RedBalloonShenanigans / MonitorDarkly

Poc, Presentation of Monitor OSD Exploitation, and shenanigans of high quality.
GNU General Public License v3.0
904 stars 135 forks source link

Mr Robot S03e02 brought me here ;) #16

Open Dingo64 opened 6 years ago

Dingo64 commented 6 years ago

Anybody from Mr Robot here?

rinaldi-rahmanda commented 6 years ago

same here lol

0xac commented 6 years ago

I am shamefully behind on watching Mr. Robot. I will stop what I'm doing now and go watch some TV -)

On Thu, Oct 19, 2017 at 4:23 PM, Rinaldi A. Rahmanda < notifications@github.com> wrote:

same here lol

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/RedBalloonShenanigans/MonitorDarkly/issues/16#issuecomment-338026964, or mute the thread https://github.com/notifications/unsubscribe-auth/AF-I3lAul0lwkaIYkhyr6d_rLnFg79ihks5st6-1gaJpZM4P_zh0 .

Dingo64 commented 6 years ago

You really should, they've just made your Github popular!

https://i.imgur.com/HCk7PId.png

Spacefish commented 6 years ago

+1 me too :) but they might change the content on the server where the base64 string is placed!

b.t.w. jBouaqK9R8jXxfpE6kGV ;)

gabriele92 commented 6 years ago

Here from Mr Robot decoding too! :) Loved this easter egg!

Dingo64 commented 6 years ago

@Spacefish I noticed the filename too. Did you decode it already?

Spacefish commented 6 years ago

@Dingo64 no :(, tried different rotational ciphers (ROT1-25), base64 and googled it, but did not find anything. It might just be a random generated string by the tool which generated the QR Code image.

It´s 20 characters and number to character ratio is pretty much normal for a random 62 symbol alphabet (26 lowercase 26 uppercase and 10 digits = 62 symbols)

thought about a hash value as well, it might be a hash for a DHT based bittorent download (magnet link). But there are no hashes which use 20 characters with a 62 symbol alphabet i know of.. SHA1 is typically 160bit and written in 32 characters which contain numbers 0-9 and letters A-Z (no lower uppercase differntiation). MD5 is written in HEX typically SHA256 or SHA2 is way too long..

The 20 character string is too long to be a youtube video identifier.

Dingo64 commented 6 years ago

@Spacefish I tried base64, ROT13 and ROT47. I think it might be a password. Doesn't look like base64 encoded hash because I don't think there is a hash function that returns 120 bits.

Spacefish commented 6 years ago

@Dingo64 updated my comment, i tried different things as well, but i don´t think it´s a hash.. the symbol set does not allow to encode 6 bit per character as there are only 62 symbols, not 64! (26 lower characters 26 upper and 10 digits = 62)

if you analyse the frequency of the different symbols in jBouaqK9R8jXxfpE6kGV each symbol is there only once, this hints at a random string as well, but the string is only 20 characters though!

Dingo64 commented 6 years ago

@Spacefish You are right it can't be typical base 64 but there are variations of base 64 that are fine for filenames: https://en.wikipedia.org/wiki/Base64#Filenames So it can be base 62 but also base 64.

Spacefish commented 6 years ago

@Dingo64 yep that´s true! It might not contain any == padding and no _ or - as the data does not contain them and don´t need padding! Maybe this whole string is just a login for: https://webmail.e-corp-usa.com/owa/index.php as for example Username: retro Password: portal downloads the pdf of elliots presentation 👍

Dingo64 commented 6 years ago

@Spacefish When decoded as base62 it returns 20 E5 D1 5E 85 D5 3F A0 10 1A 58 3E 6A 2C 3C C7. This can be a 128 bit hash of something. But base62 is very rare and Elliot likes long passwords so perhaps just a password to something.

Spacefish commented 6 years ago

@Dingo64 When Elliot logs into his PC counting the stars it´s a 21 character password.. the string we got is 20 characters long :(

Dingo64 commented 6 years ago

@Spacefish If he logs with 21 chars to his PC he can log with 20 chars to something else.

Spacefish commented 6 years ago

B.t..w found this: http://www.e-corp-usa.com/users/072391/ it´s the QR Code on elliots employee card!

haha the adress is 135 E 57th Street, New York, NY 10022, right next to the Trump Tower b.t.w. lol :D

The creators of the series really pay attention to detail! Very nice!

rtkd commented 6 years ago

Now... everybody, back to solving Liber Primus.

Spacefish commented 6 years ago

@rtkd where is my book? But my guess is, that the sequence has no real meaning and is just random. The QR generator generates a random filename for the temp file, that's my guess!

Dingo64 commented 6 years ago

@rtkd Can't now, decoding Voynich manuscript.

rtkd commented 6 years ago

@Spacefish You are literally only one click away.

chrisbog94 commented 6 years ago

I'm here as well. InB4 4chan inb4 reddit

fanick1 commented 6 years ago

wow, one never knows how deep the rabbit hole really goes

evertonmj commented 6 years ago

Whoa! I'm here because of MrRobot also :)

MicTheSquid commented 6 years ago

I am also here because of Mr. Robot. Can anyone ELI5 what this file does?

TteokbokkiNari commented 6 years ago

Haha, fun to see so many people here!

kirgy commented 6 years ago

I thought they'd be more of us! I'm only just catching up on Prime, so I'm a bit late to the game. Soz guys.

mwojt commented 6 years ago

Big respect for the creators of the series

Spacefish commented 6 years ago

Probably a lot of "Nerds/Hipsters" watch the series without a real deep technical understanding of the details (well base64 isn´t that complicated of a thing).. But i guess this is the reason why we don´t see more people here.

While i was studying we had some of these people, they got all the latest "Nerd" gadgets but didn´t know what to do with them.. One guy got an Raspberry Pi a MakerBot and a Ocolus Rift. When asked what he did do with it:

That´s like buying a car because it is cool, without owning a driver licence nor knowing how to use it..

Dingo64 commented 6 years ago

@Spacefish You might be right. However I came here straight after watching the episode and decoding the link but as I noticed some people created a thread on Reddit instead. So maybe others just didn't have a need to post an issue here and thought Reddit is a better place for such discussions. I just hope @0xac isn't mad we are spamming his Github :)

And a note to other fans of Mr. Robot- try not to create any other issues on this Github repo about Mr. Robot as this is very offtop and just post in this issue.

annalisamf commented 6 years ago

Here for Mr Robot too 😉

0xBADCODE commented 6 years ago

Yup Mr Robot brought me here. Anyone work out whether jBouaqK9RjXxfpE6kGV is random?

alessaba commented 6 years ago

The satisfaction is very high 😍

zinoharo commented 6 years ago

what?

On Thu, Nov 9, 2017 at 8:31 AM, Filippo Claudi notifications@github.com wrote:

The satisfaction is very high 😍

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/RedBalloonShenanigans/MonitorDarkly/issues/16#issuecomment-343154990, or mute the thread https://github.com/notifications/unsubscribe-auth/Ae_gJ9EllYO_Kepx18hxfDJqRTiil5R9ks5s0v68gaJpZM4P_zh0 .

alessaba commented 6 years ago

Finding the egg

Filippo Claudi

Il giorno 09 nov 2017, alle ore 16:12, zinoharo notifications@github.com ha scritto:

what?

On Thu, Nov 9, 2017 at 8:31 AM, Filippo Claudi notifications@github.com wrote:

The satisfaction is very high 😍

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/RedBalloonShenanigans/MonitorDarkly/issues/16#issuecomment-343154990, or mute the thread https://github.com/notifications/unsubscribe-auth/Ae_gJ9EllYO_Kepx18hxfDJqRTiil5R9ks5s0v68gaJpZM4P_zh0 .

— You are receiving this because you commented. Reply to this email directly, view it on GitHub, or mute the thread.

theclai commented 6 years ago

Me too

lancefisher commented 6 years ago

I just watched the episode tonight :)

Not that anyone here needs it, but here are the steps to reproduce (on OSX):

From the show

image

# Install some tools
brew install wget unrar zbar

# download the url in the email
wget https://sandbox.vflsruxm.net/plans.rar -O plans-base64.txt

# show the file for posterity
cat plans-base64.txt
UmFyIRoHAQDz4YLrCwEFBwAGAQGAgIAAaqQxujQCAwvdBwSpCSDmLtDfgAMAGGpC
b3VhcUs5UjhqWHhmcEU2a0dWLnBuZwoDAuhpGqmXR9MBykrZA0BlRWMiPzYAaWtG
4y5CKWrcagjRpWw+CVQlthXGUgSkhQFSEhBGwaFVq2EkwkYSBZ6Zla40lwY0rRaF
YNLMIiQT4VjFG+hgzEBJRKSWJUkjMwKs+JICQKJIEmY5LLcuW9n5fczubmbvebzu
83e/od3nd3m973dzeeec5mefmqzezsyKE+oJECBAomSmJ6C7VNf855mq/uDUU3vp
4Dq97Nz5F/BaAle0uC8p5xgnMS0+g+9yy3BrKldbq+D5tF18/XHvSipzd2CSz2qa
buoI+K3HqzKb8us7zREMzox1pxL3fDuZSJ/WjIHmVg5n3GB8J49zsgrIpCs3o2Fw
elehOp1zb+sPUBNrznGIbSYOKAZ9UXYnXzIr+eO7tbYlRR4HZT1ZQf4cVQpoG8PS
EZMt+g1q0Oe9/0uAZ8X05JXXez3sxGm3+uFtQK6+Hto065Ku72KlNiPKTQIeyT5l
crgkTqA4NF1QqPR7OXBmUrhWxcrzIaRqr/WBQXahXUrJtkXnJpgsd0wEboBRIbP4
sfItuGqV+KqWOblf5Ot64Hvy6jXyUEMgiDY51dmWVjyMKv5G5LdwZyyIJLKbIri1
C6Te+w/dZRNa+LP+Nt0x/ZZdyAlVWR3jJ/scC6msO/Q+4WmJ7n6Kzk80AobYK4pI
DOwx2Uei8FCZS/JFYrCthCdW4T4VpcoPaJZY3lI7Rfx6qhjsmRWpLoFK0b7aLR9l
YfKROnNI885Mp2ywOKkoSxboKOJlVp7WVGwTsTQcNxc7vKbP/yEEPbVJRb8ZdbtE
PVMYEWp6/CnHuhT7N1CWQP+lLHLU3LKw5+NWfyakyxF4hXHJAHMZc2t0UdKNrA8m
p7FsXvA/shbhioeagOCmZTIkFWPjXHwylCrUYlP8AOPrfEJur1n4og/+/HL/c6Y5
pksv3JtvDwlx6u78GsXPu7kmlFPzO1sO/p9Lt0FKp9MgDSZdvauPtO9lWFIJfHp7
/8N08CseGojeBhTMJQokVvyljS7QLP20EevozBIfJAZ+C7fFYeeaDvOmkqvrU0ip
jgIWnUv/IJbAhKH3Cr+jg5aUhW4UTHd3Q0wdnNq4afNttSRwaJuX7MGjFTdewGM9
LbYN/wIRSwib3+M2mGuywZ92YVVFpjZ4vMhNMSw9eLUFaMhfDXMnUe2M51XusaVF
qiQCyf63UDCPCQ8P0bfElu/UvS2+NyX0ALh+pSx9dxrjn3tmO9htRYwHwu5ebeXR
ZD6p9CyMpd4is9eDfl9+IspNGtGMaOntIJiBc8RzmvR4oOxlK3jP9ZJ4Rc+Qu4hx
k+O/EeVJkZ2Y6hDg/OAdd1ZRAwUEAA==%

# base64 decode the file
openssl base64 -d -in plans-base64.txt -out plans.rar

# extract the rar
unrar e plans.rar

# get the info from the qr code
zbarimg jBouaqK9R8jXxfpE6kGV.png

which will show:

QR-Code:https://github.com/RedBalloonShenanigans/MonitorDarkly
scanned 1 barcode symbols from 1 images in 0.05 seconds

🎉

zinoharo commented 6 years ago

does anyone know where the redballoon sec offices are? i know somewhere around penn station

On Sun, Dec 3, 2017 at 3:26 AM, Lance Fisher notifications@github.com wrote:

I just watched the episode tonight :)

Not that anyone here needs it, but here are the steps to reproduce (on OSX): From the show

[image: image] https://user-images.githubusercontent.com/111022/33523608-7f536d0e-d7c8-11e7-9fe5-1bbe9e23ed33.png

Install some tools

brew install wget unrar zbar

download the url in the email

wget https://sandbox.vflsruxm.net/plans.rar -O plans-base64.txt# base64 decode the file openssl base64 -d -in plans-base64.txt -out plans.rar# extract the rar unrar e plans.rar# get the info from the qr code zbarimg jBouaqK9R8jXxfpE6kGV.png

which will show:

QR-Code:https://github.com/RedBalloonShenanigans/MonitorDarkly scanned 1 barcode symbols from 1 images in 0.05 seconds

🎉

— You are receiving this because you commented. Reply to this email directly, view it on GitHub https://github.com/RedBalloonShenanigans/MonitorDarkly/issues/16#issuecomment-348748586, or mute the thread https://github.com/notifications/unsubscribe-auth/Ae_gJzvjnCW3kFIQyauEVejVyfkteE68ks5s8lsdgaJpZM4P_zh0 .

cdclawson commented 4 years ago

This is spooky. I'm finally catching up on Mr. Robot (that's what brought me here) and I'm watching it on Prime Video on my computer. The monitor I'm watching it on? A Dell Ultrasharp 2410. No wonder Elliot's monitor looked familiar...