Milkshake Stenography Challenge Solution!

Kamran Saifullah
3 min readJun 11, 2019

I has spent plenty of time getting myself familiar with different Stenography Tools and Stenography techniques for hiding different data under different data. After all that learning i thought to put everything to test and to see it’s implication in the CTF. For this i chose HackTheBox Stego challenges.

This is going to be the solution for Milkshake challenge.

CAUTION: If you haven’t solved the challenge by yourself yet. Try harder by yourself. Below are some resources which are surely going to help you get yourself familiar with the techniques used to make this challenge.

Let’s get started!

On downloading this challenge we are provided with one audio file and nothing else. It’s for sure that the flag is within the audio file. On playing the audio file we can hear a song. But once we reach the half the sound is different. There is a distraction in the first half of the audio making it sure that something has been embedded within the first half of it.

On quick google i came across lot’s of audio visualizer and Acoustic Spectrum Analysis tools.

I personally have selected the “Sonic Visualizer Tool”

It works like a charm on Windows :))

All you need is to open up the Milkshake audio file in Sonic Visualizer. It will look something like this.

Go to Pane -> Add Spectrogram -> Channel 1

We have been welcomed by our flag :))

The second tool i have used to confirm this flag is Spek which can be added to Kali Linux on single command

apt-get install spek

It is very simple and basic Spectrum Analyzer which is way more simple to use. All you need is to provide it with the file and it will show the spectrogram of the audio file.

That’s all what we needed to complete this basic but an amazing challenge.

For further reading please follow the below link :))

Don’t forget to add 50 claps if you liked the solution :))

Thanks for reading!

--

--

Kamran Saifullah

Malware/RE/Firmware Analysis, App Sec/Off Sec, VAPT, Phishing Simulations/SE | Risk Management, IS Governance, Audits, ISO 27001 LI