I wonder if anyone can point me in the right direction since I'm kinda stuck. So far, I've been able to determine that there's at least 6 different usernames, using the 'User Info' search, for different variations on Gary Hunter. 3 require a password, 2 do not require a password and 1 (admin) has a password of 'admin' and it's at this point I'm sorta stuck.
I noticed the 'cleardir.php' uses a 'dir' in the form of '<username>SQLFiles' which leads me to believe a SQL server is involved. I also noticed that when you login to the latter 3 accounts, it displays a 'Password: <some-hash>' on the page which I'm currently trying in a MD2 hash crack.
Can anyone steer me in the right direction? I know I'm missing something. EDITED BY FAITHPlease ask questions only in this topic.
Just to keep the forum neat, and hopefully your post more noticed.
Please help us to keep the forum clean by report trashy posts. :>
You may start a new post if you're making a tutorial. However, if the tutorials are similar, please do not make two.
I wish you best luck with this mission, and hope you enjoy it.