<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Walkthrough on Bobby's Headspace</title><link>https://blogs.bobbysmiles.xyz/tags/walkthrough/</link><description>Recent content in Walkthrough on Bobby's Headspace</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><managingEditor>smiles@bobbysmiles.xyz (Bobby Smiles)</managingEditor><webMaster>smiles@bobbysmiles.xyz (Bobby Smiles)</webMaster><lastBuildDate>Fri, 09 May 2025 22:23:16 +0530</lastBuildDate><atom:link href="https://blogs.bobbysmiles.xyz/tags/walkthrough/index.xml" rel="self" type="application/rss+xml"/><item><title>Bellingcat Open Source Challenge: Back In Time - Walkthrough</title><link>https://blogs.bobbysmiles.xyz/posts/cbc_back_in_time/</link><pubDate>Fri, 09 May 2025 22:23:16 +0530</pubDate><author>smiles@bobbysmiles.xyz (Bobby Smiles)</author><guid>https://blogs.bobbysmiles.xyz/posts/cbc_back_in_time/</guid><description>&lt;h1 id="bellingcat---back-in-time-walkthroughs"&gt;Bellingcat - Back In Time walkthroughs&lt;/h1&gt;
&lt;p&gt;Bellingcat recently released their &lt;code&gt;Back In Time&lt;/code&gt; series of challenges authored by &lt;a href="https://gralhix.com/list-of-osint-exercises/"&gt;Sofia Santos&lt;/a&gt;. I had a lot of fun solving these and I hope you did too. Here&amp;rsquo;s a walkthrough of how I tackled each of these challenges.&lt;/p&gt;
&lt;p&gt;Hope you learn through these walkthroughs as much as I did solving these challenges.&lt;/p&gt;
&lt;h2 id="fresh-faced-finding-the-founder"&gt;Fresh Faced: Finding the Founder&lt;/h2&gt;
&lt;figure class="center" &gt;
&lt;img src="https://challenge.bellingcat.com/assets/Sofia_Santos_1-BplhodW_.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Problem Image&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;So the question tells us that the founder of Bellingcat, Eliot Higgins, was featured on many news outlets for his groundbreaking discoveries in the year 2013. We need to find the YouTube video from which the newspaper clipping was taken.&lt;/p&gt;</description><content>&lt;h1 id="bellingcat---back-in-time-walkthroughs"&gt;Bellingcat - Back In Time walkthroughs&lt;/h1&gt;
&lt;p&gt;Bellingcat recently released their &lt;code&gt;Back In Time&lt;/code&gt; series of challenges authored by &lt;a href="https://gralhix.com/list-of-osint-exercises/"&gt;Sofia Santos&lt;/a&gt;. I had a lot of fun solving these and I hope you did too. Here&amp;rsquo;s a walkthrough of how I tackled each of these challenges.&lt;/p&gt;
&lt;p&gt;Hope you learn through these walkthroughs as much as I did solving these challenges.&lt;/p&gt;
&lt;h2 id="fresh-faced-finding-the-founder"&gt;Fresh Faced: Finding the Founder&lt;/h2&gt;
&lt;figure class="center" &gt;
&lt;img src="https://challenge.bellingcat.com/assets/Sofia_Santos_1-BplhodW_.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Problem Image&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;So the question tells us that the founder of Bellingcat, Eliot Higgins, was featured on many news outlets for his groundbreaking discoveries in the year 2013. We need to find the YouTube video from which the newspaper clipping was taken.&lt;/p&gt;
&lt;p&gt;The first and most obvious lead we have is the caption in the image. Let&amp;rsquo;s put this into &lt;a href="https://translate.google.com/?sl=auto&amp;amp;tl=en&amp;amp;op=translate"&gt;Google Translate&lt;/a&gt; to see what language it is.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss1.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Google translate for the caption in the image&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;We can see that the language was detected as &lt;strong&gt;Croatian&lt;/strong&gt;. Now from here, I didn&amp;rsquo;t find any leads, so I looked into the &lt;a href="https://en.wikipedia.org/wiki/Eliot_Higgins"&gt;Wikipedia page on Eliot Higgins&lt;/a&gt;. Reading this page, we can see that Wikipedia mentions some &lt;a href="https://brown-moses.blogspot.com/2013/04/the-brown-moses-blog-fundraiser-launches.html"&gt;non-English sources&lt;/a&gt;. Let&amp;rsquo;s check this page out and see what&amp;rsquo;s in it&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss2.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Non-English sources listed in brown-moses&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Over here, we can see a &lt;a href="https://www.vecernji.hr/vijesti/kako-sam-otkrio-da-hrvati-salju-oruzje-u-siriju-532428"&gt;Croatian news article&lt;/a&gt;, which aligns with our earlier finding of the language on the news clipping. The site didn&amp;rsquo;t contain any sort of link to a YouTube video, just the same picture as we were given in the question.&lt;/p&gt;
&lt;p&gt;So the next thing I did was to check the journalist who interviewed Eliot Higgins. His name was &lt;strong&gt;Tomislav Krasnec&lt;/strong&gt;. So I just searched &lt;code&gt;Tomislav Krasnec Eliot Higgins&lt;/code&gt; in the Google videos section and got the interview.&lt;/p&gt;
&lt;p&gt;The answer is simply the video code.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss3.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Search result for Tomislav Krasnec's interview with Higgins&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;hr&gt;
&lt;h2 id="training-time-theres-a-lot-to-learn"&gt;Training Time: There&amp;rsquo;s a lot to learn.&lt;/h2&gt;
&lt;figure class="center" &gt;
&lt;img src="https://challenge.bellingcat.com/assets/Sofia_Santos_2-BWtvTpYQ.jpeg" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Problem Image&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;So we&amp;rsquo;re asked to do some cool indoor geolocation on this image. We have to find the room in which this picture was taken. Another hint is that the image is credited to &lt;strong&gt;ARIJ network&lt;/strong&gt;. We are also told that this workshop was conducted in 2017 so that&amp;rsquo;s gonna be a cool lead as well.&lt;/p&gt;
&lt;p&gt;So just googling, &lt;code&gt;Christiaan Triebert Workshop 2017&lt;/code&gt; yielded this &lt;a href="https://x.com/trbrtc/status/928688231549423616"&gt;post&lt;/a&gt; on X.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss4.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Searching for Christiaan Higgins workshop in 2017&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;This didn&amp;rsquo;t give much information. So instead I tried using Google Dorks to find the workshop.&lt;/p&gt;
&lt;p&gt;By Google dorking this &lt;code&gt;intext:&amp;quot;December&amp;quot; intext:&amp;quot;2017&amp;quot; intext:&amp;quot;Christiaan Triebert&amp;quot; intext:&amp;quot;workshop&amp;quot;&lt;/code&gt; I found that the event was &lt;em&gt;ARIJ 10th Annual Forum&lt;/em&gt; and in their website we had an address of &lt;strong&gt;Mövenpick Resort &amp;amp; Spa Dead Sea | Dead Sea Road, 11180&lt;/strong&gt;&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss5.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;https://arij10thannualforum2017.sched.com/list/simple&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;So from finding this I looked at the rooms available in the hotel in this &lt;a href="https://movenpick.accor.com/en/middle-east/jordan/dead-sea/resort-dead-sea/meeting-rooms.html"&gt;part&lt;/a&gt; of their website. Through that I found the answer to be &lt;code&gt;The Grand Ball room&lt;/code&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="creating-community-a-new-place-to-connect"&gt;Creating Community: A new place to connect.&lt;/h2&gt;
&lt;figure class="center" &gt;
&lt;img src="https://challenge.bellingcat.com/assets/Sofia_Santos_3-B0DbysB3.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Problem Image&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Ok, so here we will have to do a &lt;em&gt;&lt;strong&gt;little&lt;/strong&gt;&lt;/em&gt; bit of scripting, nothing too complicated, just some copying and pasting.&lt;/p&gt;
&lt;p&gt;By just using this Google dork &lt;code&gt;intext:'We finally got around to creating a bellingcat Discord server&amp;quot;&lt;/code&gt; we can find the &lt;a href="https://x.com/bellingcat/status/1260211332437213184?lang=en"&gt;post&lt;/a&gt; on X. get this time: &lt;code&gt;7:42 PM · May 12, 2020&lt;/code&gt;. Note that this time will be displayed differently based on what timezone you fall under.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss6.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Twitter post containing the bellingcat server announcement&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;So once I found the post, I joined the Discord and used this &lt;a href="https://www.reddit.com/r/discordapp/comments/5wl8ny/how_to_find_the_age_of_your_server/"&gt;method&lt;/a&gt; to get the age of the server.&lt;/p&gt;
&lt;p&gt;So, this method has the following steps:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Enable developer mode on your Discord.&lt;/li&gt;
&lt;li&gt;Open Discord in your browser and open the Inspector tab on your browser.&lt;/li&gt;
&lt;li&gt;Paste the following code snippet in your browser.&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-javascript" data-lang="javascript"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#66d9ef"&gt;new&lt;/span&gt; Date(&lt;span style="color:#e6db74"&gt;&amp;#34;709752884257882135&amp;#34;&lt;/span&gt;&lt;span style="color:#f92672"&gt;/&lt;/span&gt;&lt;span style="color:#ae81ff"&gt;4194304&lt;/span&gt;) &lt;span style="color:#f92672"&gt;+&lt;/span&gt; &lt;span style="color:#ae81ff"&gt;1420070400000&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss7.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Result of the js code&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;This gives us this timestamp: &lt;code&gt;Tue May 13 1975 18:34:34 GMT+0530 (India Standard Time)1420070400000&lt;/code&gt;
Now, this will be different according to your timezone, but on doing the math we get the time to be 68.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="future-plans-a-timely-document"&gt;Future Plans: A timely document.&lt;/h2&gt;
&lt;p&gt;So we&amp;rsquo;re told that Bellingcat published a document nearly 2 years after they registered.&lt;/p&gt;
&lt;p&gt;So I found the pdf by using this Google Dork: &lt;code&gt;intext:&amp;quot;bellingcat&amp;quot; intext:&amp;quot;future plans&amp;quot;&lt;/code&gt;. Since bellingcat was registered in 2018, it tracks that this &lt;a href="https://www.bellingcat.com/app/uploads/2020/06/Bellingcat-Policy-Plan-2019-2021.pdf"&gt;result&lt;/a&gt; was the right one.&lt;/p&gt;
&lt;p&gt;Now there is no author explicitly listed in the pdf, neither do I wanna read the whole pdf. So, I decided to take a look at the &lt;a href="https://www.pdfyeah.com/view-pdf-metadata/"&gt;pdf metadata&lt;/a&gt;, which revealed that the author was &lt;strong&gt;Aric Toler&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Great, so we have one part of the challenge solved. Now let&amp;rsquo;s see if we can get all the articles he published around 2019-2020.&lt;/p&gt;
&lt;p&gt;So on searching &lt;code&gt;bellingcat.com aric toler&lt;/code&gt; I found this &lt;a href="https://www.bellingcat.com/author/arictoler/"&gt;link&lt;/a&gt;. I scoured every article until I got &lt;a href="https://www.bellingcat.com/resources/how-tos/2020/04/15/how-not-to-report-on-russian-disinformation/"&gt;this one&lt;/a&gt;. The last word of this article is the answer.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="toolkit-tracing-tool-tips-new-and-old"&gt;Toolkit Tracing: Tool tips new and old.&lt;/h2&gt;
&lt;p&gt;This was the easiest question of this release. We are asked to find a missing document in an older edition of the Bellingcat Online Investigations toolkit released in the year 2020.&lt;/p&gt;
&lt;p&gt;I used this Google dork to search it up: &lt;code&gt;intext:&amp;quot;Guides &amp;amp; Handbooks&amp;quot; intext:&amp;quot;2020&amp;quot; intext:&amp;quot;Bellingcat&amp;quot;&lt;/code&gt;&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss8.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Result of the Google dork&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;You can find the actual document mentioned in the question &lt;a href="https://p.avmedianow.com/b/e/bellingcat-s-online-investigation-toolkit-242.pdf"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In this document, in the &lt;code&gt;Guides &amp;amp; Handbooks&lt;/code&gt; section, you can find this &lt;a href="https://docs.unocha.org/sites/dms/Documents/FEAT_Version_1.1.pdf"&gt;document&lt;/a&gt;. As it turns out, it is inaccessible. So the obvious first step was to simply check for a snapshot of this document in the &lt;a href="https://web.archive.org/"&gt;WayBack Machine&lt;/a&gt;.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss9.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Result of the wayback machine search&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Once I got to the wayback machine, I simply entered the URL and voila! there it was. So we&amp;rsquo;ll simply navigate to page 39 of the document and get the first hazard listed.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Hope you found this as useful as I did.&lt;/p&gt;
&lt;p&gt;Have a nice day! :)&lt;/p&gt;</content></item></channel></rss>