Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
some guy signed up on SA to spam what is presumably an ARG:

https://forums.somethingawful.com/showthread.php?threadid=3894591
https://forums.somethingawful.com/showthread.php?threadid=3750534&pagenumber=209&perpage=40#post496949575
https://forums.somethingawful.com/showthread.php?threadid=3846107&pagenumber=265&perpage=40#post496949682
etc

don't know if there's already a thread so i'll post progress here

---

the "missing" poster in the spammed post has a github repo url in it:
https://github.com/saphirecalypso/F2D64AD97033074E

forums poster cZk got the first stage
https://forums.somethingawful.com/showthread.php?threadid=3894591#post496950300



that red text is the ISBN of TCP/IP Illustrated and a ref to a specific diagram in it


the name of the repo, F2D64AD97033074E, turns up this vid with the same name on youtube
https://www.youtube.com/watch?v=qj8uYBbUvQk
video description is "you have made it half way."

the same account also uploaded this video "OPAL JADE 3"
https://www.youtube.com/watch?v=qweD28f4hpw
video description is "C79A43F5E5E8E988"

the gihub repo also contains two EC private keys:
https://github.com/saphirecalypso/F2D64AD97033074E/blob/master/POTATOES
and a file with a hint that it's "AES256":
https://github.com/saphirecalypso/F2D64AD97033074E/blob/master/MEAT

---
i'll make the wiki

Adbot
ADBOT LOVES YOU

OldAlias
Nov 2, 2013

:firstpost:

Sirotan
Oct 17, 2006

Sirotan is a seal.


oh kewl you saved me the anxiety of trying to figure out where to post this thread

here's what I've found thus far:

youtube video has some SSTV auto, which translates to


here's that site: http://45.55.24.10/chocolateWonder.msf

currently trying to figure out what the username is supposed to be

related to this??? https://github.com/saphirecalypso/F2D64AD97033074E/blob/master/MEAT

Sirotan
Oct 17, 2006

Sirotan is a seal.


p.s. the hangul on the missing poster translates to "Let's play....reality games"

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
good poo poo op

TOOT BOOT
May 25, 2010

real life in 2019 is an alternate reality game

Sham bam bamina!
Nov 6, 2012

ƨtupid cat
gas

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

main page of that site has a link to this file http://45.55.24.10/mitmcert.cer

this looks at first glance to be a normal local mitmproxy CA. unsure of relevance if any

theres also 3 exe's linked

"LittleTornado.exe HDD/SSD nuker"
"NT8-PWGrabber.exe ntlm hash grabber"
"JADEOPAL.exe pwrsh revsh hits NY C&C cluster"

ptr record for that ip is em-attack.com fwiw

Rufus Ping fucked around with this message at 02:50 on Jul 24, 2019

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

if you go to the main page of the url in this file, there's a hidden link at the bottom of that page to http://purplewaterbottle.com/rainbowkitten/lander.php

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
rooting around also reveals 3 supposed openvpn config files, apparently for commercial vpn provider IVPN

http://purplewaterbottle.com/rainbowkitten/Filez/DANGER/

Sirotan
Oct 17, 2006

Sirotan is a seal.


Rufus Ping posted:

if you go to the main page of the url in this file, there's a hidden link at the bottom of that page to http://purplewaterbottle.com/rainbowkitten/lander.php

nice find! i am trying to figure out the AES bit of the username to log into purplewaterbottle.com/saphirecalypso, but with every ARG i've ever tried to participate on, i totally suck at ciphers

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Sirotan posted:

i am trying to figure out the AES bit of the username to log into purplewaterbottle.com/saphirecalypso

https://github.com/saphirecalypso/F2D64AD97033074E/blob/master/MEAT

aes256 uses a 256 bit (=32 byte =64 hex char) key and potentially a 128 bit (=16 byte =32 hex char) IV

the base64 string in that file is 384 bits, so it could be both concatenated. or something else entirely

what is the ciphertext we're supposed to be decrypting with aes?

i assume the plaintext is then used as the username for the next step

Sirotan
Oct 17, 2006

Sirotan is a seal.


Rufus Ping posted:

https://github.com/saphirecalypso/F2D64AD97033074E/blob/master/MEAT

aes256 uses a 256 bit (=32 byte =64 hex char) key and potentially a 128 bit (=16 byte =32 hex char) IV

the base64 string in that file is 384 bits, so it could be both concatenated. or something else entirely

what is the ciphertext we're supposed to be decrypting with aes?

i assume the plaintext is then used as the username for the next step

that MEAT file used to be this, two days ago:

quote:

So now about it. I am son to sing what his father island or foul, your loom, she was high up in two of his dead close took her side of him."

And Minerva said, "you talking; but I should you choose to decide with the waste themselves offered much by sea-king Phorcys; there them.

The suitors of his in days of his dear a prisoner among up great and hung it to the one looking fellow, I want to their pleasure. This feast of all these suitors this houses, turn about things to this way) some other righteously they would send of my longer to the many other glittle about, at the country, was dead and earth, not along will not be chief too if I could any number of his daughter of Jove, and wide after of Jove, from when to bear you will but many a beauty another gods:

Now Neptune by the nation they declared it out for the spear and will manner of Polyphemus king by two of he had given him about omens, for any present he were came in question, so story.

related???

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
as for the password,

https://pastebin.com/6pr5Trsd posted:

a = [They are classed as biologically unacceptable, a menace to the pristine heredity of the race. Once pegged as special, a citizen, even if accepting sterilization, dropped out of history. He ceased, in effect, to be part of mankind.]

b = [For pure will, unassuaged of purpose, delivered from the lust of result, is every way perfect. Every man and every woman is a star.]

M = 13 digit code(a) <!-- //DELishusRAYcast1984 -->
N = 13 digit code(b) <!-- //HeferWEISER1987 -->

CONCAT(M,N) = next pass

questions:

- what hash function outputs 13-digit (decimal digit? hex digit?) codes
- what are those comments for

Sirotan
Oct 17, 2006

Sirotan is a seal.


they are quotes from literary passages. First is from Blade Runner. second is from whatever the gently caress this is: http://lib.oto-usa.org/libri/liber0002.html

think a is probably bladerunner and b is mastertherion

Sirotan
Oct 17, 2006

Sirotan is a seal.


those fuckers are mocking us now

quote:

Sneaking about, yet not going far.
Stay on task, dont stray from the yard.
Look up the codes, dont enumerate the sites.
Enumeration comes next round, sandboxes in sight.

Oh goons...
And twitter is so much faster than you.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
<br><BR><!-- atleast youre faster than imgur... they have had a head start -->

lol

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
uhh don't know if this is meant for us or someone else but

http://purplewaterbottle.com/rainbowkitten/Filez/files.php

The AES KEY IS:
enoovgUbyr_2019 jaqiqkLqlp_2019
Keep up the excellent work. We are proud of your endevours. Virgenereire key = saphirecalypso

Sirotan
Oct 17, 2006

Sirotan is a seal.


Rufus Ping posted:

uhh don't know if this is meant for us or someone else but

http://purplewaterbottle.com/rainbowkitten/Filez/files.php

The AES KEY IS:
enoovgUbyr_2019 jaqiqkLqlp_2019
Keep up the excellent work. We are proud of your endevours. Virgenereire key = saphirecalypso

they just updated it so I guess so!

Sirotan
Oct 17, 2006

Sirotan is a seal.


hi ARG creators, ARGs are cool and your efforts are appreciated even if i am too dense to solve it

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
thank you, i hate it

Sirotan
Oct 17, 2006

Sirotan is a seal.


hmm ok the AES keys are now listed as enoovgUbyr_2018 jaqiqkLqlp_2018 (note 2018, not 2019)

also not sure where a Vigenere [sic] cipher is going to come into play yet, but here is a decoder https://www.dcode.fr/vigenere-cipher

edit: looks like this
enoovgUbyr_2018 => mnzhnpqzyg_2018
jaqiqkLqlp_2018 => rabbithole_2018

Sirotan fucked around with this message at 03:49 on Jul 24, 2019

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
it's 2017 now!

enoovgUbyr_2017 jaqiqkLqlp_2017

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
(it's also php, so might be changing automatically in response to something)

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Sirotan posted:

hmm ok the AES keys are now listed as enoovgUbyr_2018 jaqiqkLqlp_2018 (note 2018, not 2019)

also not sure where a Vigenere [sic] cipher is going to come into play yet, but here is a decoder https://www.dcode.fr/vigenere-cipher

edit: looks like this
enoovgUbyr_2018 => mnzhnpqzyg_2018
jaqiqkLqlp_2018 => rabbithole_2018

the _2018 isn't part of the alphabet used, so i think we can ignore that?

rabbitHole (capital H) looks good

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
enoovgUbyr is just rot13 of the same thing (rabbitHole) lol

hifi
Jul 25, 2012

Ready to decode this and be a part of the trump cyber team

Pollyanna
Mar 5, 2005

Milk's on them.


who cares

Sirotan
Oct 17, 2006

Sirotan is a seal.


Rufus Ping posted:

enoovgUbyr is just rot13 of the same thing (rabbitHole) lol

dang it

Pollyanna
Mar 5, 2005

Milk's on them.


args are never followed up by anything worthwhile

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
13 digit code = the isbn-13 of those books

Sirotan
Oct 17, 2006

Sirotan is a seal.


^^^noice op

image on the github page says "Do not fall for the holes, where rabbits keep their gold.", maybe this is a red herring??

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

cypher-nards

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
hrm it could be. nevertheless:

The Book of the Law - Weiser Books (Reissue edition; May 1987; ISBN 0-87728-334-6)

working on philip k dick one

Sirotan
Oct 17, 2006

Sirotan is a seal.


Do Androids Dream of Electric Sheep? 978-0345404473
The Book of the Law 978-0877283348

op do you concur

Sirotan fucked around with this message at 04:06 on Jul 24, 2019

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
electric sheep 1984 del ray edition is 9780345323880

Sirotan
Oct 17, 2006

Sirotan is a seal.


hrm, might be too many possibilities here

Sirotan
Oct 17, 2006

Sirotan is a seal.


ok I think we were forgetting these clues:

M = 13 digit code(a) <!-- //DELishusRAYcast1984 -->
N = 13 digit code(b) <!-- //HeferWEISER1987 -->

so 1984 versions of the Dick book, and 1987 version of the Crowley book?

edit: jk op it seems you did not forget these...

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
the ones i posted dont work (with username=rabbitHole), need to double check them

Adbot
ADBOT LOVES YOU

Sirotan
Oct 17, 2006

Sirotan is a seal.


so password is 97803453238809780877283348 ?

this does not work with rabbitHole or rabbitHole_2016

edit: could not find a winning combo but now it is time for sleep, goodnight op(s) and i'll pick this up tomorrow

Sirotan fucked around with this message at 04:54 on Jul 24, 2019

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply