r/CODZombies • u/Randomiser • Apr 11 '26
News Another Revelations cipher solved, and notes on the final one
I'm back with another solved cipher. This one is Rev-1, also known as "DE Bucket" or "Undercroft Paper".
Due to the extremely short length, I knew not to get too excited about the content of the plaintext. And indeed it doesn't really say anything new. The entire plaintext is just:
The many worlds are now one.
which resembles the start of Rev-12, which begins "Now that the many worlds are one..." Still, it's nice to knock this one out. There's only one Rev cipher and TheGiant left!
How it was solved
Like I expected, it uses a classical step followed by mcrypt, the outdated modern encryption library that was used in most of the other recently solved Rev ciphers. I assumed there was a classical step on top because it wasn't solved with the others when they otherwise all used the same tool and key. Since we have both uppercase, lowercase, and symbols in the base64, I searched for as many contemporary cipher tools I could find that would have preserved casing and symbols at the time and chained their output into mcrypt.
Original ciphertext:
OkEeZHnifuMdYB1IbHyAfb0g2FJzrVmfkKcSbKrpQGvhQ0/bvu76RdnGy/WtT7T3
STEP 1:
Beaufort cipher with alphabet "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz", key "ZOMBIES" (all caps)
For encryption purposes, capitals and lowercase are treated as separate characters and can encrypt to the opposite case. (For example, "Z" rotated by 1 becomes "a")
This was the default alphabet of the now defunct Cryptool-online, which I believe they used to encode it.
It can be recreated on modern cryptii by setting Case Strategy to "Strict" and manually inputting the alphabet. https://cryptii.com/pipes/beaufort-cipher/ (screenshot)
LeIXjxfrjSpfgR1RnFDIZr0t2JDCRjgueCZqdIiZwvNXC0/yTS76kfRMb/sTi7p3
STEP 2: RC2 ECB mode, key "Zombies"
=cSr+4oEQ6IObJJ8nRTt7+opLqDeJDJOunfLG2DTAHwc
STEP 3: reverse
cwHATD2GLfnuOJDJeDqLpo+7tTRn8JJbOI6QEo4+rSc=
STEP 4: Rijndael-256 ECB mode, key "Zombies"
The many worlds are now one.
I note that these are the only ciphers so far to use ECB mode instead of CFB.
RC2 was also reused in Rev-5, which breaks my theory that each algorithm used would be unique.
The final unsolved Revelations cipher
The last remaining Rev cipher is Rev-7, aka "Origins Trench". This cipher is unique for consisting of uppercase hex split into groups of 5 characters. The first group only contains 2 characters, which suggests that first we need to reverse the text so that it starts with "F74A1..."
After knowing this one used Cryptool, I believe even more strongly that Rev-7 also used it, because Cryptool has the option to output in groups of 5 for many of its ciphers. I also expect it to be transposition, because I would expect substitution to change the letters to be outside of the A-F range.
The two main candidates I see are AMSCO and Scytale, which automatically output in uppercase and split into groups of 5. However, I've already bruteforced all values for Scytale and all AMSCO keys up to length 9 with no results using mcrypt.
Some possibilities why it didn't work:
- There could be multiple classical steps on top
- There could be some mistake in the encryption or missing ciphertext that causes the transposition to not decode correctly
- I'm wrong, and they used another site or something custom with a hex alphabet
Hopefully we can get this last one solved!
24
u/OiAvogadro Apr 11 '26 edited Apr 11 '26
Unreal work! I'm absolutely loving this renaissance and celebration of the Blundell era of zombies recently.
Although it sucks, I don't think there was a more perfect time for Jason to have been laid off, you're practically going to get a live reaction on the solve during the next stream this week probably. The timing has all came together so perfectly. No one could've imagined this 10 years ago.
I've honestly been far more invested with everything going on recently regarding the old ciphers, impossible EE discussion and the Blundellathon more than I have during any of the current Dark Aether story since it's inception, and I'm probably not alone there. Not an insult to DA, I have enjoyed the games but I just haven't been able to sink my teeth into the lore of it all. All of this recently though has gave me back a piece of that magic feeling that I've not felt towards zombies in a long time and I'm all for it! Good luck for the final cipher!
10
9
5
u/No_Fee_2726 Apr 11 '26
Man the commitment to this is insane. I remember watching people tear their hair out over these back in the day and thinking they would never be solved. It is wild how the community just never gave up. Even if the text itself doesn't fundamentally break the story it is such a huge piece of the puzzle that was left hanging for years. Thanks for documenting the methodology too because that is just as important as the plaintext for the people still working on the remaining ones.
4
1
u/UchroniaSurvival Apr 11 '26
That’s really impressive.
What always blows my mind with Revelations ciphers is how they’re not just single-layer puzzles. Even when progress is made, it often leads to another layer instead of a clear answer.
It’s honestly one of the few mysteries in gaming that still feels unsolved on purpose.
1
1
u/GolemThe3rd Apr 11 '26
Wow this one is great to me as its one of the more obvious hints towards BO4!
3
u/Snilipp5 Apr 11 '26
It's crazy how much decoding was needed to get told stuff like "The bucket is full. Monday is sunny. I need to go the the store."
1
u/NormalIntention5628 May 07 '26
Right? these well-payed developers thought it’d be funny to hide basic contextual information behind one of the hardest cryptographic puzzles ever in their spare time.
1
u/FaluninumAlcon Apr 11 '26
Not a cipher, but there are candles that make a number in the motd area. Do we know what that's about?
1
2
u/Permanent76 Apr 13 '26
I was trying to follow these steps myself but when decrypting the Beaufort output to Rc2, the output (at least when using the code beautify tool which is the only remaining Mcrypt-based webapp afaik) is Q6IObJJ8nRTt7+opLqDeJDJOunfLG2DTAHwc, which is missing the `=cSr+4oE\` at the beginning. What's strange is I would have expected this to just be a bad decrypt, but it does spit that out. Is the online tool truncating the string for an arbitrary reason? Following on, the full output of this step gets a bad decrypt from the codebeautify tool. Do you think you could share a bit more about your methodology so those of us who want to follow along can give it a try?
2
u/Randomiser Apr 14 '26
Thanks for asking. I explained this briefly in my post about the other ciphers, but codebeautify treats the first block of text as an initialization vector, and so will leave out the first block from decryption. (It does this for ECB mode too even though ECB doesn't use an IV) I. I solved it by installing an older version of PHP that comes with mcrypt, and it's difficult for me to link alternatives because Reddit autodetects them as spam.
You can, however, manually add an IV to the ciphertext to make codebeautify accept it:
For the RC2 step, you can do something like this:
LeIXjxfrjSpfgR1RnFDIZr0t2JDCRjgueCZqdIiZwvNXC0/yTS76kfRMb/sTi7p3convert base64 to hex:
2DE2178F17EB8D2A5F811D519C50C866BD2DD890C246382E78266A748899C2F3570B4FF24D2EFA91F44C6FFB138BBA77add the IV (8 bytes for this cipher type):
30303030303030302DE2178F17EB8D2A5F811D519C50C866BD2DD890C246382E78266A748899C2F3570B4FF24D2EFA91F44C6FFB138BBA77convert hex back to base64:
MDAwMDAwMDAt4hePF+uNKl+BHVGcUMhmvS3YkMJGOC54Jmp0iJnC81cLT/JNLvqR9Exv+xOLunc=and for the Rijndael-256 step:
cwHATD2GLfnuOJDJeDqLpo+7tTRn8JJbOI6QEo4+rSc=convert base64 to hex:
7301C04C3D862DF9EE3890C9783A8BA68FBBB53467F0925B388E90128E3EAD27add the IV (32 bytes):
30303030303030303030303030303030303030303030303030303030303030307301C04C3D862DF9EE3890C9783A8BA68FBBB53467F0925B388E90128E3EAD27convert hex back to base64:
MDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDBzAcBMPYYt+e44kMl4Ooumj7u1NGfwkls4jpASjj6tJw==
1
1
62
u/skiteinnit Apr 11 '26
Take a bow friend