TryThis0ne >> Challenges >> Realistic
P0wW0w level
Viewers: :
Quick reply
Reply
New Topic
 
K32.nix




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 78




Send Email Top
Sent on: 13/04/2009, 17:42:24 Reply | Quote | Warn | Edit
doubt,s hints, anything related to this chal...post here!

Ratinho




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 52




Send Email Top
Sent on: 14/04/2009, 17:55:02 Reply | Quote | Warn | Edit
mhmhhm =\
hint plz :S
brute force on the folders and files??? :s

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 14/04/2009, 18:18:04 Reply | Quote | Warn | Edit
try to do this chall with sniffer

K32.nix




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 78




Send Email Top
Sent on: 14/04/2009, 23:45:17 Reply | Quote | Warn | Edit
The only thing i can't understand are those "|"... =P
shouldn't it be "/"?

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 15/04/2009, 23:45:00 Reply | Quote | Warn | Edit
ah?

K32.nix




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 78




Send Email Top
Sent on: 16/04/2009, 08:24:00 Reply | Quote | Warn | Edit
I've got the message with "arrays"... i tried to unescape() it... (i think i'm not on the right way) and i got those "|" intead of what i thought it should be.."/".

Any light at the tunnel's end?

zEt0s-




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 130




Top
Sent on: 16/04/2009, 12:28:14 Reply | Quote | Warn | Edit
Dude, i'm not sure we talk about the same lvl :P

Ratinho




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 52




Send Email Top
Sent on: 16/04/2009, 14:52:54 Reply | Quote | Warn | Edit
cp77fk4r:
try to do this chall with sniffer


well i tried again....but i found only the regular http requests...and some tcp but not something helpful...

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 16/04/2009, 17:02:43 Reply | Quote | Warn | Edit
sometimes, regular http req or _cookies_ can be very helpful to locate directory on a server...

and it's a very big hint!

Ratinho




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 52




Send Email Top
Sent on: 17/04/2009, 01:50:49 Reply | Quote | Warn | Edit
ok passed
ppl, u need to delete the cookies of the forum for this level...pay attention!

Garfield




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 7




Send Email Top
Sent on: 21/04/2009, 22:55:26 Reply | Quote | Warn | Edit
I deleted cache & cookies, and the only thing i get after refrshing the page is a new cookie with a new phpsessid
I sniffed with wireshark too, without luck

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 21/04/2009, 23:12:08 Reply | Quote | Warn | Edit
Try to think how can you use this session to locate the file that create it!

Garfield




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 7




Send Email Top
Sent on: 21/04/2009, 23:28:59 Reply | Quote | Warn | Edit
Passed now. The idea came just after writing my message above :)

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 21/04/2009, 23:46:00 Reply | Quote | Warn | Edit
;)

tomer321




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 120




Send Email Top
Sent on: 24/04/2009, 00:32:45 Reply | Quote | Warn | Edit
i read your posts but i still don't know what to do with the phpsessid cookie or the http request... help please

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 27/04/2009, 12:14:41 Reply | Quote | Warn | Edit
Try to read about session and session flexing.

All the times are GMT+2, ISRAEL
TryThis0ne >> Challenges >> Realistic

Page: 1, 2
Quick reply
Reply
New Topic


Page generated using: 12 queries
Design by SBD © GeHeNoM.Net | Powered By Tera-Byte Forums 1.5 © JonJon & HLL
ý