Jump to content

winter_soldier

Active Members
  • Posts

    31
  • Joined

  • Last visited

  • Days Won

    1

Posts posted by winter_soldier

  1. ICS on El Capitan

    Using the script here as a base : https://github.com/TGYK/OSXwp5

    I had to change a couple of strings:

    1) 1010* to 1011* to reference El Capitan

    2) Change gateway IP to 172.16.42.2 (as 172.16.42.42 is already assigned to the USB interface)

    3) Not using ethernet en0, the USB adapter ended up as en9 (I have many usb-adapters and BeagleBones), yours could be different. You'll have to identify your own interface (ifconfig) and adjust the script accordingly.

    Script is here: http://pastebin.com/jPjD74Q0

    I'm a bit lazy, many improvements could be made to this script to make it more user friendly.

    Also full credit to TGYK.

  2. DNS record leaks (PGP encrypted string):

    jA0EAwMCR4rsFW7OYnJgyTYgOMqT0htXuyDC6YSNbGEFmVNvAIABbed9WriSNxYp

    eGIuL5mQmFTLc+ya1ShLK7n1MuPlx1I=

    =qjs4

    Which is encrypted with a popular key phrase (eef5204d6a) = 37.920487, -122.382049 (believe its the geo-caching location)

    Coin:

    Babylonian Numerals (with the media 360 degrees, 60 seconds clue), are actually the position of the hands on the two clocks (as their very small), the location of the clocks within the 360 degrees give you degree references - ascension and declination; now you have a location: 38° 14' 5" , 122° 38' 33"

    This location is related with the message at the top of the coin and eff5204d6a - here you need the twitter key (hsmjexsafkvotkthdbabpktkcwuoabmikdfvkstyhcnvqqke) to translate the hint on eff5204d6a, which in turn will change and solve the message on the coin:

    ZWP '/QWAOE/MCYKB'/C - SED '/HSDWE/HSDWI'/S

    HSDWE OZORZNCG YGL WXO GDEK - - AARNA RHOMPSON ONE TWO FOUR

    sed is a linux substitution tool, so it change the message to:

    HSDWI OZORZNCG YGL WXO GDEK - AARNA THOMPSON ONE TWO FOUR

    References "Three little pigs"

    which is helpful when combined with the location; snubs previously posted this though : http://instagram.com/p/TgmdNZDOXP/#

    which is what it is hinting to.

    No luck translating the openssl encrypted string on reverse, the font is quite bad, and some numbers / letters look identical not sure if I have the right crypto text :(, but base-64 decoding you get a "salted__" string - typical of openssl encryption.

    Next the domain.com hint = the numbers on the edge of the coin, some look like zips on Darren's travels - others are not ; some are ports on darknet.hak5.org, another tweet translated from domain.com (with the twitter key) = OPENGATE

    No longer available but someone previous hinted:

    $nc 66.23.225.214 23185

    80 degrees. 5412 Horan Ct. //MP: WT, AB, HH, JG, ML, SM, RF, CG, WC

    This is from the numbers 5412 23185 which are adjacent on the coin at approx 80° one is a ZIP that represents the old Hak house (where it all began?). Hence the 5412 Horan Ct bit.

    After that it looks like a playfair cipher? but I haven't found the key?

    ------

    So need I help with the, openssl on the reverse on the coin, and the 80° puzzle...

×
×
  • Create New...