %}

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2FW8KTEDCq6ySlj9XraqVv%2Fimage.png?alt=media&#x26;token=1a8d30d0-98fb-4856-b2ca-3f9ccd6ec436" alt=""><figcaption></figcaption></figure>

* The same repo from insider 3 also have all the challenge files

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2F1VQOS68DSAGfmYafbwpc%2Ffireworks.jpg?alt=media&#x26;token=a5000314-6daf-41b0-9253-9693b9267093" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2FB6EsIit7fKQG959VYVby%2Froom.jpg?alt=media&#x26;token=021b0181-078a-4245-9384-8ac217623910" alt=""><figcaption></figcaption></figure>

* First...from the image, we simply exiftool to extract the comment that the

```
❯ exiftool fireworks.jpg
ExifTool Version Number         : 12.76
File Name                       : fireworks.jpg
...
Comment                         : Great fireworks! Thanks to the Wendell family for organizing these!
Image Width                     : 4032
Image Height                    : 3024
...
```

* Straight up — paste that comment into **google**.
* Immediately spotted the location, we can narrow the location of the hotel now. It is in Rockport, Texas.

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2F2FJ0fbc6Lb8bSejRK8fy%2Fimage.png?alt=media&#x26;token=4274ca11-48cd-4551-9fd1-edee8d950516" alt=""><figcaption></figcaption></figure>

* Another links also verified our search about the location of the challenge

{% embed url="<https://wendellfamilyfireworks.com/places-to-eat-stay-watch/>" %}

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2FfG5kmtVeNMEeihdf5GoN%2Fimage.png?alt=media&#x26;token=2c6885ef-944a-403f-b053-a171e85b5a30" alt=""><figcaption></figcaption></figure>

From that, you can use the image the challenge gave and start cross-comparing the hotels in the area **THAT CONNECTED WITH WENDELL FAMILY** that have water in between and buildings across the water. After about 30 minutes of searching and agonizing on Google Maps (which was a decent amount of time), I came across this hotel: Days Inn by Wyndham Rockport, Texas

* Andddddddddddd..... that right there, my friend, is the exact location of the hotel.
* So the hotel address is **901 Hwy 35 N, Rockport, TX 78382**. We just need to find the room number
* [Links](https://www.google.com/maps/place/Days+Inn+by+Wyndham+Rockport+Texas/@28.0315856,-97.0462669,3a,75y,269.11h,93.85t/data=!3m7!1e1!3m5!1scf74P7wpw6ffASoGftMhew!2e0!6shttps:%2F%2Fstreetviewpixels-pa.googleapis.com%2Fv1%2Fthumbnail%3Fcb_client%3Dmaps_sv.tactile%26w%3D900%26h%3D600%26pitch%3D-3.849553887290483%26panoid%3Dcf74P7wpw6ffASoGftMhew%26yaw%3D269.1111555504093!7i16384!8i8192!4m20!1m10!3m9!1s0x8669b5c70ac08861:0xe9952a48ec5111dc!2sDays+Inn+by+Wyndham+Rockport+Texas!5m2!4m1!1i2!8m2!3d28.0313443!4d-97.0466495!16s%2Fg%2F11h464lg04!3m8!1s0x8669b5c70ac08861:0xe9952a48ec5111dc!5m2!4m1!1i2!8m2!3d28.0313443!4d-97.0466495!16s%2Fg%2F11h464lg04?entry=ttu\&g_ep=EgoyMDI1MDgxOS4wIKXMDSoASAFQAw%3D%3D)

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2FljkJSzSzyUw0ym5LAn9J%2Fimage.png?alt=media&#x26;token=63c11ff8-fa7e-4a35-ae96-49716363c370" alt=""><figcaption></figcaption></figure>

I think the smart move is that you can simply check the images of the hotel from Google Maps....We have to make some assumptions here: first, that the room is on the ground floor (based on evidence from the challenge images), and second, that the hotel follows a standard American numbering convention. To verify our ground floor hypothesis, I decided to methodically scroll through every available image on Google Maps - down and down and down - to finally see the complete range of room numbers.

So my first clue is that they have a 3-digit numbering system for the room numbers, as depicted in the screenshot. Given that our target room is on the ground floor our guess can be 1XX

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2FMO1DmCunFa5IKFBYUYtO%2Fimage.png?alt=media&#x26;token=4ce75b05-fd41-49b8-a3a1-94e961a7f8c1" alt=""><figcaption></figcaption></figure>

Now let's check what we have so far for the flag construction. From the description.

* Flag format is `scriptCTF{HOTEL_ADDRESS_ROOMNUMBER}`.
* Example: `scriptCTF{1337_elite_Hwy_S_9999}` Have fun!"

Put them side by side we have

* `scriptCTF{HOTEL_ADDRESS_ROOMNUMBER}`
* `scriptCTF{`<mark style="color:blue;">**`901_Hwy_35_N`**</mark>`_???}`

<figure><img src="https://2268275695-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUrHD5lu5pQjrB9B8IR6W%2Fuploads%2Fw9IZElLVsIgebs45HGzx%2Fimage.png?alt=media&#x26;token=d2c95b33-88cd-4e34-b045-413f3cd9a982" alt=""><figcaption></figcaption></figure>

Scrolling even more through the photos, and voilà, the range is from 1-20 (they can't have that many rooms, can they???? 💀). We have to make some educated guesses here, but let's approach this systematically rather than randomly. If the hint said we shouldn't need more than 6 (later updated to 7) guesses?

Then from the image...our range is **`106 +- 6`** The answer ultimately is **111**. But I would really want to see the intended solution of how we can ACCURATELY PINPOINT it is 111 without tanking our accuracy by guessing. I guess we can do some geography reflection? Like comparing where the picture was taken compare to the room and count it.

* <mark style="color:blue;">**`scriptCTF{901_Hwy_35_N_111}`**</mark>
