Lesson pack 17 · Core · 90 minutes
Steganography
Sweep an image, audio file, or paragraph for hidden data across the whole technique space rather than guessing one method.
Print this page for a paper plan - the navigation and links drop out.Student-facing version
Before the session
- Nothing to install. Students need a browser and https://ctfpal.com. Confirm the room can reach it once; after that it works offline.
- Read the lesson yourself first - about 20 minutes.
- Have one worked example ready to paste. The classroom link builder on the instructor page turns it into a URL that opens preloaded.
Objectives
Written as things a student can do afterwards, so they can be assessed rather than asserted.
- Extract LSB data across channels, bit orders, and traversal directions
- Read a spectrogram to distinguish painted text, Morse, SSTV, and DTMF
- Detect zero-width and whitespace steganography in plain text
- Compare a suspect image against an original, perceptually and byte for byte, and say what the difference means
- Explain why LSB survives in PNG and dies in JPEG
Running order (90 min)
| Time | What happens |
|---|---|
| 0:00-0:09 | Frame the problemWhat the category looks like when you meet it cold, and why the naive approach fails. |
| 0:09-0:27 | Teach the methodThe technique itself, on the board or from the lesson. No tools open yet. |
| 0:27-0:50 | Demonstrate liveSame technique, in the workspace, on your worked example. Narrate every choice. |
| 0:50-1:21 | Practice setStudents work the challenges. Circulate rather than present. |
| 1:21-1:30 | Checkpoint and wrapCollect the artefact, name what comes next. |
Tools used
- Automatic steganography solver - Throw every applicable steganography technique at a file at once - image, audio, archive, text, and document - recursively unpack what falls out, and surface flag matches.https://ctfpal.com/?tool=stego-solver
- LSB steganography extractor - Extract least-significant-bit data from images across every channel, bit order, and traversal direction, with bit-plane visualisation.https://ctfpal.com/?tool=lsb-steganography
- PNG chunk analyzer - Walk a PNG chunk by chunk, validate CRCs, read tEXt and zTXt metadata, and find data hidden after IEND or in non-standard chunks.https://ctfpal.com/?tool=png-chunk-analyzer
- Audio spectrogram and SSTV decoder - View a WAV as a spectrogram to find text drawn in frequency space, decode Morse and SSTV, and extract LSB data from audio samples.https://ctfpal.com/?tool=audio-spectrogram
- DTMF tone decoder - Decode telephone keypad tones from audio - the dual-frequency pairs that encode digits 0-9, *, #, and A-D.https://ctfpal.com/?tool=dtmf-decoder
- Morse code translator - Translate Morse code to text and back, tolerating any dot/dash characters and any word separator. Also decodes Morse recovered from audio.https://ctfpal.com/?tool=morse-code-translator
- Zero-width character and text steganography decoder - Reveal messages hidden in zero-width Unicode characters, trailing whitespace, and homoglyph substitution - text steganography that survives copy-paste.https://ctfpal.com/?tool=zero-width-decoder
- Perceptual image hash: are these the same picture? - Compare two images by aHash, dHash and pHash in the browser - a re-encoded, resized or recompressed copy has a different checksum and nearly the same perceptual hash.https://ctfpal.com/?tool=perceptual-image-hash
Reading
- A workflow for image steganography, from magic bytes to bit planes - 7 min. Stego challenges reward order, not inspiration. The sequence that finds the payload: container checks before pixel checks, structure before statistics, and the specific tells that separate a PNG trick from a JPEG one.
- Audio steganography: spectrograms, LSB, and signals that are not music - 7 min. A layered workflow for audio challenges - what the waveform tells you, why the spectrogram is almost always the first move, decoding DTMF and SSTV and Morse, and the LSB and metadata tricks that hide in a WAV.
- Hiding in text: zero-width characters, homoglyphs, and whitespace - 6 min. A paragraph that looks ordinary and carries a payload. How to detect zero-width and bidirectional control characters, spot a Cyrillic letter posing as a Latin one, read whitespace encodings, and recover the bits.
Practice set
Real picoCTF challenges tagged with this module’s techniques, easiest first. Assign the first three in class and the rest as homework.
- Flag in Flame - picoMini by CMU-Africa, easy
- Glory of the Garden - picoCTF 2019, easy
- Hidden in plainsight - picoMini by CMU-Africa, easy
- RED - picoCTF 2025, easy
- Secret of the Polyglot - picoCTF 2024, easy
- StegoRSA - picoCTF 2026, easy
- Enhance! - picoCTF 2022, medium
- flags are stepic - picoCTF 2025, medium
- hideme - picoCTF 2023, medium
- Investigative Reversing 0 - picoCTF 2019, hard
- Investigative Reversing 1 - picoCTF 2019, hard
- Investigative Reversing 2 - picoCTF 2019, hard
Checkpoint (gradeable)
Solve a nested stego challenge and draw the chain of containers from the outermost file to the flag.
Deliberately a produced artefact rather than a quiz question: it is either there or it is not, which makes it fast to mark and hard to bluff. Every tool in ctfpal is deterministic, so two students who did the work correctly hand in the same value.
Where the room gets stuck
Steganography rewards breadth, which makes it the module where an automated sweep is most obviously better than a hypothesis. Use it to teach that a broad cheap search beats a narrow expensive guess.
- Trying one extraction and concluding there is nothing there. LSB alone has channel, bit-plane, bit-order and traversal variants, and the sweep exists because guessing which is expensive.
- Looking for LSB in a JPEG. Lossy recompression destroys it, so a JPEG challenge is almost always metadata, appended data, or the spectrogram.
- Ignoring the text. Zero-width characters and trailing whitespace survive copy-paste, and nothing about the rendered page shows them.
- Starting the sweep before identifying the container. An LSB pass over what turns out to be an archive wearing a PNG header costs the whole session, and the previous module answers that question in one command.
- Reading a passphrase prompt as a dead end. These tools take a key, and the key is almost always elsewhere in the challenge - the filename, the metadata, the accompanying text - rather than something to brute force.
If a student wants the subject, not the answer
Chapter-level references, so a student can be pointed at twenty pages rather than at a book. Nothing here is required to complete the module.
- Black Hat Go, Tom Steele, Chris Patten, and Dan Kottmann. Chapter 13, Hiding Data with Steganography. Writing the embedder makes the extraction parameters obvious, because you had to choose them.
- Evasive Malware, Kyle Cucci. Chapter 16, Encoding and Encryption. The same hiding techniques used for payload delivery, where the goal is evading a scanner rather than a player.
If you finish early
- Hand out a challenge from the cross-CTF index in this category - each one has published solutions to compare afterwards.
- Run the same input through Identify and let the class argue with the ranking. Disagreeing with a confidence score is where the technique actually lands.
- Ask a student to break their own example - construct an input that defeats the tool, and explain why.
Take this into a room
Markdown files, built here in your browser. They print, they open in anything, and they carry the challenge text - so the session works with no network in the room.