CSAW CTF Qualifications 2026 Hemispheres Writeup

Posted on Sat 19 September 2026 in ctf

This was one of those CTF challenges that wasn't particularly difficult, but I didn't have much time and still wanted to solve something. So, naturally, I picked a forensics challenge that had already been solved by others. The challenge turned out to be a nice little combination of metadata, embedded files and LSB steganography.

challenge description

1. Inspecting the image

the challenge file

The first thing I usually do with a suspicious image is check its metadata with exiftool the_signal.png:

exiftool output

The comment looked interesting:

Look past IEND for the lock. The key is in the pixels, not the words.

IEND marks the end of a PNG file. This made me think, that another file was embedded in the_signal.png.

2. Check for embedded files

Next, I wanted to see whether the PNG contained anything beyond the actual image data.

For that, I used binwalk -e the_signal.png

binwalk

And there it was: the image contained an embedded ZIP archive.

The extracted files were placed in: _the_signal.png.extracted/

So this was the lock. They key is in the pixels, not the words. Due to this hint I thought of least significant bit steganography.

3. Look between the pixels

Since this was a forensics challenge and we already had a PNG containing another file, steganography seemed like a reasonable thing to check.

I ran zsteg against the image:

zsteg --lsb the_signal.png

binwalk

And one of the results looked particularly interesting: r3ad_b3tw33n_th3_p1x3ls Something that looked like a password hidden in the least significant bits of the image. Exactly what we needed.

4. Extract the ZIP

Now we can finally extract the embedded archive:

unzip _the_signal.png.extracted/205E.zip

unzip

The archive contained a single file: flag.txt Which we can print with cat flag.txt:

flag

The flag was: csaw{0n3_f1l3_tw0_truth5_p0lygl0t_m4g1c}