Pages:
Author

Topic: The Legend of Satoshi Nakamato, FINAL STEP PUBLISHED.... 4.87 BTC GRAND PRIZE! - page 71. (Read 108519 times)

legendary
Activity: 1904
Merit: 1074
Last time, I got into this.. I went without sleep for 3 days.

And got "nada" out of it. People should apply to take part in a group, and vetted to see, if they could contribute. In the end the bounty, should be shared amongst the group, based on a "shares" system. {The more you solve, the more shares you get from the bounty}

This thing of participating and getting nothing, just do not work for me, I'd rather go play the lottery.
full member
Activity: 154
Merit: 100
I've tried the barcode approach for about an hour, but haven't found anything that resembles barcode start/stop markers at the correct distance.

The image also appears quite wide for an bar code.

If you look closely the image also has some blue and purple in it. Perhaps that is part of the solution. edit: that's probably jpeg artifacts...

Can we at least get an png version of the image? Wink
member
Activity: 67
Merit: 11
Great stuff from mirth23, frisco, micaman, dpc123 and many others working in the background.
member
Activity: 112
Merit: 10
an excursion from _

consider the following:
* the unusual _ marks in the security realm from whit3r4bbi7.com (and follow-up hint with _'s)
* #GTIN in @WHIT3R4BBI7's twitter account
* the unusual distorted-barcode background in @x1010fox's twitter account

These might be a hint that part of the user/password combination is from a barcode. _ is sometimes called a 'bar', GTIN is an inventory numbering format associated with barcodes, and we seem to have a hidden barcode in a suspicious twitter profile:



Tangentially, I suspect @x10101fox is a game account. We got the snow app hint from this account, with little activity before or afterwards. On top of that, "fox" seems consistent with the "hunter" in the poem. Also, an early reddit link to the game that went largely ignored was from "bitcoinfox" (credit to rock_collector for that last one). Also, its name is "Ruse". Anyway.

An artist-friend of mine has been trying to clean up the barcode. It looks compellingly close to readable but we haven't gotten a number out of it yet. Example attempts:


Hopefully this isn't totally off-base, but it seemed like something to think about regarding _.

On a side note, over ten-thousand brute-force password attempts from TRON and Alice and Wonderland have been made against http://whit3r4bbi7.com, with no success that I am aware of. All words have been turned into 347-style leet, normal leet, had underscores added, and so on. Reindeer Flotilla, ho!
member
Activity: 112
Merit: 10
The chess grid is an interesting idea. I was playing with it at one point (I also thought about 'game grid'), but I couldn't figure out how to cleanly create a board. There's a number of uncertainties - should we include the origin block, should we include the text block, why are there weird separators, etc. (Incidentally, I played with the idea of including the hint text block as a starting point to 'follow' from.) Then there would be the question of what pieces are represented by the x's, which seems pretty limited from the perspective of chess. I'd love to know if the two unusual separators you picked out are intentional or not. My guess would be that they are intentional. No reasonable way of building a board corresponds with the chess game from Alice Though the Looking Glass. I also feel that the '347' at the end seems to pretty clearly hint that it's a series since the 3rd 4th and 7th spaces have xs.

I was also trying to see if I could infer a GTIN code out of the OP and it seems like there's too little data to build any sort of legit bar code out of it.

I think we're getting a hint that _ is important to get to the next step. But I've been trying user/pass combos with _'s in them and haven't come up with the right one yet.
newbie
Activity: 10
Merit: 0
@TR3N47Y has changed it's twitter background and image.
http://shadowtuga.deviantart.com/art/The-Surreal-140164421 (The surreal)

No_clues_on_twitter,_just_having_fun...  Roll Eyes

full member
Activity: 176
Merit: 100
@TR3N47Y has changed it's twitter background and image.

The new avatar comes from: http://the--kyza.deviantart.com/art/Revival-276924026 titled Revival
The new background comes from: http://dani-owergoor.deviantart.com/art/Chess-305880710 titled Chess

The cite from the login also says grid, so I started thinking about where can we use a chess board, and I think it has to do with the first message and the X.

Reviewing the original messaga as a chess board 8x8 we get:
Code:
-=[O]=-=[ ]=-=[ ]=-=[x]=-=[x]=-=[ ]=-=[ ]=-=[x]=
-=[ ]=-=[x]=-=[ ]=-=[ ]=-=[x]=-=[ ]=-=[ ]=-=[ ]=
-=[x]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=
-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[x]=-=[ ]=
-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[x]=-=[ ]=-=[ ]=
-=[ ]=-=[ ]=-=[ ]=-=[x]=-=[ ]=-=[ ]E-=[M]=-=[ ]=
-=[x]=-=[ ]=-=[ ]=-=[x]=-=[ ]=-=[ ]=-=[ ]=-=[x]=
-=[ ]=-=[ ]=-=[ ]=-=[x]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=
-=[ ]=-E[x]=-=[ ]=-=[-]=-=[3]=-=[4]=-=[7]=-=[ ?
O = Origin Block
M = Message
E = Error in separators
? = Missing close square bracket

The only way to make it fit in a 8x8 grid is removing 8 blocks, the part since the last error seems to be a signature so make sense to remove it, also the M block is preceded by an error (¿false satoshi?) so maybe thats the other one we should remove, that leaves us with:
Code:
-=[O]=-=[ ]=-=[ ]=-=[x]=-=[x]=-=[ ]=-=[ ]=-=[x]=
-=[ ]=-=[x]=-=[ ]=-=[ ]=-=[x]=-=[ ]=-=[ ]=-=[ ]=
-=[x]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=
-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[x]=-=[ ]=
-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[x]=-=[ ]=-=[ ]=
-=[ ]=-=[ ]=-=[ ]=-=[x]=-=[ ]=-=[ ]=-=[ ]=-=[x]=
-=[ ]=-=[ ]=-=[x]=-=[ ]=-=[ ]=-=[ ]=-=[x]=-=[ ]=
-=[ ]=-=[ ]=-=[x]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=-=[ ]=

In a chess board it could be like this:

It can also translated to binary:
10011001
01001000
10000000
00000010
00000100
00010001
00100010
00100000

The origin block being the top left square of the board makes me think that there is no need to rotate to get the information, but I can no see how we can get some key or number to continue going down the rabbit hole.

EDIT:
Ok, he has updated again the profile now it has:
http://www.agiaco.net/The-Waiting-Place (The waiting place)
http://shadowtuga.deviantart.com/art/The-Surreal-140164421 (The surreal)

Anyway the chess board is present also in this new pictures I dom't think it is casual.

Another update:
The image now is the cover of "Moving forward" https://www.youtube.com/watch?v=zr9R7B885-Y
sr. member
Activity: 345
Merit: 500
Here's a tip for pursuing rabbits: https://www.youtube.com/watch?v=LMEmBp9MnIY

Anyone get put on the game grid yet?
Even if we get all the coloured rabbits removed, there are more than 1 white rabbit, that's why this is hard...
member
Activity: 112
Merit: 10
Here's a tip for pursuing rabbits: https://www.youtube.com/watch?v=LMEmBp9MnIY

Anyone get put on the game grid yet?
member
Activity: 112
Merit: 10
We've hammered on the server with a few thousand TRON and 347 poem-related username/password combinations with no luck yet. We're either overlooking something really obvious, or we haven't noticed a clue. Time for me to step away for a while and come back with fresh eyes.
newbie
Activity: 5
Merit: 0
“I'm_going_to_have_to_put_you_on_the_game_grid”!

http://[Suspicious link removed]/nra6fkl  *edit* //tinyurl dot com/  This takes you to a Conway's Game of Life Simulator that starts with the image from @WHIT3R4BBI7  *end edit*

Could stepping through at 3,4,7... reveal something?  
I wish I had more time to play.  I'm late.  
member
Activity: 112
Merit: 10
My ideas:
 + GTIN is a product/package number there is a search engine for registered GTINs at: http://gepir.gs1.org/v32/xx/gtin.aspx?Lang=en-US
 + GTIN sizes can be 8, 12, 13 or 14 digits
 + 192186242104 is a valid GTIB without information

Cool. I guess they look like standard barcodes so we should be on the look out. I got a hit when I searched on 'GTIN white rabbit' but it doesn't seem particularly noteworthy.

Quote
+ www.whit3r4bbi7.com has the Mysql port open which is rather strange, also FTP and SSL ports are open

It's hard to tell whether those ports are open for whit3r4bbi7.com or another site because it's behind some kind of proxy. Looks like a shared hosting situation. It's also possible to get to the cpanel admin login for the site, but that's probably outside the bounds of the puzzle.

Quote
+ Going to http://www.whit3r4bbi7.com:443/ renders a error message but the server name seems to be "sharedip-192186242104.prod.phx3.secureserver.net"

I found that weird error too. Most sites handle http against 443 a little better. If you use https:// it gives you the same name/password.

Quote
+ Image from @whit3r4bbi7 does not seem to fit any know QR format, it is 13x13

Yeah, QRs need those circular boxes in order to line up properly.

Quote
+ The X in the first hint maybe mark a long number where each digit is the number of spaces between X that whould give the sequence:
 2/3 - 0 - 2 - 1 -2 - 3 -13 - 6 - 5 - 4/(2-1) - 2 - 3 - 3 - 5 - 1

Interesting idea. Someone had noted earlier that the first x's are 3,4,7 ... so it might be an integer sequence based on the x's.

@PO347 recently tweeted: "Compete to be 1347!"

I feel like we're missing a clue for the username and password. Or that tweet is a clue that I need to figure out. Still trying some things but it's kinda brute-forceish at the moment.
full member
Activity: 176
Merit: 100
My ideas:
 + GTIN is a product/package number there is a search engine for registered GTINs at: http://gepir.gs1.org/v32/xx/gtin.aspx?Lang=en-US
 + GTIN sizes can be 8, 12, 13 or 14 digits
 + www.whit3r4bbi7.com has the Mysql port open which is rather strange, also FTP and SSL ports are open
 + Going to http://www.whit3r4bbi7.com:443/ renders a error message but the server name seems to be "sharedip-192186242104.prod.phx3.secureserver.net"
 + 192186242104 is a valid GTIB without information
 + Image from @whit3r4bbi7 does not seem to fit any know QR format, it is 13x13
 + The X in the first hint maybe mark a long number where each digit is the number of spaces between X that whould give the sequence:
 2/3 - 0 - 2 - 1 -2 - 3 -13 - 6 - 5 - 4/(2-1) - 2 - 3 - 3 - 5 - 1
member
Activity: 112
Merit: 10
Here's how the next two solves worked. I won't spoil keys if people want to play along. Both keys are pretty straightforward if you follow the clues.

1) Apply the http://www.darkside.com.au/snow/ tool to the poem+whitespace you get from running b58decode_check on the poem. Make sure to strip the extra hex '00' characters first. There is a key. This will result in a base64 representation of a Crypto-JS CipherParams object, which you quickly recognize as such if you have been playing with Crypto-JS. I suspect that people who have been trying to play with snow have ended up with some copy-paste errors when trying to create their file, so here's some python code to show one way to do it successfully:
Code:
import base58
codelist = ('18hJpcE7w51A7GpMU4QkVk1h5V6Ryj61XK', '1BRsa17vaULT26ZNViz1d4Fyjhxgfig77k', '1qFZqzT8jEMPiaHap7qwop3UGrsMWetQ6', '13xGwVghnbk7A9ZSVq18Hk5WDgaqnVAwiU', ...)
poem = ''
for c in codelist:
  poem = poem +(str(base58.b58decode_check(c)).translate(None,'\x00'))
f = open("poem.txt", "w")
f.write(poem)
f.close()
Note that you might need to 'pip install base58' if you don't have it already.

I ran snow from the command-line on the output from the above snippet:
Code:
./snow -C -p KEY poem.txt

2) Apply the Crypto-JS.Rabbit algorithm to the base64 that snow gave. Salt and iv are NOT needed since they are embedded in the base64. A different key is needed; credit to zonkism for finding it first. You can run this locally by making a simple html code on your local host and directing your browser to it, all you need is the following in the page:
Code:



This results in "http://www.whit3r4bbi7.com/"

This is a website asking for a user/login to the area “I'm_going_to_have_to_put_you_on_the_game_grid”!

next steps:
- There's a lot of user/logins in TRON with many possible variants. I've tried a bunch but have come up empty. Still hammering on that a bit.
- There is a @WHIT3R4BBI7 twitter with "Trust no one. #GTIN" in their profile. GTIN appears to refer to a type of barcode. I can't tell if this twitter account is part of the game or not, it's private unlike all of the other ones.

outstanding weird stuff:
- what do the 'x' marks mean in the OP?
- are there more secrets in the nearby blockchain and related transactions?
member
Activity: 112
Merit: 10
My partner and I are two more steps along. Proof: "I'm_going_to_have_to_put_you_on_the_game_grid"

I'll drop some more hints tomorrow, zzzzz.

Following Twitter and after some test it is clear that there is a Base64 encoded cryptogram hidden in the white spaces using:
http://www.darkside.com.au/snow/

This is correct. Credit to @x1010fox on twitter for finding snow in the first place.

Actual zzzz for me, now. Smiley
full member
Activity: 176
Merit: 100
My partner and I are two more steps along. Proof: "I'm_going_to_have_to_put_you_on_the_game_grid"

I'll drop some more hints tomorrow, zzzzz.

Following Twitter and after some test it is clear that there is a Base64 encoded cryptogram hidden in the white spaces using:
http://www.darkside.com.au/snow/

Just need to execute it: (I have uploaded original.txt to: http://pastebin.com/JmjWbDuk)
SNOW.EXE -C -p XXXX original.txt

To see random text changing the password, I have tried a lot of them but haven't found the correct one.



member
Activity: 112
Merit: 10
My partner and I are two more steps along. Proof: "I'm_going_to_have_to_put_you_on_the_game_grid"

I'll drop some more hints tomorrow, zzzzz.
member
Activity: 67
Merit: 11
hmmm, I feel the rumblings of something about to explode...

sr. member
Activity: 345
Merit: 500
"These are op-codes that tell the interpreter to put a specific amount of bytes to the stack. "
https://en.bitcoin.it/wiki/Script#Constants
member
Activity: 67
Merit: 11
Pages:
Jump to: