2009/04/19

So, what's on the cover of that Verizon data breach report? part 2

Now search for word "key" in the text of the report or if you prefer to do it the hard way find a nice way to predict the key (I've done it the hard way at first).

Now plugging the key and the ciphertext from before into a vigenere decoder gives us the solution:

CONGRATSFIRSTTOCRACKGETSREWARDGOTOWWWVERIZONBUSINESSCOMSLASH
DBIRHUNTTOCLAIMFOREVERYONEELSEHIGHLVLSTATSFORFINSVCSANDRETAIL
FOLLOWPLSSHAREFINSVCSSOURCESEXTERNALNINETEENINTERNALNINEPARTNER
TWOTHREATSMALWAREELEVENHACKINGFIFTEENDECEITFOURMISUSESIXPHYSICAL
TWOERRORONEERRORSIGCONTRIBUTORINFIFTEENTOPTHREEHACKTYPESSQL
INJECTIONSEVENMISCONFIGACLSSEVENDEFAULTCREDSTWOTOPHACKVECTOR
ISWEBAPPTENTOPASSETISONLINEDATATWENTYSIXANDALLRECORDSTOPTHREED
ATATYPESAUTHCREDELEVENPIITENPYMNTCARDEIGHTPYMNTCARDWASNINETY
EIGHTPCTOFRECORDSTOPUUISUNKNOWNCONNECTIONSSEVENDISCOVERYTAKES
WEEKSTOMONTHSRETAILSOURCESEXTERNALTWENTYTHREEINTERNALONE
PARTNEREIGHTTHREATSMALWARETENHACKINGTWENTYONEDECEITTWOMISUSE
TWOPHYSICALZEROERRORZEROERRORSIGCONTRIBUTORINSIXTEENTOPTWO
HACKTYPESSQLINJECTIONSEVENSTOLENCREDSSEVENTOPHACKVECTORIS
REMACCMGTEIGHTTOPASSETISPOSELEVENANDOVERHALFOFRECORDSTOPTWO
DATATYPESPAYCARDTWENTYTHREEPIININEDISCOVERYTAKESMOSTLYMONTHS

So, what's on the cover of that Verizon data breach report? part 1

The Verizon data breach report is here.
On the front side you can see bunch of 1s and 0s... After conversion from binary to ASCII you get the following ciphertext:

EVNTXIGYIMWSNEHEIEFOTXBSCWYHRQMWGUZABVYCBBFREYFBVEDKEVMFRIFNG
FNRBFGVKSFPNBUFZJGCEEEWAKHPXEBTZJCZOWGTBSQGTMIAYDPYDRIRYETKCJR
PYHEPWKUOAEKNVTVZHSMZNTTIVIKMMRYSNUIAKBRKQMSTYCGCCRLRRIIREFGYT
JUBUXHEYSGLEYRVHIYXDEYZCJKVTOSOIXJEHOXEVMWJBNZMTKWZEFOFCNBWNC
UWMYFIUVBKWNPWTYOEYQTIRRYRCMNVFVLRSBNTPWPAOCZPEKHLFCEERRVWV
UYBVJPUVPOAYMIKQQNSWZGHZKDGYLAEGWPKESGCYZFVJDMEPQKSSLNVSVPUV
VRVYERHDTUTYYMQGEVWRMQSZFNPNRJIGGWAJNNJLKOEQHNETRPUQYDFZWCZ
KVJEXLMCKCSIFTCTSUTLDRRMIKQTNINPGRPQQXPTZDPAIOTCEUAZFEWDQLLPZR
HXLXQGSLRJTBLZRIRVISNZIWLMVYADVOHFEVNAKKGORRXSYGXPUMVGBOMRJLC
REFCMRQVXTMIYMJJVHXNBTSZMTJEFKFGKURFLNHXPKCWLEXMIYLGYNNRWAKS
EWTHPKGZKKXGAZELLUTAYCIEKWISHUNDKEKWARGBYZFGKEPKQGZZSRIMFLGKA
RTURAINSNGEEUMEXRVEELZXTISUWVZKOYLTPBHZWEOQWNXNPXPKSSXJHPANCV
FPRYADRLROEWEBQEWHZRGATZDGUCEKLFYHZJNNZIJRGNZRVBOCAUYEZGKPSJX
JIASMVFTDWFXBIDHQZEYKDRTDRIOPPKJRPISSKMCZJFZTBVBJUGEYANJIGJTDCPTZ
DEOGUTLZPEKHTNIHTGGUMVGBOMRJLCREFSWFZOCROHEAU

Ugh...

Looking back at the report, there's strange phrase at the bottom of page 48 "yr puvsser vaqrpuvssenoyr" which after quick rot13 reveals a french phrase: le chiffre indechiffrable

A quick google search for the phrase reveals a link to Vigenere cipher.

to be continued...

Once you get it solved there is a webpage that tells you what to do next: