Page 9 of 11

Re: Basic Mission 9

PostPosted: Fri Jun 23, 2017 8:54 pm
by j8ds
BasicPanda wrote:Easiest one by far even though it left me stumped for a bit. I was looking up directory traversal and reading up on HTML attacks; I was way off. I took a step back and redid mission 8, and re-visited the nature of the script like suggested. Perfection is the key, realize that if you try it, and it doesn't work, it means that the answer isn't 100% correct. Note your current environment or document if necessary.


that's right ! i've found out after i noted the whole directory tree :lol: :lol:

Re: Basic Mission 9

PostPosted: Tue Jul 18, 2017 11:32 pm
by wetwilly64_64
OH MAN. took me a good 30 minutes on this one as opposed to mission 8.

My hint (hopefully doesn't spoil it for people) to some of you reading this.

The 'gatekeeper' on mission 8 isn't there on mission 9 ;)

Re: Basic Mission 9

PostPosted: Wed Jul 19, 2017 7:55 am
by Ir777
You will need to call some php file from "somewhere not in level 9 directory ;) " in order to accept your SSI command, you will need to know how to pass parameter to that php file by adjusting arguments names ;) , and your SSI command should switch directory from its directory to the password file directory, you will need to know the structure of a php server so that you are not fooled with the given path which could make you do much more effort than needed to access the needed path.

it took me about 5 hours as I have very little knowledge of html, php, unix cli

it hurts but it is useful :D , thanks for all people in this great site.

Re: Basic Mission 9

PostPosted: Tue Aug 08, 2017 12:51 pm
by kbencze95
After reading through all the comments on this thread, I had to check the answer online..
I almost had it, only the syntax I used were not correct.
If you read through all the comments, you must have a basic idea about what you have to do ( and where). I knew my fault was propably in the syntax, but I didn't find much about using that particular command to navigate through the directories.

It felt bad that I was that close, still I had to check the solution online. My only advice is to try every variation with that particular command and eventually you'll work it out.

Re: Basic Mission 9

PostPosted: Wed Aug 09, 2017 9:00 am
by bhups
Amazing site ladies/gentlemen!
I was sooo stuck with this level and tried what I thought was all combinations for level 8, then tried to pay some attention to the text on level 9 and just kept bashing my head to think what was I not doing.

Then using hints on the forum, I see you have to REALLY look back at level 8 and use a very similar method to get the password for level 9.

Just did not pay enough attention on how to go through directories.

Re: Basic Mission 9

PostPosted: Fri Sep 15, 2017 2:54 pm
by ARtemachka
Actually this is pretty easy if u have finished 8 mission.
Hint if u got stuck: just imagine the files tree and where exactly the needed file is. Use the same command as in mission 8 and just change the argument to get the needed destination.

Re: Basic Mission 9

PostPosted: Sun Oct 01, 2017 5:59 pm
by MsNaioi
r3congized wrote:HOLY SHIT I hate you guys... I love you guys and hate you guys sooooo much... I was so focused on testing what commands would work I didn't even realize what wasn't allowed for 8 would be allowed for 9 due to how you were checking with your script.

That aside, has anyhow actually done this without explicitly using the file path at one point or another? (Hope this isn't too spoiler-ish)


I was really close of solving it, but this comment ended up solving it for me. Not sure if it is intended or not, but maybe admins can check it out again if it is or not too "spoilerish". Imo, we can think of it as a "team work" kind of thing :P

Re: Basic Mission 9

PostPosted: Wed Oct 04, 2017 3:38 pm
by d05bro
Alright, this one wasn't too bad. I will say that the knowledge I gained studying to complete 8 really helped. If you're struggling thing about what you did in 8, but do it with an absolute path for 9.

Might be too much of a spoiler... but these forums are dead anyhow :roll:

Re: Basic Mission 9

PostPosted: Tue Nov 28, 2017 2:32 am
by saidblue
hahahahaha,, read it slowly and imagine about level tree :D :D :D :D :D :D

Re: Basic Mission 9

PostPosted: Fri Dec 01, 2017 12:43 am
by dbench2003
OMG!! I read the hint and it instantly hit me. Hint to those who are probably so stuck they look to the end of this forum, practice using the command from the last mission in a linux terminal to browse the folders. Try all kinds of things using one line of code. Hope it helps