CSAW CTF Qualifications 2026 Hemispheres Writeup
Posted on Sat 19 September 2026 in ctf
This was one of those CTF challenges that wasn't particularly difficult, but I didn't have much time and still wanted to solve something. So, naturally, I picked a forensics challenge that had already been solved by others. The challenge turned out to be a nice little combination of metadata, embedded files and LSB steganography.

1. Inspecting the image

The first thing I usually do with a suspicious image is check its metadata with exiftool the_signal.png:

The comment looked interesting:
Look past IEND for the lock. The key is in the pixels, not the words.
IEND marks the end of a PNG file.
This made me think, that another file was embedded in the_signal.png.
2. Check for embedded files
Next, I wanted to see whether the PNG contained anything beyond the actual image data.
For that, I used binwalk -e the_signal.png

And there it was: the image contained an embedded ZIP archive.
The extracted files were placed in: _the_signal.png.extracted/
So this was the lock. They key is in the pixels, not the words. Due to this hint I thought of least significant bit steganography.
3. Look between the pixels
Since this was a forensics challenge and we already had a PNG containing another file, steganography seemed like a reasonable thing to check.
I ran zsteg against the image:
zsteg --lsb the_signal.png

And one of the results looked particularly interesting: r3ad_b3tw33n_th3_p1x3ls
Something that looked like a password hidden in the least significant bits of the image.
Exactly what we needed.
4. Extract the ZIP
Now we can finally extract the embedded archive:
unzip _the_signal.png.extracted/205E.zip

The archive contained a single file: flag.txt
Which we can print with cat flag.txt:

The flag was: csaw{0n3_f1l3_tw0_truth5_p0lygl0t_m4g1c}