Hack This Site (2 Viewers)

Elnur_E65

Senior Member
Feb 21, 2004
10,848
#62
True...

I don't even care if somebody reads what's in my email.

Btw, question to experts: hotmail type email accounts- which level do they correspond to in terms of "hacking difficulty"?
 
OP
Martin

Martin

Senior Member
Dec 31, 2000
56,913
  • Thread Starter
  • Thread Starter #63
    Sarah, I'm throwing in the towel. Level 8 shouldn't be that hard but the guy made it hard on purpose and I can't figure it out. :irritate:

    ++ [ originally posted by Elnur_E65 ] ++
    Btw, question to experts: hotmail type email accounts- which level do they correspond to in terms of "hacking difficulty"?
    There have been lots of alerts about hotmail being insecure. In the past there was a well documented way of hacking any account, course that has been fixed a long time ago. Still, it's run by Microsoft, not quite the most security conscious company ever to exist.. :undecide:
     

    gray

    Senior Member
    Moderator
    Apr 22, 2003
    30,260
    #64
    bah, you guys beat 3 levels while I was asleep :lazy:

    but finally I got past level 5 :irritate:

    Did you guys find that you had to change the Content-Length: variable from 24 to _____ ?

    EDIT: Martin, you're right, level 6 is too easy.

    I hope this doesn't spoil it for anyone, but all I did was type in "aaaaaaa", and that made the rest of it waaay too simple ;) That's a pretty poor encryption algorithm if there ever was one :) I mean the whole first character thing

    EDIT: what's with level 7? why don't they just give away the password? :rolleyes:
     
    OP
    Martin

    Martin

    Senior Member
    Dec 31, 2000
    56,913
  • Thread Starter
  • Thread Starter #66
    ++ [ originally posted by gray ] ++
    bah, you guys beat 3 levels while I was asleep :lazy:

    but finally I got past level 5 :irritate:

    Did you guys find that you had to change the Content-Length: variable from 24 to _____ ?
    Nope

    ++ [ originally posted by gray ] ++
    EDIT: Martin, you're right, level 6 is too easy.

    I hope this doesn't spoil it for anyone, but all I did was type in "aaaaaaa", and that made the rest of it waaay too simple ;) That's a pretty poor encryption algorithm if there ever was one :) I mean the whole first character thing
    I guess there are too many encryption sites out there so they just made do with a really simple example here.

    ++ [ originally posted by gray ] ++
    EDIT: what's with level 7? why don't they just give away the password? :rolleyes:
    Level7 apparently was a security hazard to the site so they removed it.
     

    gray

    Senior Member
    Moderator
    Apr 22, 2003
    30,260
    #67
    ++ [ originally posted by Martin ] ++
    I guess there are too many encryption sites out there so they just made do with a really simple example here.
    I guess they had to make it simple for the sake of the exercise, but I was speaking in real life security terms ;)


    hmm, for level 8, could this be a clue?

    htt.p://www.hulla-balloo.com/hack/level8/tmp/kfsmymwl.shtml
     

    Sarah_old

    Senior Member
    Jul 30, 2002
    1,766
    #68
    G'morning *wave*

    I got level 6 on my first try too :) Reminds me of pattern sequence we learn back in school :D Though need some help with a certain table with that last character *blush*

    [++ [ originally posted by gray ] ++
    Did you guys find that you had to change the Content-Length: variable from 24 to ____?]
    I don't require that at all...but I got 24 and 0 displayed just before and after the message "Password reminder successfully sent" :)
     

    gray

    Senior Member
    Moderator
    Apr 22, 2003
    30,260
    #70
    Damn, it's not as simple as I thought. Still, the .shtml extension of the generated file is a clue. I tried putting SSI directives into the name field, using #include virtual="../index.php", but they didn't make it that easy for us :irritate: I got the message:

    If you are trying to use server side includes to solve the challenge, you are on the right track: but I have limited the commands allowed to ones relevant towards finding the password file for security reasons(because there will always be that one person who decides to execute some rather nasty commands). So please manipulate your code so that it is a little more pertaining to the level.
    any ideas Sarah or Martin? :(
     
    OP
    Martin

    Martin

    Senior Member
    Dec 31, 2000
    56,913
  • Thread Starter
  • Thread Starter #73
    ++ [ originally posted by gray ] ++
    Damn, it's not as simple as I thought. Still, the .shtml extension of the generated file is a clue. I tried putting SSI directives into the name field, using #include virtual="../index.php", but they didn't make it that easy for us :irritate: I got the message:

    any ideas Sarah or Martin? :(
    Yeah me too, tried including the index.php for level9 and just read the path to the password file verbatim.. :D But no, I've tried all kinds of things and I can't figure out what commands are allowed and "related to finding the password file". The easiest thing would be to do a
    <!-- #exec cmd="ls -la .." --> but of course allowing arbitrary code isn't what he intended us to do.
     
    OP
    Martin

    Martin

    Senior Member
    Dec 31, 2000
    56,913
  • Thread Starter
  • Thread Starter #76
    The password is stored in a text file.. is there any way you can get to that file? ;)
     

    Users Who Are Viewing This Thread (Users: 0, Guests: 1)