Basic Mission 8

Learn new things
Forum rules
DO NOT POST ANSWERS OR SPOILERS! [IE: Mission Links, Mission File Names/Pages, Scripts, etc.]

Posting these will result in warnings/bans!

Re: Basic Mission 8

Post by DaMoNarch on Sat Jan 05, 2013 7:08 pm
([msg=72050]see Re: Basic Mission 8[/msg])

streetroddingAg wrote:It's been posted about a dozen times (at least) in this thread, but I'll emphasize again: all you need to solve this can be found in the following two links:

http://httpd.apache.org/docs/1.3/howto/ssi.html

and

http://www.computerhope.com/unix/uls.htm

Once you figure that out, be very VERY mindful of your url bar (that cost me some extra time). I kinda feel dumb for that part.



I finally got it after this hint! The format of the command has to be very specific. Seems like spaces and everything must be exact. I was typing in the correct command but was not formatting it with the correct spacing. :evil:
DaMoNarch
New User
New User
 
Posts: 4
Joined: Sat Jan 05, 2013 4:29 pm
Blog: View Blog (0)


Re: Basic Mission 8

Post by shailx7 on Fri Jan 11, 2013 8:15 am
([msg=72201]see Re: Basic Mission 8[/msg])

One thing i dont understand that SSI is supposed to be from server side ok? we r user i mean client ok? so how can we use this SSI.......
shailx7
New User
New User
 
Posts: 3
Joined: Thu Jan 10, 2013 6:46 am
Blog: View Blog (0)


Re: Basic Mission 8

Post by pharous on Fri Jan 11, 2013 12:36 pm
([msg=72203]see Re: Basic Mission 8[/msg])

shailx7 wrote:One thing i dont understand that SSI is supposed to be from server side ok? we r user i mean client ok? so how can we use this SSI.......


I have yet to read the basic information, so don't take it as truth without confirming yourself, but my guess is that those are commands that are executed completely serverside. you can still manipulate the commands, just not the progress of executing them.
pharous
New User
New User
 
Posts: 1
Joined: Thu Jan 10, 2013 7:19 am
Blog: View Blog (0)


Re: Basic Mission 8

Post by shailx7 on Fri Jan 11, 2013 12:45 pm
([msg=72204]see Re: Basic Mission 8[/msg])

^PLZ ELABORATE i have completed my mission but i didn't able to understand some things---

1. SSI supposed to work or add functionality from the serverside while we are client by the time we submit name. then how it works?
2. why cant we use password line as the command line?
3. There is nothing that i found related with php on the source code of the level8 page...then what did that asshole's daughter did with php.
4. how that thing xyz.php tells password which is supposed call the function which tells letters in name?

"IF I SHOWED ANY DUMBNESS PLZ EXCUSE I M A LEARNER"
shailx7
New User
New User
 
Posts: 3
Joined: Thu Jan 10, 2013 6:46 am
Blog: View Blog (0)


Re: Basic Mission 8

Post by KthProg on Wed Jan 23, 2013 8:18 pm
([msg=72577]see Re: Basic Mission 8[/msg])

Ok i used the correct command, got all of the file names, but Im not sure what url to find them in.
none go to an existing file.

i dont think posting this would be a spoiler, most windows users, myself included, would not even know that the var/... has anything to do with unix.

EDIT: Nevermind I was using the wrong command, you should offer a brief explanation that var/ is in the root directory on unix systems.

EDIT EDIT: Apparently i solved it without understanding why it worked. nevermind my last edit.
Last edited by KthProg on Wed Jan 23, 2013 8:50 pm, edited 2 times in total.
User avatar
KthProg
Poster
Poster
 
Posts: 219
Joined: Wed Jan 23, 2013 7:06 pm
Blog: View Blog (0)


Re: Basic Mission 8

Post by fashizzlepop on Wed Jan 23, 2013 8:29 pm
([msg=72578]see Re: Basic Mission 8[/msg])

Try again, one of them should give you the password.
The glass is neither half-full nor half-empty; it's merely twice as big as it needs to be.
User avatar
fashizzlepop
Moderator
Moderator
 
Posts: 2145
Joined: Sat May 24, 2008 1:20 pm
Blog: View Blog (0)


Re: Basic Mission 8

Post by dydrax on Sun Jan 27, 2013 11:07 pm
([msg=72749]see Re: Basic Mission 8[/msg])

If you are trying to use server side includes to solve the challenge, you are on the right track: but I have limited the commands allowed to ones relevant towards finding the password file for security reasons(because there will always be that one person who decides to execute some rather nasty commands). So please manipulate your code so that it is a little more pertaining to the level.

how can i get out from tmp directory ???
i only use jump back command,then it block
dydrax
New User
New User
 
Posts: 1
Joined: Sun Jan 27, 2013 7:33 am
Blog: View Blog (0)


Re: Basic Mission 8

Post by fashizzlepop on Mon Jan 28, 2013 3:07 pm
([msg=72787]see Re: Basic Mission 8[/msg])

You are only able to submit one command. This command will have to do everything you need it to. You can't take this one step at a time.
The glass is neither half-full nor half-empty; it's merely twice as big as it needs to be.
User avatar
fashizzlepop
Moderator
Moderator
 
Posts: 2145
Joined: Sat May 24, 2008 1:20 pm
Blog: View Blog (0)


Re: Basic Mission 8

Post by 1njustice on Fri Feb 01, 2013 8:23 am
([msg=73141]see Re: Basic Mission 8[/msg])

My cyber GOD!
I was doing the same executing the same command string for an hour until I realized there was a space where there shouldn't of been.. My hint would be, check your spaces!

Just joined this forum & site and are loving it so far. Thanks for all the hard work keeping people like me entertained on the web! Keep up the good work, expect a donation from me real soon.
Last updated: 01/02/2013: 14:49

Code: Select all
Challenges
Basic missions: 1 - 11 complete
User avatar
1njustice
New User
New User
 
Posts: 23
Joined: Fri Feb 01, 2013 7:26 am
Blog: View Blog (0)


Re: Basic Mission 8

Post by thehackertoyou on Tue Feb 05, 2013 9:52 pm
([msg=73499]see Re: Basic Mission 8[/msg])

So what's the diff between php and ssi? and how can I tell the difference between those two and html by viewing the page source?
thehackertoyou
New User
New User
 
Posts: 6
Joined: Tue Jan 01, 2013 1:27 pm
Blog: View Blog (0)


PreviousNext

Return to Basic

Who is online

Users browsing this forum: No registered users and 0 guests