Please ask questions only in this topic.

Re: Please ask questions only in this topic.

Post by lambda0 on Wed Jun 24, 2009 4:17 pm
([msg=25886]see Re: Please ask questions only in this topic.[/msg])

A bit of handy advice: when you find a way to "list" the files of ~/realistic/14/ it would be smart to view the source directly as your browser will most likely kill the first line of files. Note the viewing it normally won't show the 2 things EVERY directory should have: "." and "..".
User avatar
lambda0
New User
New User
 
Posts: 20
Joined: Sun May 04, 2008 7:00 am
Blog: View Blog (0)


Re: Please ask questions only in this topic.

Post by eljonto on Wed Jun 24, 2009 8:13 pm
([msg=25893]see Re: Please ask questions only in this topic.[/msg])

vbCrLf wrote:I'm stuck at the moderator panel for so much time. Which username should I search for?

you don't know specific usernames so you know you can't enter one. Think- who would be the first user to be mad on a forum site set up by an admin? now think, since the input isn't a username, it must be a command, and what command will allows you to view the poisition in the data table where the admin username would be.
-Quis custodiet ipsos custodes?, Juvenal
_________________________________________________________________
User avatar
eljonto
Poster
Poster
 
Posts: 373
Joined: Thu Apr 17, 2008 1:16 am
Location: Australia
Blog: View Blog (0)


Re: Please ask questions only in this topic.

Post by vbCrLf on Thu Jun 25, 2009 3:27 pm
([msg=25907]see Re: Please ask questions only in this topic.[/msg])

eljonto wrote:
vbCrLf wrote:I'm stuck at the moderator panel for so much time. Which username should I search for?

you don't know specific usernames so you know you can't enter one. Think- who would be the first user to be mad on a forum site set up by an admin? now think, since the input isn't a username, it must be a command, and what command will allows you to view the poisition in the data table where the admin username would be.

First user to be mad? I don't get you... Can't think of anyone/anything. :?
Regarding the command, is it some sort of SQL injection?

Thanks,
Ori.
vbCrLf
New User
New User
 
Posts: 4
Joined: Sat Apr 25, 2009 7:12 pm
Blog: View Blog (0)


Re: Please ask questions only in this topic.

Post by secdef9 on Thu Jun 25, 2009 3:50 pm
([msg=25909]see Re: Please ask questions only in this topic.[/msg])

vbCrLf wrote:
eljonto wrote:
vbCrLf wrote:I'm stuck at the moderator panel for so much time. Which username should I search for?

you don't know specific usernames so you know you can't enter one. Think- who would be the first user to be mad on a forum site set up by an admin? now think, since the input isn't a username, it must be a command, and what command will allows you to view the poisition in the data table where the admin username would be.

First user to be mad? I don't get you... Can't think of anyone/anything. :?
Regarding the command, is it some sort of SQL injection?

Thanks,
Ori.


You're on the right path. Go wild
User avatar
secdef9
New User
New User
 
Posts: 9
Joined: Sat Jan 31, 2009 12:45 pm
Blog: View Blog (0)


Re: Please ask questions only in this topic.

Post by vbCrLf on Thu Jun 25, 2009 4:27 pm
([msg=25913]see Re: Please ask questions only in this topic.[/msg])

secdef9 wrote:
vbCrLf wrote:
eljonto wrote:you don't know specific usernames so you know you can't enter one. Think- who would be the first user to be mad on a forum site set up by an admin? now think, since the input isn't a username, it must be a command, and what command will allows you to view the poisition in the data table where the admin username would be.

First user to be mad? I don't get you... Can't think of anyone/anything. :?
Regarding the command, is it some sort of SQL injection?

Thanks,
Ori.


You're on the right path. Go wild

I read your post again and again and couldn't think of anything wilder. Until I read it loudly :D That was really wild.
Without your last word I would never get that. Thanks secdef9 and eljonto :)
vbCrLf
New User
New User
 
Posts: 4
Joined: Sat Apr 25, 2009 7:12 pm
Blog: View Blog (0)


Re: Please ask questions only in this topic.

Post by eljonto on Fri Jun 26, 2009 11:30 pm
([msg=25963]see Re: Please ask questions only in this topic.[/msg])

err yeah, that was a typo- sorry, i meant to write 'made' not 'mad' O.o
-Quis custodiet ipsos custodes?, Juvenal
_________________________________________________________________
User avatar
eljonto
Poster
Poster
 
Posts: 373
Joined: Thu Apr 17, 2008 1:16 am
Location: Australia
Blog: View Blog (0)


Re: Please ask questions only in this topic.

Post by T0ha on Fri Jul 17, 2009 3:51 pm
([msg=26916]see Re: Please ask questions only in this topic.[/msg])

Hi,
could you give me a hint where can i found name of account to view it in m*******r.c** file.
But please be more specific.
T0ha
New User
New User
 
Posts: 1
Joined: Fri Jul 17, 2009 3:45 pm
Blog: View Blog (0)


Re: Please ask questions only in this topic.

Post by relictus on Mon Jul 20, 2009 1:59 am
([msg=27004]see Re: Please ask questions only in this topic.[/msg])

My problem is that I can't see the source of the m********.cgi file; the approach using null byte poisoning that I used for listing the files in the directory fails when applied to that file, while it works for other files in the same directory. Can anybody give me an hint?
archlinux user ~ wannabe hacker
User avatar
relictus
New User
New User
 
Posts: 21
Joined: Sat Jul 18, 2009 1:12 pm
Blog: View Blog (0)


Re: Please ask questions only in this topic.

Post by bala-linux on Tue Jul 21, 2009 2:06 am
([msg=27095]see Re: Please ask questions only in this topic.[/msg])

relictus wrote:My problem is that I can't see the source of the m********.cgi file; the approach using null byte poisoning that I used for listing the files in the directory fails when applied to that file, while it works for other files in the same directory. Can anybody give me an hint?

Same issue :( Looks like not able to view the source for any cgi. Any hint please ?

FYI : I am getting "Malformed Request".
bala-linux
New User
New User
 
Posts: 1
Joined: Tue Jul 14, 2009 1:39 am
Blog: View Blog (0)


Re: Please ask questions only in this topic.

Post by Defience on Tue Jul 21, 2009 9:18 am
([msg=27127]see Re: Please ask questions only in this topic.[/msg])

It seems that there is currently an issue with that part of the mission, please submit it a bug report so that a developer may correct it. Thanks.
User avatar
Defience
Addict
Addict
 
Posts: 1265
Joined: Thu Jun 12, 2008 3:16 pm
Blog: View Blog (0)


PreviousNext

Return to (Real 14) Yuppers Internet Solutions

Who is online

Users browsing this forum: No registered users and 0 guests