October 10, 2026
Shiba Insider | Blue Team Labs Online — Writeup
Step-by-step
By Sushma
4 min read
Step-by-step
1. Read the PCAP (Q1)
Open the provided capture in Wireshark and look at the HTTP responses (filter http). One response carries a short message addressed to whoever is investigating.
- Answer:
use your own password - The hint is that the password isn't going to be handed to you.
2. Get into the ZIP (Q2) The author searched the capture for the password and found nothing, so he cracked it:
zip2john file.zip > hash.txt
john --wordlist=/usr/share/wordlists/rockyou.txt hash.txtzip2john file.zip > hash.txt
john --wordlist=/usr/share/wordlists/rockyou.txt hash.txtzip2john converts the archive's encryption data into a hash John can attack, and RockYou is a common leaked-password wordlist.
- Answer:
redforever - The takeaway is that a weak, dictionary-based password offers almost no protection.
OR
Inspect the request's Authorization header to read the credentials. The password is redforever (Q2).
3. Check whether more passwords are needed (Q3)
Open README.txt from the extracted ZIP. It states that there are no other passwords.
- Answer:
No
Unlock the ZIP with that password. It contains a text file and an image. The text says Shiba Dog has everything and no more passwords will be needed (Q3: No).
4. Inspect the image metadata (Q4, Q5)
The ZIP contains an image (ssdog1.jpeg). The standard tool for reading file metadata is exiftool:
exiftool ssdog1.jpegexiftool ssdog1.jpeg- Q4 answer:
exiftool - Q5 answer:
Technique : Steganography, a metadata field that tells you data is hidden in the image.
┌──(kali㉿kali)-[~/Downloads/95f2cd3276574571c2523c1dc447e79c48410c6c/file]
└─$ exiftool ssdog1.jpeg
ExifTool Version Number : 13.55
File Name : ssdog1.jpeg
Directory : .
File Size : 84 kB
File Modification Date/Time : 2021:09:26 16:07:52-04:00
File Access Date/Time : 2026:10:10 07:13:38-04:00
File Inode Change Date/Time : 2026:10:10 07:13:32-04:00
File Permissions : -rw-rw-r--
File Type : JPEG
File Type Extension : jpg
MIME Type : image/jpeg
JFIF Version : 1.01
Resolution Unit : None
X Resolution : 1
Y Resolution : 1
XMP Toolkit : Image::ExifTool 11.88
Technique : Steganography
Technique Command : steghide
Image Width : 1080
Image Height : 1018
Encoding Process : Baseline DCT, Huffman coding
Bits Per Sample : 8
Color Components : 3
Y Cb Cr Sub Sampling : YCbCr4:4:4 (1 1)
Image Size : 1080x1018
Megapixels : 1.1┌──(kali㉿kali)-[~/Downloads/95f2cd3276574571c2523c1dc447e79c48410c6c/file]
└─$ exiftool ssdog1.jpeg
ExifTool Version Number : 13.55
File Name : ssdog1.jpeg
Directory : .
File Size : 84 kB
File Modification Date/Time : 2021:09:26 16:07:52-04:00
File Access Date/Time : 2026:10:10 07:13:38-04:00
File Inode Change Date/Time : 2026:10:10 07:13:32-04:00
File Permissions : -rw-rw-r--
File Type : JPEG
File Type Extension : jpg
MIME Type : image/jpeg
JFIF Version : 1.01
Resolution Unit : None
X Resolution : 1
Y Resolution : 1
XMP Toolkit : Image::ExifTool 11.88
Technique : Steganography
Technique Command : steghide
Image Width : 1080
Image Height : 1018
Encoding Process : Baseline DCT, Huffman coding
Bits Per Sample : 8
Color Components : 3
Y Cb Cr Sub Sampling : YCbCr4:4:4 (1 1)
Image Size : 1080x1018
Megapixels : 1.1
5. Extract the hidden data (Q6, Q7) The tool for retrieving hidden data from JPEGs is steghide:
steghide extract -sf ssdog1.jpegsteghide extract -sf ssdog1.jpegWhen asked for a passphrase, just press Enter, since there is none (consistent with the README). This extracts idInsider.txt. Read it to get the ID.
- Q6 answer:
steghide - Q7 answer:
0726ba878ea47de571777a
┌──(kali㉿kali)-[~/Downloads/95f2cd3276574571c2523c1dc447e79c48410c6c/file]
└─$ cat README.txt
Shiba Dog has everything you need and decided that no more passwords will be needed
┌──(kali㉿kali)-[~/Downloads/95f2cd3276574571c2523c1dc447e79c48410c6c/file]
└─$ cat README.txt
Shiba Dog has everything you need and decided that no more passwords will be needed
┌──(kali㉿kali)-[~/Downloads/95f2cd3276574571c2523c1dc447e79c48410c6c/file]
└─$ steghide extract -sf ssdog1.jpeg
Enter passphrase:
wrote extracted data to "idInsider.txt".
┌──(kali㉿kali)-[~/Downloads/95f2cd3276574571c2523c1dc447e79c48410c6c/file]
└─$ ls
idInsider.txt README.txt ssdog1.jpeg
┌──(kali㉿kali)-[~/Downloads/95f2cd3276574571c2523c1dc447e79c48410c6c/file]
└─$ cat idInsider.txt
0726ba878ea47de571777a
┌──(kali㉿kali)-[~/Downloads/95f2cd3276574571c2523c1dc447e79c48410c6c/file]
└─$ cat README.txt
Shiba Dog has everything you need and decided that no more passwords will be needed
┌──(kali㉿kali)-[~/Downloads/95f2cd3276574571c2523c1dc447e79c48410c6c/file]
└─$ cat README.txt
Shiba Dog has everything you need and decided that no more passwords will be needed
┌──(kali㉿kali)-[~/Downloads/95f2cd3276574571c2523c1dc447e79c48410c6c/file]
└─$ steghide extract -sf ssdog1.jpeg
Enter passphrase:
wrote extracted data to "idInsider.txt".
┌──(kali㉿kali)-[~/Downloads/95f2cd3276574571c2523c1dc447e79c48410c6c/file]
└─$ ls
idInsider.txt README.txt ssdog1.jpeg
┌──(kali㉿kali)-[~/Downloads/95f2cd3276574571c2523c1dc447e79c48410c6c/file]
└─$ cat idInsider.txt
0726ba878ea47de571777ano password
6. Identify the insider (Q8) Use that ID to look up the matching profile on the site the challenge points to.
- Answer:
bluetiger
BTLO Edit description
The ID is a BTLO user ID. Open any BTLO profile page, replace the ID in the profile URL with the one you found, and the page shows the user bluetiger (Q8). The author got stuck here at first, trying crypto-ID lookups because of the Shiba theme, and the word "Insider" in the title was the hint to check the platform itself.
Challenge Link:
BTLO Edit description
Notes for your writeup
- Skill chain: network forensics → password cracking → metadata analysis → steganography → OSINT pivot on an identifier.
- Defensive lessons: exfiltrated or planted data can hide in ordinary-looking images, which is why content inspection, DLP, and metadata checks matter. Weak archive passwords fall to wordlists in seconds.
- Gaps to fill from your own run:
- The article doesn't say how the ZIP was extracted from the PCAP. Presumably you export it via File → Export Objects → HTTP, but confirm this yourself.
- It doesn't name the site used for the final profile lookup, since that was in a screenshot.
- Verify values: copy the ID and the profile name from your own output, since I'm relying on this single source and couldn't see the screenshots.
- Attack chain: credentials sent in cleartext over HTTP, a weak or exposed ZIP password, data hidden in an image via steganography, and an identifier linking back to a real account.
- Defensive takeaways: avoid HTTP Basic auth over unencrypted channels, inspect outbound images for hidden payloads, and treat user IDs as sensitive identifiers.
Thanks for Reading:)