Please ask questions ONLY in this topic.

Racist pigs are organizing an 'anti-immigrant' rally in Chicago. Help anti-racist activists take over their website!

Re: Please ask questions ONLY in this topic.

Post by N3nvy on Tue May 28, 2013 6:52 am
([msg=75819]see Re: Please ask questions ONLY in this topic.[/msg])

I found the hidden path straight away, and from there it was a simple Google search to what a SQL Injection was. The answer is given to you instantly on some sites, so keep looking until you find the right solution.
N3nvy
New User
New User
 
Posts: 8
Joined: Mon May 27, 2013 9:15 am
Blog: View Blog (0)


Re: Please ask questions ONLY in this topic.

Post by darthvaderish on Tue Jun 04, 2013 4:18 am
([msg=75944]see Re: Please ask questions ONLY in this topic.[/msg])

Just a question, but can you use Firebug to change the password protocol?
darthvaderish
New User
New User
 
Posts: 1
Joined: Tue Jun 04, 2013 3:48 am
Blog: View Blog (0)


Re: Please ask questions ONLY in this topic.

Post by -Ninjex- on Tue Jun 04, 2013 6:09 pm
([msg=75955]see Re: Please ask questions ONLY in this topic.[/msg])

darthvaderish wrote:Just a question, but can you use Firebug to change the password protocol?


Well, to answer your question in short, you can change any of the visible source code using firebug.
Whether your changes will actually take affect server side, is another story.
If you're not willing to learn, no one can help you. If you're determined to learn, no one can stop you.⠠⠵
The absence of evidence is not evidence of absence.
I can explain it for you, but I can't understand it for you.
User avatar
-Ninjex-
Addict
Addict
 
Posts: 1344
Joined: Sun Sep 02, 2012 8:02 pm
Blog: View Blog (0)


Re: Please ask questions ONLY in this topic.

Post by Skyfa11 on Fri Jun 14, 2013 10:12 pm
([msg=76113]see Re: Please ask questions ONLY in this topic.[/msg])

Do I need to use classic sql injections or more advanced stuff for this.
here's the website im using: http://www.sqlinjection.net/
User avatar
Skyfa11
New User
New User
 
Posts: 33
Joined: Sat Mar 09, 2013 1:04 am
Blog: View Blog (0)


Re: Please ask questions ONLY in this topic.

Post by -Ninjex- on Fri Jun 14, 2013 10:50 pm
([msg=76114]see Re: Please ask questions ONLY in this topic.[/msg])

Skyfa11 wrote:Do I need to use classic sql injections or more advanced stuff for this.
here's the website im using: http://www.sqlinjection.net/


That website has too much information for me to look over to tell you if it has the correct methodology for this type of attack. However, browsing through it explains how the attack of an sqli works in pretty good detail. You just need to keep in mind that anywhere the website is grabbing information from a database, it may be exploitable via sqli. Such as login fields, URL parameters, or even a regular form with seemingly unimportant data being stored into a database. This is a great opportunity to think outside of the box, and be creative with what you have learned so far about sqli.
If you're not willing to learn, no one can help you. If you're determined to learn, no one can stop you.⠠⠵
The absence of evidence is not evidence of absence.
I can explain it for you, but I can't understand it for you.
User avatar
-Ninjex-
Addict
Addict
 
Posts: 1344
Joined: Sun Sep 02, 2012 8:02 pm
Blog: View Blog (0)


Re: Please ask questions ONLY in this topic.

Post by John-Doe252 on Tue Jul 09, 2013 12:49 am
([msg=76387]see Re: Please ask questions ONLY in this topic.[/msg])

Hi guys!

I found the /update.php page, to enter the login data. There I did what is necessary to complete the message.

I love your stuff guys. But for learning it would be incredibly helpful to me if the statements you put in actually return data instead of just completeing the mission. Just wanted to add that as a feedback :).

Johnny
John-Doe252
New User
New User
 
Posts: 7
Joined: Tue Jul 09, 2013 12:35 am
Blog: View Blog (0)


Whoops

Post by Basiclife on Thu Aug 08, 2013 8:47 am
([msg=76782]see Whoops[/msg])

So... A colleague of mine is doing some of the realistic missions and I'm lending a hand whenever he gets too stuck. After about 3 hours on mission #2, he finally gave up and came to ask me for help.

It turns out that he'd followed the links to the gifs, then started working up the directory structure. The problem is, the images are linked directly to the real American Nazi party website and he's spent the last 3 hours trying to hack them...

As he's new 'round here, he assumed it was common for the "realistic" missions to have their own domains, etc. I wondered why he'd been saying things like "This is a very complex mockup"
Basiclife
New User
New User
 
Posts: 1
Joined: Sun Apr 13, 2008 6:48 pm
Blog: View Blog (0)


Re: Whoops

Post by -Ninjex- on Thu Aug 08, 2013 3:43 pm
([msg=76787]see Re: Whoops[/msg])

Basiclife wrote:So... A colleague of mine is doing some of the realistic missions and I'm lending a hand whenever he gets too stuck. After about 3 hours on mission #2, he finally gave up and came to ask me for help.

It turns out that he'd followed the links to the gifs, then started working up the directory structure. The problem is, the images are linked directly to the real American Nazi party website and he's spent the last 3 hours trying to hack them...

As he's new 'round here, he assumed it was common for the "realistic" missions to have their own domains, etc. I wondered why he'd been saying things like "This is a very complex mockup"


hahaha, that's a great laugh right there. I suppose hackthissite should have those pictures stored and pulled locally instead.
If you're not willing to learn, no one can help you. If you're determined to learn, no one can stop you.⠠⠵
The absence of evidence is not evidence of absence.
I can explain it for you, but I can't understand it for you.
User avatar
-Ninjex-
Addict
Addict
 
Posts: 1344
Joined: Sun Sep 02, 2012 8:02 pm
Blog: View Blog (0)


Re: Stuck

Post by Rename on Wed Aug 28, 2013 2:01 pm
([msg=77088]see Re: Stuck[/msg])

GTADarkDude wrote:You don't need to find a password.
Google SQL Injection ;)


what do oyu mean by that i can\t seem to login
Rename
New User
New User
 
Posts: 2
Joined: Wed Aug 28, 2013 11:49 am
Blog: View Blog (0)


Re: Stuck

Post by fashizzlepop on Wed Aug 28, 2013 2:18 pm
([msg=77089]see Re: Stuck[/msg])

Rename wrote:
GTADarkDude wrote:You don't need to find a password.
Google SQL Injection ;)


what do oyu mean by that i can\t seem to login


There, read it again.
The glass is neither half-full nor half-empty; it's merely twice as big as it needs to be.
User avatar
fashizzlepop
Developer
Developer
 
Posts: 2303
Joined: Sat May 24, 2008 1:20 pm
Blog: View Blog (0)


PreviousNext

Return to (Real 2) Chicago American Nazi Party

Who is online

Users browsing this forum: No registered users and 0 guests