It's not that hard. If you think this one is hard then you should see the puzzle inside this puzzle.
Comment has been collapsed.
He made an awesome work as puzzle maker. Thank you Award and congratulations to the winner.
Comment has been collapsed.
"A repeating pattern to notice is NPV" wiped me out. AWESOME puzzle, though.
Comment has been collapsed.
Great puzzle.
Got to where you had to reverse VPN, I got that VPN=GAY was an 11-shift ceasar cypher, but didn't think think about reversing it.
Great puzzle and nice giveaways.
Comment has been collapsed.
I loved this puzzle, but somehow I got stuck while trying to decode the XPComment. For some reason, after doing the ROT-13 and the base64, the binary led me to a string of weird characters that didn't make any sense. How could this happen? Here's the binary string so you can see it for yourself: 00011010111001110111110111001011000110011100101101111110111010110001100111001011011111011100011101111110111010110001101011100111000110101110011101111101110010110111111011101011000110101110011101111110111010110111110111000111011111101110101100011010111001110001101011100111000110101110101100011001110010110111111011101011000110011100101101111101110010110111111011101011000110011100011100011001110001110001101011101011000110011100101101111110111010110001101011100111000110011100011101111110111010110111110111000111000110101110011100011010111001110001100111001011011111101110101101111110111010110001100111000111000110101110011101111110111001110001101011100111011111011100011100011001110010110111111011100111011111011100101100011001110001110111111011101011011111011100101100011010111010110111111011100111011111101110101101111110111010110001101011100111000110011100011101111110111010110001101011101011000110101110011100011010111001110111111011101011011111101110101101111110111010110111110111000111000110101110011101111110111001110001101011100111000110011100011100011010111010110111111011100111011111011100101100011001110001110111110111000111000110011100011100011010111001110001100111000111011111011100101101111101110001110111111011100111011111011100011101111110111010110111110111001011000110101110011100011010111010110001100111001011011111101110011100011010111010110111110111000111011111011100011101111101110001110001101011100111000110011100101101111101110010110111111011101011011111101110011100011001110001110111110111001011000110011100011100011010111001110001101011101011000110101110101101111110111010110111111011101011000110011100101101111101110001110001100111000111011111101010100000100111010000000101010100001001010101111000000001110010101010110011010111100110
Comment has been collapsed.
Too much complex computer/programming language jargon and stuff.
Comment has been collapsed.
You received an offer for trading your excess of luck with me, but now it's too late. ;)
Comment has been collapsed.
I already took your offer but I didn't inform you about it and I can't blame for not noticing that you are mssing something. I may have some spare luck lately but it didn't help with parts 2 and 3 so I thought your puzzle solving brain would be a very useful asset for me in the future.
Comment has been collapsed.
Unfortunately I can't give you a piece of my puzzle solving brain, but I will make you a good offer if you can demonstrate that your excess of luck works on giveaways with a number of entries greater than 20. The evidence that you showed is only for 2-15 entries giveaways so far.
Comment has been collapsed.
I never asked for your permission. I'm a ninja, I saw that puzzle solving brains of yours lying inside your head and I snatched it, no thanks given. I agreee that the extent of my luck hasn't been thoroughly examined but why should you of all people not be satisfied with a 15 entries giveaway? You make it into a lot of those.
Comment has been collapsed.
Nowadays it is difficult to find a serious excess luck trader.
Comment has been collapsed.
I would like to thank you very much for posting the solution. I spent quite a bit of time trying to solve this puzzle and I found the first 2 giveaways and the packed txt file. I was experimenting with the hex form of it indeed and applied the anti-crack hint to it. I guess the VPN is GAY hint is where I got stuck...
Unfortunately I already had the first 2 games, so despite all my efforts, I didn't get to enter anything, but oh well...
Still... I'm really grateful for this explanation, because I seriously wanted to find out what there was to do next. Many people don't post the solutions. :(
Comment has been collapsed.
Man, I got stuck on the MBE thing, that is totally NOT easily found online.
Comment has been collapsed.
Hmm http://www.google.com/search?q=mbr+identifier+0x35 first thing I see is JFS.
Here too, not to be one sided: http://www.bing.com/search?q=mbr+identifier+0x35
Comment has been collapsed.
Don't think it is easily found, but it is definitely possible to find the answer online. Think the problem is the term 'MBR identifier'. Posted something about it in the first giveaway, but Award didn't comment about it there. ;)
I think more accurately it is called partition type identifier inside the partition table which is just one part of the MBR. But as the MBR doesn't need an identifier, it is quite clear what was asked for. ;)
Comment has been collapsed.
Oh noes! You've discovered the great EXIF conspiracy now you have to be.. silenced...
Just kidding :) I should've totally put some foreshadowing to another puzzle, but honestly I don't think I'll make another like this one. I can always fix it.. maybe retrofit the other part of MIME boundary to be a Chekhov's gun carrying on even further? The one part I can always salvage is the final substitution cipher (the pair of alphanumeric keys). But I don't think so :)
This looks like something specific to the plugin? It is some sample picture from a site that reviews cameras. I got the trollface image originally from knowyourmeme.com and edited a bit in Adobe Photoshop Elements 6.0, but the program added a lot of EXIF metadata and its own thumbnail, so I did a screenshot and saved from MS Paint to remove most of it. Then I used file properties to add artists and comment. Next, I used exiftool.exe to swap the thumbnail and finally appended 7z part. So really can't see how that link would end up in the picture.
Comment has been collapsed.
... I almost had it. :'( fuck.
Really nice puzzle. Very clever. I just wish that some of the piles of garbled text were a little simpler to figure out what to do with. I spent forever trying to figure out what to do with the xpcomment text. Damn. Wanted the game too heh.
Good work on being very creative though.
Comment has been collapsed.
82 Comments - Last post 2 hours ago by WaxWorm
56 Comments - Last post 4 hours ago by Carenard
1,811 Comments - Last post 4 hours ago by ngoclong19
72 Comments - Last post 6 hours ago by Reidor
545 Comments - Last post 9 hours ago by UltraMaster
41 Comments - Last post 9 hours ago by ViToos
1,520 Comments - Last post 10 hours ago by ayuinaba
182 Comments - Last post 20 minutes ago by Aerctaure
51 Comments - Last post 25 minutes ago by g2gfast
28,265 Comments - Last post 50 minutes ago by ngoclong19
10,787 Comments - Last post 56 minutes ago by eeev
27 Comments - Last post 1 hour ago by Mitsukuni
113 Comments - Last post 1 hour ago by eeev
1,250 Comments - Last post 1 hour ago by ProphetFinagle
I had a blast in this community since joining, and what is a better way to thank than to make some giveaways. However, what I enjoyed the most, by far, were various puzzles, so I'm obviously making one of my own now.
There are 3 giveaways, first one should be pretty accessible, it's a rather easy encoding/trivia puzzle so a tradition is fulfilled. The real challenge starts from there. I tried to design it so it is hard, but solvable without a requirement of wild mass guessing, divine intervention, bruteforcing or very proficient English command. Thinking is still required though. Mostly logical thinking.. Mostly. Sometimes lateral, too. We'll see how it works out.
Also, I checked everything at least three times and I honestly think it is very unlikely that I messed something up.
I set the giveaways to end on Sunday, May 20th, 2100 ZULU. Lookie, lookie, I even made a handy timer for y'all.
So, onto the first puzzle! Good luck!
http://www.steamgifts.com/giveaway/Xxxxx
(no digits).---- ... -/.-.. . - - . .-./.. .../.- - --- -- .. -.-./-. ..- -- -... . .-./---../.- -. -../- .... ./.-.. .- ... -/...--/.-.. . - - . .-. .../.... .- ...- ./-- -... .-./.. -.. . -. - .. ..-. .. . .-./----- -..- ...-- .....
Solution
Foreword
I tried to put myself in shoes of a solver and not to do something that would not be logical. Wanted to crate a certain flow in the puzzle with a lot of not crucial detail but hopefully something to appreciate by puzzle connoisseurs. There were only few steps that I considered really hard, intertwined with some easier (but still possibly hard) steps to keep interest and morale up, to give a sense of progress.
It could get bit technical at times, something I guess more technical people (like me) would appreciate, but for less technical people it could become like a meta-puzzle.
With my first puzzle I subtly encouraged searching online for answers, also in my email, so even if something wasn't immedietely recognizable I think it was searchable.
Overall I'm satisfied with the achieved results. The number of solvers/entrants for each giveaway matched quite well what I had in mind when designing this. I expected a bit more on the first one though.. Didn't count exactly how many commenters already had the games, save for the last one where it was easy (one person). I aimed for something around 200/50/10 solvers, got 147(+?)/40(+?)/8(+1).
I don't think I'll make as hardcore puzzle next time. I got stumped on many puzzles, sometimes (not always) imho unfairly, and in my own way wanted to make a few statements, not all of which I'm going to explain :) Anyway, I think I am artistically complete now. xD
Congratulations to all solvers, and especially the winners!
1. The trivial beginning.
morse code with slashes dividing words
1st letter is atomic number 8 = (O)xygen
last 3 letters have MBR identifier 0x35 = JFS (easily found online; okay as one user pointed out this is technically partition identifier within MBR, so I've used bit of a shorthand there)
2nd letter not mentioned, but I didn't want you to brute force. Just take 'x' from pattern. Some people thought (Ox)ygen and it's a lucky coincidence it actually worked out for them :)
First giveaway code: Oxjfs - it was Time Gentlemen Please! and Ben There Dan That! Special Edition Double Pack
Had some fun with trivia/quiz giveaways concept. The way how you may end up bruteforcing a letter, the way some stuff is easily found on the internets, etc. Morse code thrown in for good measure. This was meant to be rather accessible, but a puzzle that stands on its own nonetheless.
Slashes confused some people (and some tools). Not really intended but there you go, added challenge I guess.
2. The Hidden Email
The email has kind of an easter egg for the very end. Kind of a satire. I have toyed with the idea for it to be the code for the final giveaway, but didn't want to take the risk someone actually figuring that out. So instead it pointed back to the first giveaway. It would still seriously weird out someone if found. In hindsight, I could've probably risked pointing to the second giveaway with some rot13 thrown in for teh lulz.
Pastebin.com didn't like (MI)ME, they called me a spammer! ("Stop spamming! Contact admin@pastebin.com to get this ban lifted"). I had to find another site but as an added bonus it had email syntax highlighting. Nice touch.
3. The Face Value
Imagine that, base64 wasn't invented to make puzzles. It actually was invented to send binary data over a channel that accepted only (lower, 7 bit) ASCII text and some binary data could have control characters and whatnot and mess it up.
In hindsight, I could've put EXIF on top and 7z second, perhaps, to point out you gotta go EXIF route first? I think people discovered entrance to the final message for giveaway #3 too early and got confused. But I said in email, look for artists first. EXIF metadata "artists"! I also repeated many times, there is no random guesswork involved, so there was no point in trying passwords if you were not 100% sure it actually is the password.
4. Artists and (XP)Comments
._
"->"01
": replace ".
" with "0
" and "_
" with "1
".pass=sha1(full_txt_from_exif_thumbnail)
- meaning to look for exif thumbnail and whatever text appears there, compute the value of sha1 hash function for itThe idea of binary => base64 => rot13 is ripped off directly from (I mean, inspired by) a puzzle from a month ago. I'd give credit but the author didn't provide solution methinks so not gonna do that. It was basically impossible to solve one part without bruteforcing until he added a very clear hint about using rot13 first. He linked to this puzzle from one of his more recent ones, too. I decided to use this stuff and add some subtler hints. It turned out to be a killer again. Though you actually could get to giveaway #2 without it, seeing the EXIF thumbnail earlier by chance in a tool or file explorer. It was still required for giveaway #3, though.
There was a similar puzzle recently, too, just not with rotated base64, but something else (Welsh). So some experienced puzzlers might have been tipped off.
5. The Trolling QR Code
YAY! Celebratory midway giveaway: xTuPP. Keep this for later: [anti-crack hint: 0123456789-
>GINPQRSTVY]
I think too many people couldn't believe me I didn't do anything that was not logical. It was pretty logical (even if not necessarily obvious) to me that if original big image is flipped, the thumbnail is too.
This was actually a base forming my puzzle, something I noticed when playing with QR Codes to get an inspiration for some puzzles. I've noticed that a code flipped around diagonal (rotated 90 degrees right, flipped horizontally) looks legit, but is not. Decided to hide it in thumbnail and add a main picture that would hint a transformation is required. I made it a base for middle tier giveaway, added something fun and light at the beginning to make more people happy, and dang hardcore puzzle based mostly on playing with various encodings for the final giveaway.
I needed a way to hint people to find the thumbnail, if they didn't do it by chance. EXIF on trollface was a pretty good hint already, while XPComment was directing straight there.
6. Diving Deeper
636ad91c7a69885e6abda390c9548205f8decfe9
final_message.txt
!The password was long and effectively random to prevent someone from cracking the archive. I just decided to warn people (in Hydrophobia message) about some potential caveats: keep the qr code message without newline at the end, and you could still end up with lower or upper case, but only one works.
7. The Final Countdown
F4B36238F4B36238
)FQBPSNPVFQBPSNPV
NPV
GAYDAMBQGAYDAMBQ
0000000000
, but you get the point)0-
>1
This was a bunch of various text transformations piled up together. I was inspired to use base32 in my puzzle by some forum key giveaway (can't find the link, sorry). It actually got me totally stumped back then as I didn't use base32 earlier at all.. So I decided to use it myself, but hint about it. I played with it, encoded zeroes and ones and noticed this one peculiar repeating pattern. Like I said, it was hard to miss and hard not to use in my puzzle.
8. The Easter Egg
Very nice, almost there!!! The final
part is a simple substitution cipher.
First alphanumeric string is:
4WES0M3PUZLG1VAYNOH8KTXBIRCJDFQ25769
Second alphanumeric string is:
0ABCDEF12GHIJO3PQRSTUVXYZ4567W8KLMN9
I will let you figure out which
direction to use. 50/50, eh? Casing
should not be a problem.
Oh, yes. You wonder where to use the
cipher. The encoded giveaway code
is back in the MIME boundary, last
part after the dot. Hex encoded 1st.
It may look suspiciously familiar!
The final easter egg was a statement that FOR CRYING OUT LOUD, HOW I WAS SUPPOSED TO FIGURE THIS OUT WITHOUT PRIOR KNOWLEDGE OR INSIGHT INTO THE PUZZLE CREATORS MIND! ;)
Epilogue
In the end, there was a nice and light puzzle for the first giveaway, funky mind bending idea with QR code for the second giveaway, and heaps upon heaps of various decodings required for the final giveaway. A lot of stuff was twisted, though, and hidden in not necessarily obvious places. But there was always a hint on what to do and where to look.
In the encodings area arguably the most funky thing I used was base32. Besides that I only used morse, base64, binary, Caesar shifts including well known rot13, and some substitutions that always had the key provided.
Thank you for participation, I hope you had fun, even if you didn't win anything nor had solved everything.
No, I did not count just how many steps there were.
Comment has been collapsed.