picoGym | Disk, disk, sleuth! II Write-up

Challenge description

All we know is the file with the flag is named down-at-the-bottom.txt … Disk image: dds2-alpine.flag.img.gz

Category: Forensics


First, let’s examine the file presented to us by the challenge using the file command.

Looks like it is a gzip archive

Decompressing the archive with the command gzip -d results in the disk image file dds2-alpine.flag.img.

Next, I used the binwalk tool to extract data from the disk image. (binwalk -e dds2-alpine.flag.img). This step produced the following.

Using file on 100000.ext suggests that it is an MBR boot sector image, and ext-root is the extracted root filesystem.

The description of the challenge mentioned a file called down-at-the-bottom.txt. Let’s see if it’s somewhere in ext-root.


From here we simply have to read the text file with cat to get our flag.


