[{"content":"","date":"26 July 2025","externalUrl":null,"permalink":"/","section":"Aaarghhh's Blog","summary":"","title":"Aaarghhh's Blog","type":"page"},{"content":"","date":"26 July 2025","externalUrl":null,"permalink":"/tags/blockachain/","section":"Tags","summary":"","title":"Blockachain","type":"tags"},{"content":"","date":"26 July 2025","externalUrl":null,"permalink":"/categories/","section":"Categories","summary":"","title":"Categories","type":"categories"},{"content":"","date":"26 July 2025","externalUrl":null,"permalink":"/categories/ctf/","section":"Categories","summary":"","title":"CTF","type":"categories"},{"content":"","date":"26 July 2025","externalUrl":null,"permalink":"/tags/ctf/","section":"Tags","summary":"","title":"CTF","type":"tags"},{"content":"","date":"26 July 2025","externalUrl":null,"permalink":"/tags/hackinbo/","section":"Tags","summary":"","title":"HAckInBO","type":"tags"},{"content":"","date":"26 July 2025","externalUrl":null,"permalink":"/series/hib-2025-spring-edition-ctf-writeups/","section":"Series","summary":"","title":"HiB 2025 Spring Edition, CTF Writeups","type":"series"},{"content":"","date":"26 July 2025","externalUrl":null,"permalink":"/tags/investigations/","section":"Tags","summary":"","title":"Investigations","type":"tags"},{"content":"","date":"26 July 2025","externalUrl":null,"permalink":"/tags/osint/","section":"Tags","summary":"","title":"OSINT","type":"tags"},{"content":"This post is the second part of the CTF challenge called \u0026ldquo;Silent Signal\u0026rdquo; published for OSINTITALIA - HAckinBO Spring Edition 2025 event.\nThis write-up covers the CTF challenge called Silent Signal, published for the OSINTITALIA – HackInBo Spring Edition 2025 event.\nThe challenge was divided into 16 steps, each with its own flag.\nIn this second part, we will walk through the remaining steps of the challenge.\nFLAG09: Il profilo # We have the address of the hidden service and the source code of the web page.\nA GitHub profile was also provided, which is likely related to the challenge.\nThe challenge was described as follows:\nOttimo lavoro! Siamo riusciti a identificare anche un profilo GitHub riconducibile a quello che sembra essere il creatore dell’hidden service. L’elemento interessante? L\u0026rsquo;immagine utilizzata come foto profilo sembra ritrarre un volto noto. Potrebbe trattarsi di un riferimento simbolico o di un omaggio intenzionale. Riesci a identificare chi è la persona raffigurata nell\u0026rsquo;immagine? E, soprattutto: qual è una delle sue frasi celebri?\nThe first step is to analyze the GitHub profile and its profile picture.\nThe image appears to be of a well-known figure, and we can use reverse image search tools to identify the person.\nAfter performing a reverse image search, we identify it as coming from an old TV series called Utopia.\nInspecting the IMDb page of the series, we find that the character’s name was Arby.\nThe wiki page of the series contains a quote from the character Arby: \u0026ldquo;Where is Jessica Hyde?\u0026rdquo;\nThe flag is the string Where is Jessica Hyde?.\nFLAG10: Linked # After identifying the character and the quote, the next step is to find a link between the character and their current identity.\nThe challenge was described as follows:\nUn profilo utente LinkedIn sembra essere riconducibile all’azienda identificata durante l’indagine. Il collegamento potrebbe non essere immediatamente evidente, ma alcuni indizi, come: la cronologia lavorativa, la posizione geografica o le skill elencate uggeriscono una possibile affiliazione con l\u0026rsquo;organizzazione sospetta. Identifica il profilo e verifica se l’utente ha effettivamente interagito con la pagina aziendale (es. tramite like, commenti, endorsement o menzioni) oppure se risulta membro attivo dell’organizzazione, ad esempio elencandola come esperienza lavorativa nel proprio profilo. Se riesci a identificare un utente connesso all’organizzazione Black Echo, prova a comprendere altre ulteriori esperienze lavorative.\nSearching for the organization Black Echo on LinkedIn, we find a page that appears to be related to an entity displaying a logo similar to the one identified earlier on the website.\nThe page lists a single employee: a user named Franco Molpiani.\nThe identified user lists previous experience working for the company ALZMETALL and has a connection with the organization.\nAs the request explained the goal was obtain information about a previous experience, in thi case, the flag is the string ALZMETALL.\nFLAG11: Il messaggio # This challenge involved interpreting an audio file.\nIt was described as follows:\nDurante le fasi di monitoraggio del sito ospitato sul darkweb, è stato rilevato il caricamento di un file audio anomalo. Apparentemente innocuo, il messaggio sembra solo un breve frammento vocale, ma qualcosa non torna: la qualità della voce, il tono, la struttura\u0026hellip; tutto lascia intendere che non si tratti di un semplice vocale casuale. Diversi indizi fanno sospettare che il file contenga un messaggio codificato o una firma vocale riconducibile a un individuo specifico: forse il mittente stesso del messaggio o un’entità che desidera essere riconosciuta da chi sa ascoltare con attenzione. Determina, con gli elementi raccolti, l’identità o id del mittente o un riferimento chiaro su di lui (nickname, voce nota, firma acustica\u0026hellip;).\nThis challenge is a bit tricky, as it involves analyzing an audio file to extract a message or signature that could identify the sender.\nStarting from the hidden service, it is possible to download the audio file.\nUsing a transcription tool, we find that the audio contains a message that is not immediately clear.\nThe message is spoken in a robotic voice, which makes it difficult to understand.\nA tool like Whisper on Hugging Face can be used to transcribe the audio file and obtain the text.\n8 Papa Zulu Papa 8, this is Zulu Bravo 2 Yankee November. Encrypted transmission follows. I repeat, encrypted transmission follows. 4 Charlie, 61, 74, 20, 33, 32, 2 Echo, 39, 32, 39, 37, 2 Charlie, 4 Charlie, 6 Foxtrot, 6 echo 33 2 Echo 32 36 38 39 Message complete. This station is closing down. Zulu Bravo 2 Yankee November, out. The tricky part comes here: the message contains a payload sent using the ICAO phonetic alphabet, a standardized way of spelling out letters and numbers using words.\nThe message follows the standard used by TLC operators, where RECEIVER is the first ID communicated and SENDER is the second.\nAfter this part comes the actual message — in this case, the payload.\n8PZP8 this is ZB2YN Encrypted transmission follows. I repeat, encrypted transmission follows. 4C, 61, 74, 20, 33, 32, 2E, 39, 32, 39, 37, 2C, 4C, 6F, 6E, 33, 2E, 32, 36, 38, 39 Message complete. This station is closing down. ZB2YN out. The flag is the id ZB2YN.\nFLAG12: Da dove si propaga? # Another step was to identify the origin of the message.\nThe challenge was described as follows:\nDurante l’analisi del messaggio audio recuperato dal sito nel darkweb, è emerso un dettaglio fondamentale: il file contiene un identificativo radio trasmesso come parte del messaggio, un indicativo di chiamata o un identificatore associabile a un\u0026rsquo;emittente radiofonica o una stazione.\nA simple search for the ID ZB2YN on Google or other search engines leads to a page where the ID is associated with a radio station.\nThe page contains the history of the radio station and its location. The flag is italian word of the name of city Gibraltar: Gibilterra.\nFLAG13: Chi è il Destinatario? # As before, the challenge was to identify the recipient of the message.\nThe challenge was described as follows:\nDurante l’analisi del messaggio audio intercettato, è stato rilevato il codice alfanumerico del destinatario. Un codice apparentemente anonimo\u0026hellip; ma chi conosce lo spettro radio sa che certi formati non sono casuali. Dopo un’analisi iniziale, il codice risulta conforme al formato ICAO — lo standard internazionale usato per identificare aeromobili, stazioni di terra e trasmettitori radio ad uso aereo, civile o militare. Ma il significato del codice identificato non è immediatamente ovvio, potrebbe trattarsi di: Un identificativo assegnato temporaneamente Un transponder spoofato\nOppure un richiamo intenzionale a una sigla reale, appartenente a una stazione registrata. Individua la scritta, insegna o simbolo che il dispositivo (o l’organizzazione dietro di esso) potrebbe esporre.\nAs before, the challenge involved analyzing the message to identify the recipient.\nThe message contains an alphanumeric code that follows the ICAO format, which is used to identify aircraft, ground stations, and radio transmitters.\nSearching for the code 8PZP8 leads us to a page showing that it is related to a cargo ship called PARDUS.\nInspecting the page, along with its related pages and photos, allows us to identify the name of the ship: CENTURY VENUS.\nThe flag is the name CENTURY VENUS.\nFLAG14: Il nome definitivo.. # It appears that a legitimate organization was founded in the past.\nAnother flag required identifying the name of the company’s creator.\nThe challenge was described as follows:\nUn nome oscuro è riemerso dai meandri della rete: Black Echo. I suoi movimenti sono silenziosi, le tracce appena percettibili, ma qualcosa — o qualcuno — si muove dietro questo nome. Durante le tue indagini, sei riuscito a risalire al nome di un’azienda e al relativo sito web ufficiale che sembrano legati, almeno in apparenza, al progetto \u0026ldquo;Black Echo\u0026rdquo;. Ma è tutto troppo\u0026hellip; pulito. Il sito è registrato, l\u0026rsquo;azienda sembra esistere — ma è reale? È ancora attiva? Oppure è solo una facciata? Potrebbe trattarsi di un\u0026rsquo;entità legale dismessa il cui nome è stato \u0026ldquo;resuscitato\u0026rdquo; per celare un\u0026rsquo;operazione sotterranea. Oppure è un\u0026rsquo;organizzazione attiva che viene inconsapevolmente (o intenzionalmente?) sfruttata come copertura. Identifica il nome del legale rappresentante dell\u0026rsquo;azienda che ipotetiamente è collegata al nome Black Echo.*\nStarting from the previous step, we have the name of the company and its website.\nThe challenge was to identify the name of the company’s legal representative.\nThe contact page displays a map showing the company’s location in Oklahoma, USA.\nSearching for the company name on OpenCorporates leads to a page containing the name of the legal representative: NATE ROBERT CALLEN.\nThe company was registered in 2015 and is no longer active: it was cancelled in 2024.\nThe flag is the name of the legal representative: NATE ROBERT CALLEN.\nFLAG15: Un altro tassello. # In this challenge, we had to identify the name of the city mentioned in the message sent by the radio station.\nThe challenge was described as follows:\nAttraverso l’analisi del sito nel darkweb, abbiamo compreso che l’audio trasmesso non è casuale, ma è la registrazione di una trasmissione radio reale. Il messaggio, codificato e trasmesso a intervalli regolari, sembra indirizzato a una nave cargo attualmente in transito. Determina un nome della città coinvolta nel contenuto del messaggio.\nWe have already identified the message sent by the radio station, which contains a payload encoded in hexadecimal format.\nThe payload is as follows:\n4C, 61, 74, 20, 33, 32, 2E, 39, 32, 39, 37, 2C, 4C, 6F, 6E, 33, 2E, 32, 36, 38, 39 Using a tool like CyberChef, we can decode the message and obtain the flag.\nAfter decoding the payload, we can find a Lat and Long coordinates that point to a location in the city of Hassi R'Mel. The flag is the name of the city: Hassi R\u0026rsquo;Mel.\nFLAG16: Il mosaico # This was likely the last step of the challenge, and it was the hardest one.\nThe text was as follows, with no hint provided:\nAbbiamo ottenuto informazioni estremamente rilevanti che gettano nuova luce sull\u0026rsquo;operazione in corso. Un server nascosto sulla rete darkweb è utilizzato per trasmettere coordinate geografiche criptate a una nave cargo. Le coordinate sembrano indicare punti di consegna secondari, dove parte del carico viene dirottato in modo mirato. Le indagini suggeriscono che un dipendente della società Altmetall sia coinvolto nella rete. Questa persona, sfruttando il proprio accesso interno, organizza il furto o la vendita illecita di parte del materiale prodotto o trasportato dall\u0026rsquo;azienda. Il materiale trafugato viene poi dirottato verso l’entroterra algerino, dove viene temporaneamente stoccato o riconfezionato. Da lì, viene ulteriormente distribuito attraverso una rete ancora in parte sconosciuta. Una volta che hai compreso come verrà utilizzato il materiale, specifica dov\u0026rsquo;è la destinazione ultima del furto?\nDuring the previous steps, we identified a large amount of data and information.\nNow we need to put all the pieces together to determine the final destination of the stolen material.\nDigging deeper into the analysis of the site black-echo.digital, we find a page in the contact section that contains a telephone number.\nThe phone number is +212 77 434 1188, which is an Moroccan phone number.\nA tool like Osint Industries can be used to identify the location of the phone number and other related information.\nAlternatively, using tools like Telegram-Phone-Number-Checker,\nor simply adding the number to a contact list, allows us to determine that the phone number is associated with a Telegram account.\nExploring the Black Echo site, we find a specific rule in the robots.txt file.\nThe rule was as follows:\nUser-agent: * Disallow: /*?page_id= The description of the Telegram account contains a specific phrase:\nلجواب لي راك تقلب عليه راهو في الصفحة ٣٤ That translates to: \u0026ldquo;The answer you are looking for is on page 34\u0026rdquo;.\nGoing to page 34 of the site (https://black-echo.digital/?page_id=34), we find a password-protected page.\nDuring the previous steps, we identified a string embedded in the engine of the dark web site a .txt file containing a passphrase.\nThe passphrase was Sedate0-Happily1-Uncork2, which served as the password to access the page.\nWith a reverse image search, we find that the image is related to a specific location in Algeria called Le Refuge Assekrem.\nThe tricky part of the challenge was understanding that the valid name was Refuge de l'Assekrem.\nThe ship used to transport the stolen material was likely heading to this location, a remote place in the Sahara Desert.\nThe flag is the name of the location: Refuge de l\u0026rsquo;Assekrem.\nFLAG 17: \u0026ldquo;Follow\u0026rdquo; the money # On the identified page, there is a QR code used for receiving funds for the organization, which aims to build its headquarters in the middle of the Algerian desert.\nThe challenge involved identifying any other potential actors interested in the project.\nThe challenge was described as follows:\nAll’interno della pagina web protetta da password, tra placeholder, fotografie, emerge un elemento che spicca: un QR code. Una volta decodificato, rivela un indirizzo BTC attivo nel 2020 ma che potrebbe celare il coinvolgimento di altre reti criminali. Ora rimane la domanda, quale altra organizzazione criminale potrebbe essere coinvolta nel progetto “Black Echo”?\nThe QR code contains a Bitcoin address, which is used to receive funds for the organization. The address is 3Dhv3q6mQeVij7H1yP6Nukr8uFeYDLB49o\nAnalyzing it using a service like Arkham Intelligence reveals that the address was used to receive funds in the past.\nOver the last five years, the address received a total of 0.0422 BTC from an address tied to Ivan Kondratiev (LockBit Ransomware).\nWe can therefore assume, with low confidence, that the flag is related to the LockBit Ransomware group.\nThe flag is the string Lockbit.\n","date":"26 July 2025","externalUrl":null,"permalink":"/posts/osintitalia-hb-2025-writeup-02/","section":"Posts","summary":"\u003cp\u003eThis post is the second part of the CTF challenge called \u0026ldquo;Silent Signal\u0026rdquo; published for OSINTITALIA - HAckinBO Spring Edition 2025 event.\u003c/p\u003e","title":"OSINTITALIA - HAckinBO Spring Edition 2025 - Writeup! /02","type":"posts"},{"content":"","date":"26 July 2025","externalUrl":null,"permalink":"/posts/","section":"Posts","summary":"","title":"Posts","type":"posts"},{"content":"","date":"26 July 2025","externalUrl":null,"permalink":"/series/","section":"Series","summary":"","title":"Series","type":"series"},{"content":"","date":"26 July 2025","externalUrl":null,"permalink":"/tags/social-media/","section":"Tags","summary":"","title":"Social Media","type":"tags"},{"content":"","date":"26 July 2025","externalUrl":null,"permalink":"/tags/","section":"Tags","summary":"","title":"Tags","type":"tags"},{"content":"","date":"26 July 2025","externalUrl":null,"permalink":"/tags/telegram/","section":"Tags","summary":"","title":"Telegram","type":"tags"},{"content":"","date":"26 July 2025","externalUrl":null,"permalink":"/categories/writeup/","section":"Categories","summary":"","title":"Writeup","type":"categories"},{"content":"This post is the first part of writeup of the CTF challenge called \u0026ldquo;Silent Signal\u0026rdquo; published for OSINTITALIA - HAckinBO Spring Edition 2025 event.\nThis write-up covers the Silent Signal CTF challenge, released for the OSINTITALIA – HackInBo Spring Edition 2025 event. The challenge consisted of 16 steps, each providing its own flag. In this first part of the write-up, we’ll walk through the first 8 steps in detail, explaining the thought process and techniques used to solve them.\nFLAG01: C\u0026rsquo;è posta per te! # The challenge began with Step One, which came with the following description:\nUna nuova community underground ha fatto la sua comparsa nel panorama della cybercriminalità. Pochi giorni fa è stato individuato un nuovo forum, RAPID LEAKED EXCHANGE, ospitato sul dominio rapid-leakedexhange[.]to. La piattaforma ha rapidamente attirato l’attenzione di numerosi attori malevoli, in quanto ha iniziato sin da subito a pubblicare materiale riservato, incluso contenuto di natura militare. Come spesso accade in ambienti competitivi, alcune community rivali hanno reagito lanciando attacchi DDoS contro l’infrastruttura del forum. In risposta, l’amministratore — consapevole di alcune vulnerabilità presenti nel CMS — ha deciso di mettere temporaneamente offline il servizio. Nel frattempo, le autorità sono riuscite a effettuare il take down del dominio. Attualmente, il sito risulta irraggiungibile: i servizi pDNS non hanno registrato evidenze rilevanti sui record DNS e non sono disponibili dettagli associati al record WHOIS. In qualità di cyber threat investigator, ti viene richiesto di indagare sull’identità dell’autore — o degli autori — responsabili della creazione e gestione del forum. Hai ricevuto una copia della mail automatica inviata agli utenti durante la registrazione al forum. Questo artefatto potrebbe celare indizi utili per tracciare l’infrastruttura utilizzata dall’avversario. Analizza attentamente l’header, i link e i metadati: potrebbe essere la chiave per iniziare a collegare i punti. Prova a comprendere dove risiede parte dell\u0026rsquo;infrastruttura ospitante il forum. Specifica l\u0026rsquo;indirizzo\nAs attachment there was a file named message.eml containing the following email:\nBy inspecting the email header, we can determine that the message originated from the IP address 138.199.229.114.\nThe Received header also indicates that it was sent via mail.rapid-leakedexchange.to.\nThe flag is the IP address of the sender, which is 138.199.229.114.\nFLAG02: Chiedi supporto # The second step of the challenge was introduced with the following description:\nL’indirizzo IP identificato durante l’analisi sembra appartenere a una nota compagnia di hosting, frequentemente utilizzata sia da utenti legittimi che — occasionalmente — da attori malevoli per mascherare la propria infrastruttura. Considerata la rilevanza potenziale dell’informazione, potrebbe essere strategico contattare direttamente il provider per richiedere eventuali dettagli aggiuntivi che possano supportare le indagini in corso. Tali dettagli potrebbero includere dati di registrazione, log accesso o timestamp di creazione dei servizi associati all’IP. Il tuo compito, ora, è individuare il punto di contatto ufficiale messo a disposizione dall’azienda per segnalazioni di abusi, richieste legali o collaborazioni con le forze dell’ordine. In particolare, cerca l’indirizzo email dedicato a segnalazioni di abuso o richieste da parte di investigatori.\nThe challenge required identifying the abuse contact email address for the hosting provider associated with the given IP address.\nUsing a service like IPinfo, we can determine that the IP address is registered to a company called Hetzner Online GmbH.\nA quick Google search for \u0026quot;Hetzner abuse contact email\u0026quot; reveals their unofficial abuse contact email address.\nThe flag was the email address displayed in the IPinfo page: abuse@hetzner.com.\nFLAG03: Alone in the Dark # The third step of the challenge was introduced with the following description:\nAbbiamo ricevuto un riscontro ufficiale dal team di supporto di Hetzner, relativo all’istanza server oggetto dell’indagine. Secondo quanto riportato, è stato rilevato un traffico di rete anomalo associato a quel server, significativamente superiore alla norma per una macchina di quel tipo. In particolare, i tecnici sospettano che il server possa essere utilizzato per ospitare un servizio sul darkweb. Tuttavia, a differenza dei classici hidden services — solitamente caratterizzati da un traffico irregolare e sporadico — la telemetria mostra un flusso costante e sostenuto di dati a intervalli regolari. Questo comportamento ha portato a formulare l’ipotesi che si possa trattare di un servizio di streaming anonimo, potenzialmente accessibile solo tramite la rete Tor.\nBuilding on the previous step, we already have the IP address.\nThe text suggests that the server is likely hosting a service on the dark web — specifically, a streaming platform accessible only via Tor.\nUsing the IP address, we can attempt to identify the Tor hidden service associated with it.\nTools and platforms such as Validin, Shodan, Censys, or FOFA can reveal interesting details about the hidden service.\nIt appears that the hidden service administrator made some OPSEC mistakes.\nBy using a Validin scan, we can identify the HTTP response headers of the service exposed on port 8080.\nThe HTTP header contains the address of an active hidden service.\nThe flag is included in the HTTP header response as: j6nphmtl6mqayglcd5eir2jglayitbvqd3eprhiw2yyiv66ki2fonuid.onion.\nFLAG04: Catturali tutti! # The fourth step of the challenge began with the following description:\nAbbiamo individuato l’indirizzo del sito .onion. Dall’analisi preliminare, emergono dettagli curiosi: sembra che l’amministratore — e probabilmente anche il creatore — dell’hidden service abbia lasciato tracce insolite all’interno del sito. Alcuni elementi visivi, testuali o di struttura sembrano non essere lì per caso. La tua prossima sfida: riesci a individuare eventuali easter egg nascosti all’interno del sito? Presta particolare attenzione a riferimenti criptici, pseudonimi, simboli o nomi ricorrenti: potrebbero indicare a quale personaggio o figura l’autore si è ispirato nella costruzione dell’identità del progetto. Ogni indizio può essere il tassello di un puzzle più ampio.\nThe challenge involved analyzing the Tor hidden service to look for any easter eggs or clues left by the administrator or creator.\nUpon visiting the hidden service, we find a simple HTML page containing some text and images.\nThe text describes the service as \u0026ldquo;Silent Signal\u0026rdquo; and refers to it as a dark web streaming service.\nBy checking for the existence of additional pages or assets, we discover a strange string in the server’s response.\nExploring its source code helped to solve the new chalenge:\nThe flag is the name of a famous Pokemon: Pikachu.\nFLAG05: Indizi dietro la facciata # The fifth step of the challenge was introduced with the following description:\nL’applicazione si presenta in modo anomalo: all’apparenza sembra offrire un servizio di file drop per tracce audio, ma non dispone né di un’interfaccia di login né di una funzione visibile per la creazione o gestione dei file. Questa discrepanza solleva dubbi sul reale scopo dell’applicazione. Il tuo compito è analizzare in profondità il comportamento del sistema e cercare di comprenderne il funzionamento. Esamina routing, endpoint nascosti, script lato client e tutte le funzionalità non documentate. Se riuscirai a ricostruire la logica del progetto, potresti scoprire un dettaglio cruciale nascosto nella root del repository: un file, un messaggio o una configurazione lasciata volontariamente per chi sa dove guardare.\nThe challenge required analyzing the application\u0026rsquo;s behavior to understand its functionality and uncover any hidden details.\nThe code reveals a simple HTML page with a form that allows users to upload audio files. However, there is no visible login interface or file management functionality.\nBy searching the page’s source code on common platforms like GitHub, we can find an interesting clue that leads to a repository containing the project’s code.\nExploring the repository, we find a file named read_th1s_for_the_Fl4g.txt.\nBy checking its commit history, we can uncover the flag.\nThe flag is the string Sedate0-Happily1-Uncork2.\nFLAG06: Animali nel dark-web # After obtaining the address of the repository, it seemed straightforward to find the flag — but it wasn’t that easy.\nThe challenge was described as follows:\nDopo ore di analisi, ricerche incrociate tra domini, metadati e repository oscuri, sei finalmente riuscito a risalire ai repository sorgente dei file hostati sull’hidden service. Tra i file presenti, emerge il codice di una pagina web dedicata a un presunto servizio di audio drop, ovvero la possibilità di caricare e condividere tracce audio. A un primo sguardo, il progetto si presenta come un semplice web tool per lo scambio anonimo di messaggi vocali. Tuttavia, un’analisi più attenta suggerisce uno scenario differente: il codice potrebbe essere stato progettato per confondere l’osservatore, mascherando la reale finalità del servizio. L’ipotesi più accreditata è che il server funga da interfaccia fittizia, dietro la quale si cela un meccanismo per pubblicare messaggi audio destinati ad essere successivamente inoltrati via radio (forwarded over RF). Il tuo compito ora è analizzare il codice e determinare: Come funziona realmente il server? Quale classe viene utilizzata per servire il web server (es. Apache, Nginx, FastAPI, ecc.). Mi raccomando ricorda che la flag non è case insensitive!!!!!\nThe challenge involved analyzing the web page’s code history to understand how the server operates and which class is used to run it.\nReading the code, we can see that the server is implemented using the HTTPServer Python class.\nThe flag was the name of the class used to serve the web server, which is HTTPServer.\nConsidering the response header and the search engine results, it appears the developer spoofed the class name by inserting the string PHP/5.6.40 in the response header: self.send_header(\u0026quot;X-Powered-By\u0026quot;, \u0026quot;PHP/5.6.40\u0026quot;).\nThe flag is the string HTTPServer.\nFLAG07: L\u0026rsquo;altro Dominio # Building on the previous step, we now have the address of the hidden service and the source code of its web page.\nThe challenge was described as follows:\nNella bio del profilo GitHub dell’utente è presente un URL che punta a un sito web. Tuttavia, come avrai notato, il sito non appare attendibile: presenta numerosi placeholder, testi generati automaticamente (es. Lorem Ipsum) e sezioni incomplete. Tutto fa pensare che il sito sia ancora in fase di sviluppo, oppure sia stato creato come copertura. Inoltre, il record WHOIS associato al dominio è oscurato tramite un servizio di privacy, rendendo difficile risalire direttamente all’intestatario. La tua prossima missione: Individua un altro dominio simile o correlato a quello già identificato.\nBy checking the bio of the GitHub profile, we find a link to a website that appears to be under construction or not totally deployed.\nThe site contains placeholder text and incomplete sections, suggesting it is either still in development or intentionally created as a cover.\nHowever, the domain’s DNS TXT record contains a clue that leads to useful information.\nThe domain was integrated into an MS Azure Tenant.\nGoing deeper and understanding other related domains using tools like aadinternals.com/osint,\nwe discover that the domain black-echo.digital is related to the domain drpbx.link.\nThe flag is the string drpbx.link.\nFLAG08: Non sembra lecito # The next step of the challenge is to identify the services hosted on the domain drpbx.link.\nThe challenge was described as follows:\nSiamo riusciti a identificare un nuovo dominio potenzialmente collegato all’infrastruttura sospetta: drpbx.link. Il passo successivo è fondamentale per l’indagine. Analizza il dominio drpbx.link e verifica se ospita o ha ospitato un servizio web o un’applicazione che potrebbe essere utilizzata per scopi illeciti (esfiltrazione dati, drop zone,C2, ecc.). Individua e specifica il servizio nel seguente formato: nomeapplicazione+scopo_dell_applicazione apache+serverweb nextcloud+filehosting flask+api_interfaccia_malware\nUsing search engine tools like Validin, VirusTotal, or similar services, we can see that the domain drpbx.link is hosting a web application.\nChecking the subdomain list displayed on the page, we find a subdomain called gophish.drpbx.link, which appears to be an open-source application used as a phishing framework.\nGophish is a well-known open-source phishing framework that allows users to create and manage phishing campaigns.\nIt is often used for educational purposes, security awareness training, and testing the effectiveness of security measures against phishing attacks.\nThe flag is the string gophish+phishing.\n","date":"25 July 2025","externalUrl":null,"permalink":"/posts/osintitalia-hb-2025-writeup-01/","section":"Posts","summary":"\u003cp\u003eThis post is the first part of writeup of the CTF challenge called \u0026ldquo;Silent Signal\u0026rdquo; published for OSINTITALIA - HAckinBO Spring Edition 2025 event.\u003c/p\u003e","title":"OSINTITALIA - HAckinBO Spring Edition 2025 - Writeup! /01","type":"posts"},{"content":" Giacomo Giallombardo, # Dev,\\s(deep|dark)web\\sLurker,\\sCyber\\sThreat\\sIntel\\sAnalyst\\sby\\sday.\\nOSINT-lover\\sby\\snight.\nI am a Cyber Threat Analyst with a strong background in Software Development and Cyber Security, I am passionate about Cyber Security, Open Source Intelligence (OSINT), and Cyber Threat Intelligence (CTI). I have experience in developing tools and integrations for threat intelligence platforms, such as OpenCTI, MISP, and Maltego. I am a member of the OpenCTI community and have contributed to the development of several connectors for the platform. I work as a volunteer for a local committee of Italian Red Cross.\nI am a member of the Curated Intelligence community and CTI League CTIL.\nSkills # Areas of Expertise: Cyber Threat Intelligence, OSINT, (Dark|Deep)web investigations, Blockchain investigations, Software development, Malware Analysis, Incident Response Programming Languages: Go, Python, JavaScript, C#, C, *scripts Frameworks: OpenCTI, Maltego, MISP, STIX/TAXII, YARA, Sigma, ATT\u0026amp;CK, VERIS Projects # Forwardgram PLUS # Forwardgram Plus (on Steroids) is a free and open source, Telegram to discord message forwarder bot. It natively supports forwarding messages from Telegram to Discord, and vice versa. It also supports automatic translation and image analysis via OCR. It is based on a fully refactored version of the original Forwardgram.\nATOP - A TON of privacy # \u0026ldquo;A TON of Privacy\u0026rdquo; formally called ATOP \u0026hellip; is an opensource CLI tool for conducting OSINT investigations on TON (Telegram 🙃) NFTs. The TON network is increasingly integrated with the Telegram ecosystem, via NFT. Telegram allows people to purchase numbers, domains and nicknames through cryptocurrency.\nATOP - Maltego transform # A Maltego transform useful to make investigations on TON assets like TON nickname, TON DNS and TON Telephone Number. These kinds of entities are NFT on TON network and they are fully integrated in Telegram client. The transform is based on ATOP ATOP.\nTweetfeed OpenCTI Connector # An extarnal-import connector created for ingesting Tweetfeed IOC streams. It creates and import Observables and Indicators collected from different researchers and shared on X platform. Tweetfeed was developed by Daniel López.\nMWDB OpenCTI Connector # MWDB is an opensource malware collector and databases. The connector ingests malware feeds in order to import Observables and Indicator related to malwares and their configurations.\nFeel free to reach out to me for collaborations or inquiries about my projects.\n","date":"11 August 2024","externalUrl":null,"permalink":"/about/","section":"Aaarghhh's Blog","summary":"","title":"About","type":"page"},{"content":"","externalUrl":null,"permalink":"/authors/","section":"Authors","summary":"","title":"Authors","type":"authors"}]