{"id":917,"date":"2010-08-11T10:35:00","date_gmt":"2010-08-11T10:35:00","guid":{"rendered":"https:\/\/www-new.brucon.org\/2018\/2010\/08\/11\/winner-and-solution-of-thehexfactor-sample-challenge\/"},"modified":"2010-08-11T10:35:00","modified_gmt":"2010-08-11T10:35:00","slug":"winner-and-solution-of-thehexfactor-sample-challenge","status":"publish","type":"post","link":"https:\/\/archive.brucon.org\/2023\/2010\/08\/11\/winner-and-solution-of-thehexfactor-sample-challenge\/","title":{"rendered":"Winner and solution of TheHexFactor sample challenge"},"content":{"rendered":"<p>The first person to answer the challenge completely was Philippe Teuwen. Kudos for solving this challenge the day itself. Since he already has a ticket, he receives a Tshirt and prices will go to the runner-up Mark Hillick!<\/p>\n<p>For those who wondered what the correct answer was, here is the solution:<\/p>\n<ul>\n<li><span><span style=\"font-size:100%\">Hidden.rtf is hidden in  vader.gif using steganography with the IDEA encryption protocol. Using  the passphrase &#8220;hexfactor&#8221; the file can be extracted.<\/span><\/span><\/li>\n<li><span><\/span><span><span style=\"font-size:100%\">Hidden.rtf contains the following url :  http:\/\/blog.remes-it.be\/wp-content\/uploads\/2010\/07\/poodleman.jpg<\/span><\/span><\/li>\n<li><span><\/span><span><span style=\"font-size:100%\">Poodleman.jpg metadata contains  UHJpbnNlbmdhbGVyaWosIEJydXNzZWwsIEJlbGdpdW0= <\/span><\/span><\/li>\n<li><span><\/span><span><span style=\"font-size:100%\"> The base64 string contains the following information : Prinsengalerij,  Brussel, Belgium<\/span><\/span><\/li>\n<li><span><span style=\"font-size:100%\">With Google Maps, you can find the location  and retrieve pictures taken nearby.  The famous statue is among them : <a href=\"http:\/\/en.wikipedia.org\/wiki\/Jeanneke_Pis\"> <span style=\"font-weight: bold\">Jeanneke Pis<\/span><\/a><\/span><\/span><\/li>\n<li><span><\/span><span><span style=\"font-size:100%\">With tineye.com, you can find out which  sites also host the poodleman pictures :<\/span><\/span><\/li>\n<\/ul>\n<p style=\"margin: 0pt\"><span><span style=\"font-size:100%\">              <\/span><\/span><span><span style=\"font-size:100%\">               <\/span><\/span><span><span style=\"font-size:100%\">http:\/\/daviddust.blogspot.com\/2009\/11\/happy-couples.html<\/span><\/span><\/p>\n<p style=\"margin: 0pt\"><span><span style=\"font-size:100%\">              <\/span><\/span><span><span style=\"font-size:100%\">               <\/span><\/span><span><span style=\"font-size:100%\">http:\/\/picturewar.wordpress.com\/<\/span><\/span><\/p>\n<p style=\"margin: 0pt\"><span><span style=\"font-size:100%\">              <\/span><\/span><span><span style=\"font-size:100%\">               <\/span><\/span><span><span style=\"font-size:100%\">http:\/\/blog.stuttgarter-zeitung.de\/category\/dumm-gelaufen-dg\/<\/span><\/span><\/p>\n<p style=\"margin: 0pt\"><span><span style=\"font-size:100%\">              <\/span><\/span><span><span style=\"font-size:100%\">               <\/span><\/span><span><span style=\"font-size:100%\">http:\/\/awkwardfamilyphotos.com\/2009\/11\/07\/sns-mans-bff\/<\/span><\/span><\/p>\n<p style=\"margin: 0pt\"><span><span style=\"font-size:100%\">              <\/span><\/span><span><span style=\"font-size:100%\">               <\/span><\/span><span><span style=\"font-size:100%\">http:\/\/profile.myspace.com\/index.cfm?fuseaction=user.viewprofile&amp;friendid=189401<\/span><\/span><\/p>\n<p style=\"margin: 0pt\"><span><span style=\"font-size:100%\">              <\/span><\/span><span><span style=\"font-size:100%\">               <\/span><\/span><span><span style=\"font-size:100%\">http:\/\/www.cutewithchris.com\/formal_cat_portraits\/index.html<\/span><\/span><\/p>\n<p style=\"margin: 0pt\"><span><span style=\"font-size:100%\">              <\/span><\/span><span><span style=\"font-size:100%\">               <\/span><\/span><span><span style=\"font-size:100%\">http:\/\/www.magazine13.com\/awkward-family-photos\/<\/span><\/span><\/p>\n<p style=\"margin: 0pt\"><span><span style=\"font-size:100%\">              <\/span><\/span><span><span style=\"font-size:100%\">               <\/span><\/span><span><span style=\"font-size:100%\">http:\/\/poorlydressed.com\/<\/span><\/span><\/p>\n<p style=\"margin: 0pt\"><span><span style=\"font-size:100%\">              <\/span><\/span><span><span style=\"font-size:100%\">               <\/span><\/span><span><span style=\"font-size:100%\">http:\/\/ffffound.com\/image\/d0153c516c834df263886b518bcc77f827eb4508<\/span><\/span><\/p>\n<p style=\"margin: 0pt\"><span><span style=\"font-size:100%\">              <\/span><\/span><span><span style=\"font-size:100%\">               <\/span><\/span><span><span style=\"font-size:100%\">http:\/\/www.spock.com\/q\/%5EDog-Groomer%5E<\/span><\/span><\/p>\n<p style=\"margin: 0pt\"><span><span style=\"font-size:100%\">              <\/span><\/span><span><span style=\"font-size:100%\">               <\/span><\/span><span><span style=\"font-size:100%\">http:\/\/squat.net\/overtoom301\/pages\/events.html<\/span><\/span><\/p>\n<p style=\"margin: 0pt\"><span><\/span><\/p>\n<p style=\"margin: 0pt\"><span><span style=\"font-size:100%\">For those who want to have more fun and learn new stuff&#8230;. come over to BruCON and play TheHexFactor! The venue will stay open all Friday evening so you can play after the last presentations to your hearts content.<br \/><\/span><\/span><\/p>\n<p style=\"margin: 0pt\"><span><\/span><\/p>\n<p style=\"margin: 0pt\"><span><span style=\"font-size:100%\">Previous posts:<\/span><\/span><\/p>\n<ul>\n<li><a href=\"http:\/\/blog.brucon.org\/2010\/08\/hints-for-hex-factor-sample-challenge.html\" class=\"broken_link\" rel=\"nofollow\">Hints  for  <\/a><a href=\"http:\/\/blog.brucon.org\/2010\/08\/win-prize-hex-factor-sample-challenge.html\" class=\"broken_link\" rel=\"nofollow\">Win  a prize: a Hex Factor sample challenge<\/a><\/li>\n<li> <a href=\"http:\/\/blog.brucon.org\/2010\/08\/win-prize-hex-factor-sample-challenge.html\" class=\"broken_link\" rel=\"nofollow\">Win  a prize: a Hex Factor sample challenge<\/a>\n<div>  <\/div>\n<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The first person to answer the challenge completely was Philippe Teuwen. Kudos for solving this challenge the day itself. Since he already has a ticket, he receives a Tshirt and prices will go to the runner-up Mark Hillick! For those who wondered what the correct answer was, here is the solution: Hidden.rtf is hidden in vader.gif using steganography with the IDEA encryption protocol. Using the passphrase &#8220;hexfactor&#8221; the file can be extracted. Hidden.rtf contains the&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,26],"tags":[],"class_list":{"0":"post-917","1":"post","2":"type-post","3":"status-publish","4":"format-standard","6":"category-hacking-challenge","7":"category-prizes"},"menu_order":0,"_links":{"self":[{"href":"https:\/\/archive.brucon.org\/2023\/wp-json\/wp\/v2\/posts\/917","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/archive.brucon.org\/2023\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/archive.brucon.org\/2023\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/archive.brucon.org\/2023\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/archive.brucon.org\/2023\/wp-json\/wp\/v2\/comments?post=917"}],"version-history":[{"count":0,"href":"https:\/\/archive.brucon.org\/2023\/wp-json\/wp\/v2\/posts\/917\/revisions"}],"wp:attachment":[{"href":"https:\/\/archive.brucon.org\/2023\/wp-json\/wp\/v2\/media?parent=917"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/archive.brucon.org\/2023\/wp-json\/wp\/v2\/categories?post=917"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/archive.brucon.org\/2023\/wp-json\/wp\/v2\/tags?post=917"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}