MAGNET WEEKLY CTF #3

 

MAGNET WEEKLY CTF #3

This question also refers to an Android image.
 

"exit, pass by, Cargo"

Some sort of route or map may be involved.

Maybe something visual?

 

A search the media folder on the device

turned up some .mp4 videos and .jpegs:


The videos yielded no clues.

But one of the still images revealed part of a highway exit sign:

There wasn't enough of the sign in the still image to read.

However, this .jpg has a filename prefix of MVIMG,
indicating that it is a Motion Photo.

I recalled Jessica Hyde's presentation with Christopher Vance on 10/7/20 where she showed that additional visual information could be extracted from the Motion Photo format, which contains extra frames in the form of an embedded .mp4 movie file.

 

 

Jessica said that she manually extracted the extra frames,
but didn't give any details about the method that she used.

 

Stack overflow had exactly what I needed.

https://stackoverflow.com/questions/53104989/how-to-extract-the-photo-video-component-of-a-mvimg

I used Phil Harvey's exiftool:

https://exiftool.org/

In addition to some python code:
(Thanks, Mitchle)


Even the best shot of the exit sign contained no visible clues.


I think I saw another picture on the drive
that was taken from a moving vehicle.

That shot contained an aircraft glide path antenna array,
so that could mean a nearby airport and CARGO!

 
I used the same extraction technique as above,
but this time I had better luck:
 

Cargo exit! And a highway number. F16?
Could it be E16? It's cut off in the photo.


I can't be sure from the photo, so I'll go back to exiftool
to get the geocoordinates of the image.

 


 The corresponding map of the area shows highway E16.

 

 


 

 

This demonstrates the importance of using more
than one method to validate examination results.


 


Comments

Popular posts from this blog