Please ask questions ONLY in this topic.

i am so lost

Post by amasarac on Sat Jun 20, 2009 12:20 am
([msg=25641]see i am so lost[/msg])

i found the hash but now i'm stuck. help would be good
amasarac
New User
New User
 
Posts: 2
Joined: Fri Jun 19, 2009 2:22 am
Blog: View Blog (0)


JTR problems

Post by always_watching on Sun Jun 21, 2009 2:27 pm
([msg=25698]see JTR problems[/msg])

I have the hash but when i try to crack it with JTR it says access denied. Im the administrator on this computer so im kind of at a loss. Help please?

Thanks
Always_watching
always_watching
New User
New User
 
Posts: 3
Joined: Tue Jun 16, 2009 2:37 pm
Blog: View Blog (0)


Re: Please ask questions ONLY in this topic.

Post by djtecha on Tue Jun 23, 2009 12:09 pm
([msg=25817]see Re: Please ask questions ONLY in this topic.[/msg])

For those who have found the hash and still have trouble with JTR you might wish to read http://www.osix.net/modules/article/?id=455
djtecha
New User
New User
 
Posts: 5
Joined: Fri Jun 19, 2009 12:48 pm
Blog: View Blog (0)


Re: Please ask questions ONLY in this topic.

Post by ds3 on Tue Jun 23, 2009 8:16 pm
([msg=25843]see Re: Please ask questions ONLY in this topic.[/msg])

I have read all the apache tutorials and know the file name the hash should be under (I think...) and I have found the directory, but how do I get permission to view the file? Every time I try I get the "You can't view that file" message.
I need the password to get the hash I need the hash to get the password...
Any hints?
ds3
New User
New User
 
Posts: 2
Joined: Mon Jun 22, 2009 7:22 pm
Blog: View Blog (0)


Re: Please ask questions ONLY in this topic.

Post by Defience on Wed Jun 24, 2009 10:18 am
([msg=25871]see Re: Please ask questions ONLY in this topic.[/msg])

ds3 wrote:I have read all the apache tutorials and know the file name the hash should be under (I think...) and I have found the directory, but how do I get permission to view the file? Every time I try I get the "You can't view that file" message.
I need the password to get the hash I need the hash to get the password...
Any hints?


Pay attention to the url.....,maybe it could come in handy here.
User avatar
Defience
Addict
Addict
 
Posts: 1279
Joined: Thu Jun 12, 2008 3:16 pm
Blog: View Blog (0)


Still no idea!!

Post by tomgeorge88 on Wed Jul 01, 2009 7:26 am
([msg=26082]see Still no idea!![/msg])

Well I've tried every possible way I can think of!But how do you get the hash file? I know where it should be!! but I simply can't access it. And the 16 pages of posts are just about cracking some hash which I believe was dealt with in realistic 6! :x
tomgeorge88
New User
New User
 
Posts: 6
Joined: Wed Jul 01, 2009 6:24 am
Blog: View Blog (0)


Re: Still no idea!!

Post by Defience on Wed Jul 01, 2009 3:17 pm
([msg=26100]see Re: Still no idea!![/msg])

tomgeorge88 wrote:Well I've tried every possible way I can think of!But how do you get the hash file? I know where it should be!! but I simply can't access it. And the 16 pages of posts are just about cracking some hash which I believe was dealt with in realistic 6! :x


Realistic 6 is about an encrypted message, real 7 deals with cracking hashes.
May the source be with you,
may the source be with you,
may the source be with you.

Think along the lines of basic 3, where you found something of interest and then put it somewhere useful.
User avatar
Defience
Addict
Addict
 
Posts: 1279
Joined: Thu Jun 12, 2008 3:16 pm
Blog: View Blog (0)


Re: Please ask questions ONLY in this topic.

Post by tomgeorge88 on Thu Jul 02, 2009 7:09 am
([msg=26130]see Re: Please ask questions ONLY in this topic.[/msg])

Well srry there was a hash in real 5!! and well I looked at the source but frankly I didn't find anything interesting except a directory listing which of course has a inaccessible directory!! any other clues? :?
tomgeorge88
New User
New User
 
Posts: 6
Joined: Wed Jul 01, 2009 6:24 am
Blog: View Blog (0)


Re: Clueless.

Post by greyshogun on Sun Jul 12, 2009 4:40 pm
([msg=26698]see Re: Clueless.[/msg])

sniper15 wrote:i'm not sure if this is a spoiler or not but here we go... the hashed file is called .htpasswd so you use that knowledge and that of directory transversal and a little bit of url exploitation and poof there you go. it will dis play the hash file as a broken image (image with a red X in the top right corner). i hope i didn't give to much information away. i didn't really tell you how to accomplish anything just where to look. hope that helps....

-sniper15


Thanks for the assistance, my man.

An additional technique that some of you may not be familiar with -- google hash cracking.

Many passwords have already been cracked and in this regard google is your friend.

Working through this puzzle though, I realize that I need to learn more about server security architecture (i.e. apache).
greyshogun
New User
New User
 
Posts: 18
Joined: Sun May 24, 2009 9:39 pm
Blog: View Blog (0)


Re: Please ask questions ONLY in this topic.

Post by unskilled on Fri Jul 17, 2009 5:10 pm
([msg=26922]see Re: Please ask questions ONLY in this topic.[/msg])

i've got a bit of a problem.

i figured this one out pretty much by myself, took me a while though. i've got the hash.

the problem is jtr says it can't run on x64 (vista) and i don't know what type of hash it is for cain. i'd be grateful if someone could either decode the hash for me or tell me what type of hash it is. i'm kinda new to all this (done a bit of html and javascript, and a little bit of c++ before but never proper hacking), so i don't really know how i'm supposed to tell what kinda hash it is. they all just look like big strings of letters/numbers.

cheers
unskilled
New User
New User
 
Posts: 1
Joined: Wed Jul 15, 2009 4:01 pm
Blog: View Blog (0)


PreviousNext

Return to (Real 7) What's Right For America

Who is online

Users browsing this forum: No registered users and 0 guests