Return to Unfiction unforum
 a.r.g.b.b 
FAQ FAQ   Search Search 
 
Welcome!
New users, PLEASE read these forum guidelines. New posters, SEARCH before posting and read these rules before posting your killer new campaign. New players may also wish to peruse the ARG Player Tutorial.

All users must abide by the Terms of Service.
Website Restoration Project
This archiving project is a collaboration between Unfiction and Sean Stacey (SpaceBass), Brian Enigma (BrianEnigma), and Laura E. Hall (lehall) with
the Center for Immersive Arts.
Announcements
This is a static snapshot of the
Unfiction forums, as of
July 23, 2017.
This site is intended as an archive to chronicle the history of Alternate Reality Games.
 
The time now is Wed Nov 13, 2024 6:06 pm
All times are UTC - 4 (DST in action)
View posts in this forum since last visit
View unanswered posts in this forum
Calendar
 Forum index » Archive » Archive: General » ARG: Slumberil
[PUZZLE] login to /secure on slumberil
View previous topicView next topic
Page 1 of 2 [19 Posts]   Goto page: 1, 2 Next
Author Message
yanka
Fickle


Joined: 06 Oct 2003
Posts: 1214
Location: undesirable

[PUZZLE] login to /secure on slumberil

http://www.slumberil.com/secure/ or http://secure.slumberil.com

Currently, an incorrect login displays this message:
Code:
Greetings.
Your actions are being logged.
Quit messing up our system.
We will prosecute.
This is MY house.

-Neil aka God


This is the secure area that on the day of launch contained all of this stuff (thanks again, colin).

Neil has previously used these passwords:
- j5042100
- ZAISV0101
- redpill
- 1_AM_g0d!

and issued these passwords to other users:
- tr0n5uck5
- 314_is_l1f3

There was also that curiously leet password used by Pandora: "w4k3up".

Since /private on slumberil.com started displaying this message yesterday: "Dead End Look Elsewhere", I am inclined to believe that we are supposed to keep trying to log in to /secure.
So far, Neil has only used "neil" as his username, I believe (?), which doesn't necessarily mean that only Neil has a valid login to /secure.
_________________
Annushka has already bought the sunflower oil, and has not only bought it, but has already spilled it.

PostPosted: Sun Jan 09, 2005 3:30 pm
 View user's profile
 Back to top 
AnthraX101
Entrenched

Joined: 18 Mar 2003
Posts: 797

Re: [PUZZLE] login to /secure on slumberil

yanka wrote:

There was also that curiously leet password used by Pandora: "w4k3up".


Just a note; that is a recomended way of increasing password strength (but not by much). Many people use some form 1337 speak in their passwords (Especialy when you have matrix fanboys brute forcing your website Wink )

AnthraX101
_________________
VGhlcmUgaXMgbm8gc3Bvb24u
ll----ll--ll--ll----l---ll---llll---ll--l--ll---llll-ll-l-ll-llll--l-.


PostPosted: Sun Jan 09, 2005 3:39 pm
 View user's profile
 Back to top 
codeish
Guest


I talked to someone that brute forced using a 500 meg file with all permutations of words up to 33 characters long, took him a long time, and he said he didn't get through.
I'm thinking as of now, they think we're still focusing on zmail, since they opened up zmail and that neil pw that was already tried in the past and didnt work did now, that they haven't opened up secure.s.c

PostPosted: Sun Jan 09, 2005 4:48 pm
 Back to top 
Strings
Guest


A friend of mine informed me that the secure login was on a loop so that no matter what you entered, it would bring you back to the same page...

I'm not sure how he found out so i don't know if it's true but... there you go.

PostPosted: Sun Jan 09, 2005 4:49 pm
 Back to top 
AnthraX101
Entrenched

Joined: 18 Mar 2003
Posts: 797

codeish wrote:
I talked to someone that brute forced using a 500 meg file with all permutations of words up to 33 characters long, took him a long time, and he said he didn't get through.
I'm thinking as of now, they think we're still focusing on zmail, since they opened up zmail and that neil pw that was already tried in the past and didnt work did now, that they haven't opened up secure.s.c


This is extremely doubtful. First, all words of 33 characters (assuming lower-case letters and numbers only, no other characters) would take about 2.28025032 × 10^51 bytes. If we were able to store a byte per atom, we would not have enough storage if we converted the entire earth into a storage device.

Secondly, the amount of time to brute force over the internet is large. Assuming his 500mb word list has an average length of 8 characters, there are about 62.5 million words. Assuming he were able to brute force 100 passwords a second (Which is a large estimate), it would take him about 7 days to try every one.

Strings wrote:
A friend of mine informed me that the secure login was on a loop so that no matter what you entered, it would bring you back to the same page...

I'm not sure how he found out so i don't know if it's true but... there you go.


Unless he were able to break into the server and download the php code, there would be no way to be sure that it always returns the same answer.

AnthraX101
_________________
VGhlcmUgaXMgbm8gc3Bvb24u
ll----ll--ll--ll----l---ll---llll---ll--l--ll---llll-ll-l-ll-llll--l-.


PostPosted: Sun Jan 09, 2005 6:19 pm
 View user's profile
 Back to top 
codeish
Guest


I'm not saying that was the exact filesize and I should have stated there was only one 33 character word since I told him the pw would most likely not be over 20. All in all he did brute it with quite a few permutated dictionaries and large files.
It may have not been 500 meg and he could have told me the wrong one, but he did fail, no matter what he did. Wink

PostPosted: Sun Jan 09, 2005 8:52 pm
 Back to top 
JustLurking
Veteran

Joined: 12 Nov 2004
Posts: 80
Location: Santa Clara, CA

As posted on xmyth, we can now login to the secure site again, using the pandora username password combination.

PostPosted: Mon Jan 10, 2005 2:21 am
 View user's profile AIM Address
 Back to top 
Ehsan
Entrenched

Joined: 09 May 2003
Posts: 992

JustLurking wrote:
As posted on xmyth, we can now login to the secure site again, using the pandora username password combination.


Yup, we found it in this thread.. I think the next step is to think about the /nmap thing..

PostPosted: Mon Jan 10, 2005 2:57 am
 View user's profile
 Back to top 
yanka
Fickle


Joined: 06 Oct 2003
Posts: 1214
Location: undesirable

wrong thread... sorry
_________________
Annushka has already bought the sunflower oil, and has not only bought it, but has already spilled it.

PostPosted: Mon Jan 10, 2005 3:15 am
 View user's profile
 Back to top 
jonathan
Boot

Joined: 10 May 2004
Posts: 36
Location: UK

I tried U/N pandora
P/W box

and it took me to http://secure.slumberil.com/trash/confidential/


Dunno if this has been done before, just getting into this ARG

PostPosted: Mon Jan 10, 2005 5:49 pm
 View user's profile Visit poster's website MSN Messenger
 Back to top 
fredthedeadhead
Greenhorn

Joined: 22 Nov 2003
Posts: 6

jonathan wrote:
I tried U/N pandora
P/W box

and it took me to http://secure.slumberil.com/trash/confidential/


Dunno if this has been done before, just getting into this ARG


It seems you don't need a password anymore, just put the Username as 'Pandora'

PostPosted: Mon Jan 10, 2005 6:15 pm
 View user's profile AIM Address MSN Messenger
 Back to top 
yanka
Fickle


Joined: 06 Oct 2003
Posts: 1214
Location: undesirable

fredthedeadhead wrote:
jonathan wrote:
I tried U/N pandora
P/W box

and it took me to http://secure.slumberil.com/trash/confidential/


Dunno if this has been done before, just getting into this ARG


It seems you don't need a password anymore, just put the Username as 'Pandora'

I think you can now log in either with a correct password (as a user = monkey, for example - or without specifying a user at all) or as Pandora without a password.
_________________
Annushka has already bought the sunflower oil, and has not only bought it, but has already spilled it.

PostPosted: Mon Jan 10, 2005 6:35 pm
 View user's profile
 Back to top 
eXt
Boot

Joined: 27 Dec 2003
Posts: 40
Location: Sweden

When accessing secure.slumberil.com the title changes randomly . This is the tiltles I found:

/beskeered
/trash
/tmp
./
/neilownzyou
/

Could this mean something?

PostPosted: Wed Jan 19, 2005 8:36 pm
 View user's profile MSN Messenger
 ICQ Number 
 Back to top 
edmnc
Boot

Joined: 28 Oct 2003
Posts: 10

hmm looks like there exists folder /tmp since it redirects back to / instead of showing a 404 Not found

PostPosted: Thu Jan 20, 2005 6:26 am
 View user's profile
 Back to top 
orphaen
Veteran


Joined: 09 Jan 2005
Posts: 142
Location: southern Louisiana

eXt, we've known that for a while, and we haven't really put it to use yet, if it's anything besides his ego. Wink
edmnc, entering any in the above list redirects to anything else in the above list, try it out -more- than once Very Happy
_________________
Here I am, Paradox Personified.

PostPosted: Thu Jan 20, 2005 2:00 pm
 View user's profile Visit poster's website AIM Address Yahoo Messenger
 ICQ Number 
 Back to top 
Display posts from previous:   Sort by:   
Page 1 of 2 [19 Posts]   Goto page: 1, 2 Next
View previous topicView next topic
 Forum index » Archive » Archive: General » ARG: Slumberil
Jump to:  

You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum
You cannot post calendar events in this forum



Powered by phpBB © 2001, 2005 phpBB Group