Rating: 5.0

## Open-Source Intelligence/Personal Breach (173 solves)
Created by: `Lychi`

> Security questions can be solved by reconnaissance. The weakest link in security could be the people around you.

We are looking for the following information points about Iris:
- How old is Iris?
- What hospital was Iris born in?
- What company does Iris work for?

Looking through what we have, in the tagged posts section of Michelangelo's Instagram is a post!

![Post tagging Michelangelo](https://seall.dev/images/ctfs/irisctf2024/pb_1.png)

It's from Iris, we can now look through her Instagram.

![Iris's Instagram](https://seall.dev/images/ctfs/irisctf2024/pb_2.png)

Looking through her posts, a particular one jumps out at me:

![Post mentioning mother](https://seall.dev/images/ctfs/irisctf2024/pb_3.png)

We can see she mentions an `Elaina Stein` and trying to visit an Instagram with that tag fails, so I check Facebook and get a hit!

![Elaina's Facebook](https://seall.dev/images/ctfs/irisctf2024/pb_4.png)

Looking through her posts, we find two birthdays. One for herself (8th of April 1965) and for Iris (27th of April 1996).

We now know Iris's age to be `27`.

In the comments of the birthday post is Elaina with some extra information.

![Facebook Comment](https://seall.dev/images/ctfs/irisctf2024/pb_5.png)

By searching for the exact phrase "best maternity hospital in Manhattan" we get a hit on [Yelp](https://www.yelp.com/search?find_desc=maternity+hospital&find_loc=Manhattan%2C+NY).

Our top result is `Lenox Hill Hospital`, so there's our hospital.

![Hospital Review](https://seall.dev/images/ctfs/irisctf2024/pb_6.png)

Looking up Iris's name online we also get a [LinkedIn](https://www.yelp.com/search?find_desc=maternity+hospital&find_loc=Manhattan%2C+NY).

![LinkedIn for Iris](https://seall.dev/images/ctfs/irisctf2024/pb_7.png)

And there's her job! `Mountain Peak Hiring Agency`

![Submission of answers](https://seall.dev/images/ctfs/irisctf2024/pb_8.png)

There we go!

Flag: `irisctf{s0c1al_m3d1a_1s_an_1nf3cti0n}`

**Files:** None provided :(

Original writeup (https://seall.dev/posts/irisctf2024/#open-source-intelligencepersonal-breach-173-solves).