
ravingraver wrote:I don't really understand this... I'll try to be as discreet as possible (so I don't give away any answers) and maybe someone could pm me about it...
I dont understand how if "...the first occurance of '<--', and looks to see what follows directly after it. If it matches "#exec cmd="ls"-->" or "#exec cmd="ls /home/xec96/public_html/missions/basic/8/"-->" it accepts it. If it does not match any of the situations above, then it kicks the user out." and yet we can still execute something else in that input that is not one of those 2 options. Am I missing something?
P.S: I have the answer so please don't try to hide it (if you pm me). I just really don't understand it. Thanks


austinlab wrote:was that a hint or a correction. cause ya i looked it up and your right its a directory traversal or transversal. is there a difference between parent directory and directory traversal?

ravingraver wrote:I don't really understand this... I'll try to be as discreet as possible (so I don't give away any answers) and maybe someone could pm me about it...
I dont understand how if "...the first occurance of '<--', and looks to see what follows directly after it. If it matches "#exec cmd="ls"-->" or "#exec cmd="ls /home/xec96/public_html/missions/basic/8/"-->" it accepts it. If it does not match any of the situations above, then it kicks the user out." and yet we can still execute something else in that input that is not one of those 2 options. Am I missing something?
P.S: I have the answer so please don't try to hide it (if you pm me). I just really don't understand it. Thanks

banda wrote:ravingraver wrote:I don't really understand this... I'll try to be as discreet as possible (so I don't give away any answers) and maybe someone could pm me about it...
I dont understand how if "...the first occurance of '<--', and looks to see what follows directly after it. If it matches "#exec cmd="ls"-->" or "#exec cmd="ls /home/xec96/public_html/missions/basic/8/"-->" it accepts it. If it does not match any of the situations above, then it kicks the user out." and yet we can still execute something else in that input that is not one of those 2 options. Am I missing something?
P.S: I have the answer so please don't try to hide it (if you pm me). I just really don't understand it. Thanks
I think you are correct.
BTW to execute #exec cmd="ls /home/xec96/public_html/missions/basic/8/"--> how do you even think of this path??? I have no clue. To complete level8 I executed a command different from both above.


ravingraver wrote:Well by putting in something else, I meant the answer to mission 9.
And I didn't put the file path, i put ../ instead, for mission 8.

Defience wrote:
It's giving you that path as a hint.


Users browsing this forum: No registered users and 0 guests