Skip to main content

m00nwalk picoCTF 2019 Solution

Extract a hidden image transmitted as an audio signal using a retro analog transmission format.

Published: April 2, 2026Updated: September 20, 2026

Description

Find the flag in the audio file. This is an SSTV transmission.

Download the audio file.
bash
wget <url>/message.wav

Solution

Want to try it yourself first?

The guided walkthrough reveals hints one step at a time.

Walk me through it
  1. Step 1Identify the SSTV signal
    Observation
    The description calls the file an SSTV transmission, and the name 'm00nwalk' nods to Apollo. The first move is to play the WAV and confirm the characteristic SSTV chirp.
    Play the audio file. You will hear the characteristic chirp and tone sequence of an SSTV (Slow Scan Television) transmission. The audio encodes an image by mapping pixel brightness values to audio frequencies over time.
    Learn more

    SSTV (Slow Scan Television) is a method used by amateur radio operators to transmit images over audio channels. Different SSTV modes (Martin 1, Scottie 1, Robot 36, etc.) use different image sizes and encoding timings. The mode is announced at the start of the transmission with a VIS (Vertical Interval Signaling) code.

  2. Step 2Decode with QSSTV or RX-SSTV
    Observation
    The audio carries the recognizable SSTV tone sequence. A dedicated decoder like QSSTV or RX-SSTV turns those frequencies back into a picture.
    Install QSSTV (Linux) or RX-SSTV (Windows). On Linux, configure QSSTV to receive from a virtual audio loopback device, then play the WAV file to the loopback. On Windows, set RX-SSTV to listen to the sound card and play the WAV file.
    bash
    sudo apt install qsstv
    bash
    # Configure: set audio input to virtual loopback
    bash
    # Then play: aplay message.wav
    What didn't work first

    Tried: Reach for multimon-ng, since it is the usual go-to for demodulating audio modes from a WAV file.

    multimon-ng has no SSTV demodulator at all. Its mode list is POCSAG, FLEX, EAS, the AFSK family, DTMF, ZVEI, MORSE_CW and friends, so '-a SSTV' is rejected as an unknown demodulator. SSTV needs a purpose-built decoder such as QSSTV or a Python SSTV decoder.

    Tried: Open QSSTV and start receiving with the default audio input set to the physical microphone, then play the WAV file through the speakers.

    A microphone picks up room noise and speaker distortion instead of the clean signal, so QSSTV shows a blank or corrupted image. Route the playback through a virtual audio loopback (PulseAudio's null-sink, or VB-Cable on Windows) so QSSTV gets a lossless digital copy.

    Learn more

    A simpler approach: use a Python SSTV decoder that reads the WAV samples directly, which avoids the audio-loopback setup entirely. Note that the pysstv package is an encoder (it turns images into SSTV audio), so it will not help here. Another popular approach is to open the WAV in Audacity and visually inspect the spectrogram - SSTV appears as distinctive horizontal lines in the frequency domain.

    If the WAV is at an awkward sample rate for your decoder, normalize it first with sox message.wav -r 44100 -c 1 message_44k.wav and decode that copy instead.

  3. Step 3Read the flag from the decoded image
    Observation
    QSSTV renders the signal as a complete image, so the flag should simply be readable in that picture. No further processing needed.
    QSSTV will render the audio as an image. The flag text is visible in the image that appears.
    Learn more

    SSTV grew out of amateur radio in the late 1950s as a way to squeeze still images through a voice-bandwidth channel. NASA separately used its own slow-scan television cameras on the Apollo missions, which is what the challenge name is nodding at: Apollo 7 carried the first live TV broadcast from a crewed American spacecraft in 1968, and the Apollo 11 moonwalk was televised through a slow-scan camera whose output had to be converted before it could be broadcast.

Interactive tools
  • StegallDrop any file and Stegall runs every applicable steg technique in parallel: LSB sweeps, bit planes, spectrograms, polyglot carving, metadata, whitespace decode, and a 6-layer base/ROT/XOR/zlib cascade. Recursively unpacks results and surfaces flag matches.
  • Strings ExtractorPull printable text from any binary, library, or image. ASCII and UTF-16 detection, configurable minimum length, flag-like highlight, no command line needed.

Flag

Reveal flag

picoCTF{beep_boop_im_in_...}

Decode the SSTV audio transmission with an SSTV decoder such as QSSTV to reveal the image containing the flag. The flag is shown abbreviated on this page; work the steps above to recover the full value.

Key takeaway

SSTV encodes an image as audio, mapping pixel brightness to frequencies swept over time, so a visual payload hides completely from anyone expecting ordinary sound. Hiding data in an unexpected medium runs all through forensics CTFs: images in audio spectrograms, text in packet timing, files bolted on after a JPEG end-of-image marker. Spotting the SSTV chirp, or any covert channel, comes down to knowing what the legitimate encoding sounds like.

Related reading

Useful tools for Forensics

Where to go next