Challenge - Password is a file

General technological topics without their own forum go here

Challenge - Password is a file

Post by rasm910a on Tue Apr 16, 2013 11:18 am
([msg=75158]see Challenge - Password is a file[/msg])

I recently got a challenge from a friend, he made a temporary website that i need to find and logon the admin account.
The only problem is I haven't learned to do this through the multiple courses on this site.
He has made it such that you need to upload a specific file to enter the site. No username or password.

This is what i got from the admin login site:


<form action='' method='POST' enctype='multipart/form-data'>
<input type='file' name='passfile'>
<input type='submit' name='submit_login' value='Log Ind'>
</form>

There's a lot of beers waiting on me if i succeed!
rasm910a
New User
New User
 
Posts: 5
Joined: Tue Apr 16, 2013 11:13 am
Blog: View Blog (0)


Re: Challenge - Password is a file

Post by limdis on Tue Apr 16, 2013 2:06 pm
([msg=75160]see Re: Challenge - Password is a file[/msg])

Would you be willing to link the site? There just isn't enough information here.
If you do link, make sure your friend has something on the site that indicates that it is a test site for you.
"The quieter you become, the more you are able to hear..."
"Drink all the booze, hack all the things."
User avatar
limdis
Moderator
Moderator
 
Posts: 1346
Joined: Mon Jun 28, 2010 5:45 pm
Blog: View Blog (0)


Re: Challenge - Password is a file

Post by rasm910a on Tue Apr 16, 2013 2:47 pm
([msg=75162]see Re: Challenge - Password is a file[/msg])

*removed until consent given*

Its a danish website, he took it from a currently active website where he is admin and he popably hasnt given any hints.
rasm910a
New User
New User
 
Posts: 5
Joined: Tue Apr 16, 2013 11:13 am
Blog: View Blog (0)


Re: Challenge - Password is a file

Post by limdis on Tue Apr 16, 2013 4:00 pm
([msg=75165]see Re: Challenge - Password is a file[/msg])

So there will be no issues when we contact the admin with a link to this thread then?
"The quieter you become, the more you are able to hear..."
"Drink all the booze, hack all the things."
User avatar
limdis
Moderator
Moderator
 
Posts: 1346
Joined: Mon Jun 28, 2010 5:45 pm
Blog: View Blog (0)


Re: Challenge - Password is a file

Post by hellow533 on Tue Apr 16, 2013 5:02 pm
([msg=75166]see Re: Challenge - Password is a file[/msg])

limdis wrote:So there will be no issues when we contact the admin with a link to this thread then?

Don't take this personally, it's just that HTS could be held partially responsible/liable if we aided you in hacking an actual website you have no permission to. It's safer for everybody this way. If it does turn out to be nothing more than a target site, then best of luck to you.
“Teach me how to hack!”
"What, like, with an axe?"
User avatar
hellow533
Contributor
Contributor
 
Posts: 506
Joined: Thu Jan 29, 2009 3:27 pm
Blog: View Blog (0)


Re: Challenge - Password is a file

Post by rasm910a on Wed Apr 17, 2013 3:04 am
([msg=75174]see Re: Challenge - Password is a file[/msg])

Well it wouldn't be to a problem if you contact the admin, his name is Daniel A H. But if he knows i got helped i wouldn't get any reward for it. At least thats what I would.
rasm910a
New User
New User
 
Posts: 5
Joined: Tue Apr 16, 2013 11:13 am
Blog: View Blog (0)


Re: Challenge - Password is a file

Post by Ice_giant on Wed Apr 17, 2013 4:26 am
([msg=75176]see Re: Challenge - Password is a file[/msg])

So, I uploaded something randomly and this is the page what I got,
*removed until consent given*

Was that usefull? ;)
Ice_giant
New User
New User
 
Posts: 4
Joined: Wed Feb 20, 2013 8:44 am
Blog: View Blog (0)


Re: Challenge - Password is a file

Post by hellow533 on Wed Apr 17, 2013 5:00 am
([msg=75177]see Re: Challenge - Password is a file[/msg])

Ice_giant wrote:So, I uploaded something randomly and this is the page what I got,
*removed until consent given*

Was that usefull? ;)

Not in the slightest, that shows just about nothing to us. It's nothing more than another page. Actually it might be the same page.

I wouldn't try messing around until we hear back from the admin of the site.
“Teach me how to hack!”
"What, like, with an axe?"
User avatar
hellow533
Contributor
Contributor
 
Posts: 506
Joined: Thu Jan 29, 2009 3:27 pm
Blog: View Blog (0)


Re: Challenge - Password is a file

Post by rasm910a on Wed Apr 17, 2013 8:26 am
([msg=75184]see Re: Challenge - Password is a file[/msg])

What kind of response do you want from the Admin of the side?
rasm910a
New User
New User
 
Posts: 5
Joined: Tue Apr 16, 2013 11:13 am
Blog: View Blog (0)


Re: Challenge - Password is a file

Post by hellow533 on Wed Apr 17, 2013 8:31 am
([msg=75185]see Re: Challenge - Password is a file[/msg])

Something saying it's cool for you to pen test the website.
“Teach me how to hack!”
"What, like, with an axe?"
User avatar
hellow533
Contributor
Contributor
 
Posts: 506
Joined: Thu Jan 29, 2009 3:27 pm
Blog: View Blog (0)


Next

Return to General

Who is online

Users browsing this forum: No registered users and 0 guests