A couple of days ago, we concluded one of the most emotionally charged events that we were lucky enough to host on our blog — an online hacker game involving the destruction of a server.
The results exceeded all our expectations: participants didn’t just join in; they quickly organized into a cohesive community of 620 people on Discord, which took the quest by storm within two days without a break for sleep.
And here's how it ended:

How it all began and what was it all about?
The game started on August 12, when we posted on the blog with a video where a hacker in the guise of a skull invites players to join a game, destroy the server, create a short circuit in the room (or maybe a mini-fire), and claim the remaining money in the shredder.
It was an online quest: we launched a YouTube broadcast from a room filled with IoT devices, featuring an under-bed server (which was the target for destruction), and over the server, we placed an aquarium and hung a weight above it. To make the game more thrilling, we decided to set a prize pool of 200,000 rubles, which we loaded into the shredder to activate every 60 minutes. Every hour, the shredder consumed 1,000 rubles — the sooner the players stopped it, the more money they would win.

Building this quest was an adventure in itself — we had to survive on takeout food and sleep only a few hours a day right in the same room. But the most amazing part was witnessing the players' creativity and their emotional investment throughout the process.
Honestly, the inventiveness of the players in solving the puzzles far surpassed our modest idea: every free minute, we read the Discord chat and, in some cases, literally cried from laughter, discovering what the players were doing and how they were joking around during the game.
Seven people worked tirelessly on the project: a backend developer, a hardware expert, a real film producer, a CG designer, and two creative co-producers.
In future posts, we will discuss how the quest was implemented from a technical perspective, but for now, let me reveal its solution: how to hack this room during the broadcast. Let’s also recall the timeline of events and all the crazy Illuminati theories from the Discord chat.
What the players experienced at the beginning of the game.
All items in the room were divided into three categories:
- Simple-to-manage, non-gaming IoT devices
- Gaming devices for completing quests
- Atmosphere

We placed 8 very easy-to-manage elements: two lamps, one garland, and five letters spelling SOKOL, each of which could change color. All of this could be turned on/off directly from the website, allowing immediate visibility of results in the broadcast — we made them accessible to all players, regardless of their technical expertise.

Everything that could easily be turned on from the website
Among the important game elements needed to complete the quest, access to which was not so simple:
- A server with an open lid and an aquarium above it
- A kettlebell, suspended to break the aquarium
- Megatron 3000 — a powerful laser pointer aimed at the rope holding the kettlebell
- A powerful fan that activated under load on the server
- A flip chart displaying the login and password to Megatron
- A phone that you could call to see your call live
- A shredder that devoured a 1000-ruble bill per hour
How the quest was solved
I’ll say right away: the box opened quite simply.
The goal of the game was to stop the shredder by causing a short circuit in the room. To do this, the aquarium needed to be broken by launching the kettlebell into it and flooding the server with water. The kettlebell was held by a cord targeted by Megatron. By taking control of Megatron, the rope could be cut. This was done in 5 simple steps:
Step 1. Load the server that was in the room
For example, by sending packets using a command.
ab -r -n 10000 -c 100 -s 280 -l https://ws.ooosokol.ru/captchaThe hint was a very loading to .

The very captcha that needed to be attacked

With the server load, its temperature increased, and this could be tracked on the monitoring display right in front of the camera. Then, a fan would turn on, opening a light curtain on the flip chart. This revealed the login and password written on the board to access Megatron's page.
The management page for Megatron could be found by checking all certificates issued for the domain ooosokol.ru.
On the subdomain The management page for Megatron was displayed. However, it would not open until primary power was supplied to Megatron.
All these steps were almost immediately discussed by players in the YouTube stream comments. The tasks became a bit more difficult, and the players created the RUVDS Hack Room Discord server to continue the discussion there.
Step 2. Supply primary power to Megatron.
All smart devices controlled from the website (the same lights that players continuously turned on and off) had their own identifiers.
To supply primary power to Megatron and illuminate it, it was necessary to find and activate the hidden device on the office management page.

To do this, it was necessary to look at the device identifiers and notice that there were a total of 4 devices, while only 3 were available on the website.

The Megatron page became accessible when the 4th device was turned on, and the laser itself was illuminated. However, it was impossible to shoot the laser, and there was a message indicating that the laser was currently unavailable and a hint: the fuses in the office had blown, and it was necessary to call the management company to request power supply. Hint about the management company.

3. Call the management company and request to turn on the power for Megatron.
According to the lore, Megatron could not fire because the fuses in the office had blown. Only the management company could restore the power, and it was necessary to call them and undergo identification as the owner of the LLC.
Finding the management company's phone number was easy — we placed it right in the footer.
However, passing the identification was much more challenging.

When calling the number +74991130688, a female operator answered and asked in a bored voice to provide the company's tax ID and the owner's full name. Without this information, she refused to restore power, explaining that she was just a dispatcher outsourced, with 2000 clients and offices, and without this information, it was impossible to find the right one.
This turned out to be the most challenging step for the players. The correct tax ID and the owner's full name were sought for almost two days, while I (as the dispatcher operator) received more than 400 calls during this time. The phone rang every 2-3 minutes.
The guys were digging as much as they could. Everything was used: they scoured the website's source code, Googled the website owner Sokolov, and searched through social media.
They were looking for the tax ID of various companies.
They were searching for the tax IDs of different companies.

Almost a complete search scheme
At some point, they even called with a spoofed number—as if they were calling from the office of the company Sokol, listed in the footer.
That’s when we learned how many companies are named Sokol. Players were reaching out to virtually every one of these companies, but it was nothing compared to what the site experienced. , from whom we had actually purchased that very Megatron about a month ago.
At first, Discord attacked the support of Lasermasters.

Then they managed to find someone’s account there! Meanwhile, Lasermasters' support had already stopped holding back on their expressions.
Caution, keep children away from the screen


Eventually, we decided to simply DDoS Lasermasters and their site went down. We also managed to take down Sokol's site, although we quickly brought it back up.
During the investigation, the guys from Discord even found the actor whose photo we had purchased from stock to play the role of the main antagonist, the owner of LLC Andrey Sokolov. It turned out his name was Yuri and he was completely unaware of the mess he had gotten into.

Andrey Sokolov, the character in the game

Yuri, the model
If only he knew how he kept 600 people awake for two days…)
Then they started digging specifically into me, as the organizer of the quest (which could have ended successfully if the guys had thought to hack my work channels).

I even got a little worried when they mentioned my patronymic and even my tax ID. But I relaxed when, during a game of broken telephone, I suddenly had an older brother who unexpectedly turned out to be the technical director of Habr.
My dear brother, who also got caught up in this

Meanwhile, the speculations became more and more incredible

And it led to Illuminati theories.

The most juicy conspiracy theories involved SpongeBob, Harry Potter, and the blinking Chinese LED garland that we had placed inside the system unit.
Where did SpongeBob and Harry Potter come from, you may ask? We had stuffed their addresses into Sokol's contact page, which spawned a mass of speculation in the Discord community. Although we just wanted to pay tribute to our favorite childhood creations.

That very reference on the ""
And as a result





It turned out that the series really contains documents of SpongeBob. They referred to them as tax IDs.

One of the most complex theories was that the blinking of the Chinese lantern contained a message in Morse code.
The flickering was recorded and attempts were made to decipher it.



Among simpler theories, the guys tried to understand whether a clue was hidden in the maps.

On the way, we were compared to — an undeservedly high rating, but still pleasant.


Players were actively trying social engineering. I received calls posing as FSB agents, firefighters, Sokolov himself, his ex-wife, and a security guard supposedly sitting downstairs. They said there was a fire, someone was stuck in the elevator, and the most heart-wrenching story was about a puppy supposedly left behind in the burning office.

Attempts at bribery were also made.
Gradually, our own memes started appearing in the chat.
Here are a couple of them.



Meanwhile, the factories were idle.





Tip
The money in the shredder was getting less and less. To ensure the winner received something, we decided to provide a hint. Following game design rules, we aimed to raise the tension just before the finale.
In a separate on the blog, we posted a video. At the beginning, a clip from Fight Club was included as a nod to Tyler Durden, who considered inserting the 25th frame into films while working in cinemas.
We decided to use the same mechanic and included a hint as the 25th frame on how to the correct TIN and the name of the owner.


After that, the guys figured it out very quickly.
Step 4. Fire the laser in non-combat mode.
When powered by the managing company and upon the circuit breakers being turned on, Megatron would start and could shoot in test mode. A token for a test shot was already pre-filled in the input form.

Every 25 seconds, a new token was generated, which could be used to activate the laser for 10 seconds at a power of 10/255.
Then the laser cooled down for 1 minute and was unavailable during this time, not accepting new firing requests.
This power was completely insufficient to cut through a rope, but any player could fire Megatron and see the laser beam in action.
The community's reaction was more than enthusiastic.

But everyone quickly calmed down and realized that this was not the end of the game.

Next, the community began figuring out how to activate combat mode.
Brainstorm.


Fake accounts appeared in Discord.
We didn't know that something was written on the leg of the table during the stream.
The community has reached step 4. Understanding how tokens are generated: find the gist and generate a token that includes the laser in combat mode.
Megatron's combat mode is 100% laser power at 3W. This is enough for 2 minutes to burn the rope holding the weight, break the aquarium, and flood the server.
We left some hints on : namely, the token generation code, which made it clear that test and combat tokens are generated based on a single counter value. In the case of the combat token, in addition to the counter value, salt is also used, which was almost completely left in the change history of this gist, except for the last two characters.

As everyone quickly guessed, it was 42.
In the gist comments, there was correspondence between Andrey Sokolov and the developer (the 'wise dev', as the guys from Discord called him).
In the correspondence, Andrey sent one of the combat tokens, and the dev replied that this token was initialized at counter value 42.

Knowing this data, one could brute-force the last two characters of the salt and essentially find out that numbers from Lost were used for it, converted to hexadecimal.
Next, players just had to catch the counter value (by analyzing the test token) and generate the combat token using the next counter value and the salt found in the previous step.
The counter simply incremented with each test shot and every 25 seconds. We didn't mention this anywhere; it was meant to be a little gameplay surprise. The guys figured it out very quickly and launched Megatron in combat mode.
Step 5. Burn the rope with the laser.

Here it was quite simple. Sending the combat token activated the laser in combat mode, and the room changed to enter the 'disaster mode', as we called it in the overall scenario:
All the lights in the room went out.
- The IoT device buttons on the site became inaccessible.
- A strobe light and siren sound were activated.
- The red weight was illuminated.
- The TV screen started a countdown to the activation of the laser in combat mode.
- The countdown began on the television screen.
We gave a countdown of an hour and a half for everyone who played to start the stream and see the finale. And it was worth it: as I waited with bated breath for the sound of the hit and the shattering glass from the next room, the entire team that built the quest, without discussing it, began to head to the base to see the finale with their own eyes. They just rushed into the room and started hugging each other.
Meanwhile, in Discord


After the countdown ended, the laser switched to combat mode and burned through the rope in two minutes — the weight flew straight into the aquarium. Before the hit, a crazy capybara screamed on the screen, panic raising its little paws.
Since the entire team had gathered there, we recorded a small message for everyone who spent two days fighting for the finale in Discord and went to open champagne:

How did we calculate the timing for launching the commercial videos and the weight's flight?
After a dozen tests burning the rope with the laser, we realized that it was a very unreliable setup — a partially burned rope became thinner, stretched under the weight of the weight, shifted position, and the laser could no longer cut through it completely.
So we took a different approach: we doubled the burning process by wrapping the rope with nichrome wire. We passed current through the wire, it heated up to red and burned through the rope in about 2 seconds — this gave us precise timing for when to activate the screaming capybara, stop the launch timer, and start the commercial:

What didn’t work for us?
During the finale, thick smoke was supposed to pour from the system unit like in a fire — we prepared smoke bombs, ignited them in a similar way, but for some reason, they didn't work (probably because of the water).
Who is the winner?
The winner turned out to be Arkadiy Alekseev from Saint Petersburg — he was the first to generate the test token and won the remaining 134,000 rubles in the shredder.
A short interview with Arkadiy.
Tell us about yourself, what do you do for work?
By education, I am a safety specialist, graduated from BIT at ITMO. I work as a full-stack web developer in outsourcing. In school, I was an Olympian, including in programming and mathematics.
How did you find out about the game?
I just went on Habr to read and saw the article, I got interested.
How many hours did you play, when did you join?
I joined on the evening of the day the article was published (that is, a day before the end). I spent the evening and a significant part of the next day.
What did you like and what didn’t you like?
Overall, I liked everything (after all, I won)), but I was a bit stressed by the calls. I mean, calling and checking each version felt awkward at least — I understood that several dozen others were calling as well, half joking and trying social engineering.
How did you figure out how to find the battle token for the Megatron?
When I logged in, they had already spammed the server, poked at the lights, found the admin password for the laser, various subdomains, and pages.
It was also easy to find a profile on GitHub and a gist with comments. From there, the process of generating the token and secret for it was obvious. In such quests, there's no need to overly invent IMHO, as one can drown in a myriad of scenarios; and accordingly, you need to follow where the quest creator nudges you.
Considering the other subdomains and the test site on Tilda, it was clear that after powering the laser, a token would need to be obtained. Consequently, that same evening, I drafted a rough request to turn on the laser (based on 4 available forms: 1 on the working site and 3 on the test/old one) and I tried to brute-force the working tokens starting with 42 (just for fun — maybe everything was already on, and the token submission page would simply open after entering the INN and full name).
I’m not sure if the request was correct, as there was no time to check (after all, the only thing I could verify was turning on the laser), but I had prepared for the token brute-forcing in advance.
There was also obvious logic with websockets and device control in the app.js file. There was a strong hint about the a9 device, which crashed the socket when sending power: true. I tried various things to send to it — who knows, it could have had an additional device for deciphering the INN, but without success.
Later, I checked the other IDs next to those ten, but all showed unknown device. I also tried to Google various things, accessed chsokolow@gmail.com, sent different things through the form on the pricing page, and looked into lasermasters, but all without success. The next day I was in the chat, Googling things, then the stego topic came up, and I consulted a person about stegsovl for pictures and GIFs (but I understood that 99% there is nothing, as it would contradict the main quest line).
But in the end, I also spent a couple of hours digging through all the pictures and GIFs. I called a couple of times with different TIN options, but to no avail. Then I decided to let it go, but they posted a hint — and it became clear that they would find the TIN soon, which happened. Then either I or someone else (it wasn't obvious) sent power: true to the a9-device, and the laser worked, although maybe there's no connection here, and it just worked after the TIN. In general, I entered the admin panel of the laser and was quite surprised, as the server sent the token by itself (and I was already preparing to brute-force). It became obvious that the token was a test one, as the broadcast + common sense + I checked it.
The code had the logic to send the working token somewhere as a notification, but apparently, either it was the wrong code or it was needed for other parts of the system. I wrote a script to get the current working token from the current test one and started refreshing it, trying to send them — that was problematic, as everyone was constantly clicking the send button, thus changing the token. Then the site went down, the counter reset, but that's not the point — after a while, I sent the working token. Ideally, the counter was 58 and the token was 449a776938f7ce4cf19f8603045dca0f at the time of activation, if I'm not mistaken. That’s basically it.
Then I got a bit heated from comments like "oh, this is all trivial, just got lucky." Well, if you go to the page, think for a minute, write a script in a couple of minutes, check it — then yes, it's trivial. But I did it in about 10-20 seconds, and then I just couldn't send the token for several minutes.
Of course, it would have been possible to try writing the logic for automated capturing and sending, but that would take longer and involve a significant risk, plus the cloud would probably start complaining. What I was truly fortunate with was the very last stage — a bit of algorithms for speed + reaction speed; that's right up my alley. If there had been a task directly from the pentest, I probably wouldn't have been first.
But this is not the end yet.
I can’t wait to tell you about the amazing team that built this quest and all the engineering solutions they came up with. However, this post has already become too huge — so there will be separate articles on this, so stay tuned and subscribe to our blog on Habr.
Source: habr.com
