Please ask questions ONLY in this topic.

Your friend is being cheated out of hundreds of dollars. Help him make things even again!

Re: Please ask questions ONLY in this topic.

Post by conscience on Fri Jun 21, 2019 10:38 am
([msg=98457]see Re: Please ask questions ONLY in this topic.[/msg])

coopersnick wrote:Hi All,

Just a question - is Uncle Arnolds page supposed to be functional before I do anything to it?
E.g. without editing the page if I just click and vote on stuff am I supposed to see a change in the score? I see nothing, the buttons have no effect.

So that means for the final result am I expected to modify the server state and be able to see a page that will load with the raging inferno right up top?

I ask because I know how to push in different values - and it will send me off to what I assume is the success page. However even there it just has a blue "Go On" button aiming at the next task. It doesn't actually say "success" or anything.


As far as I can recall, the server side just checks your input and if it fits the task, you get forwarded to the 'Go on' page.
Let him who hath understanding reckon the number of the beast, for it is a human number: His number is 0x029A.
conscience
Poster
Poster
 
Posts: 310
Joined: Thu Jan 08, 2009 9:05 pm
Location: 127.0.0.1
Blog: View Blog (0)


Re: Please ask questions ONLY in this topic.

Post by LizardQueen on Thu Jun 27, 2019 11:33 am
([msg=98517]see Re: Please ask questions ONLY in this topic.[/msg])

I completed the mission by locally changing the HTML source code, but I'm having trouble doing it using Javascript injection. Can anyone possibly help me see what I'm doing wrong? Maybe through a PM to prevent spoilers?
LizardQueen
New User
New User
 
Posts: 1
Joined: Thu Jun 27, 2019 11:30 am
Blog: View Blog (0)


Re: Please ask questions ONLY in this topic.

Post by conscience on Sat Jun 29, 2019 4:40 am
([msg=98532]see Re: Please ask questions ONLY in this topic.[/msg])

LizardQueen wrote:I completed the mission by locally changing the HTML source code, but I'm having trouble doing it using Javascript injection. Can anyone possibly help me see what I'm doing wrong? Maybe through a PM to prevent spoilers?


Sure. I can't guarantee I'll be quick though.
If you wish, send me your steps and results and we'll figure out where the possible misunderstanding comes from.
Let him who hath understanding reckon the number of the beast, for it is a human number: His number is 0x029A.
conscience
Poster
Poster
 
Posts: 310
Joined: Thu Jan 08, 2009 9:05 pm
Location: 127.0.0.1
Blog: View Blog (0)


Re: Please ask questions ONLY in this topic.

Post by und3x on Mon Sep 09, 2019 12:01 pm
([msg=99101]see Re: Please ask questions ONLY in this topic.[/msg])

Basic missions where much harder than this one.
Resolved in first attempt in 2 minutes. :twisted: :twisted: :twisted: :twisted:

But I worked with HTML no injections so can someone PM me and hep how to make injection in hacker stile because I use old stile hand work methods.
und3x
New User
New User
 
Posts: 6
Joined: Fri Aug 23, 2019 2:17 pm
Blog: View Blog (0)


Re: Please ask questions ONLY in this topic.

Post by conscience on Wed Sep 11, 2019 12:56 am
([msg=99119]see Re: Please ask questions ONLY in this topic.[/msg])

und3x wrote:... can someone PM me and hep how to make injection in hacker stile because I use old stile hand work methods.


There's really no "hacker style" to meet here. There's simply more than one method of solving this.
You can use a certain browser feature now present in all popular web browsers (a couple of years ago it required a separate browser plugin), or execute JavaScript, without touching any tools, that does the work for you, etc.
Whatever you can come up with to end up wherever you want to be (preferably without unwanted side effects in general).
These are all equally valid solutions.
You could even skip using a browser at all, but that'd be beyond what makes sense.

If I'm not mistaken, the method you are curious about is the no-tool one I mentioned above.
(Tip: Make sure your script does not have a return value as that'll overwrite your whole DOM)

Back in the day, the oldies (sorry guys, we're old AF, you'll have to live with it :mrgreen:) usually did it using either any of the aforementioned methods or... uhmm... let's put it this way: by downloading and editing something locally (which I guess is what you referred to as "hand work methods" - shall we call it a handjob? :?).

Sidenote: The "injection" everyone keeps and was talking about back then is actually not the proper name for the feature/technique, but if I gave you the right one, it'd give the whole thing away. Let's call it Somethinglet.

PS.: AFAIK Firefox currently won't work. Not completely sure what's up with it, but it won't execute JS via our subject method. You can enable a certain setting I believe...
Let him who hath understanding reckon the number of the beast, for it is a human number: His number is 0x029A.
conscience
Poster
Poster
 
Posts: 310
Joined: Thu Jan 08, 2009 9:05 pm
Location: 127.0.0.1
Blog: View Blog (0)


realistic 1

Post by Craigs on Thu Apr 02, 2020 7:20 pm
([msg=101941]see realistic 1[/msg])

Hi guys,
I'm still quite new to this,
Is there anything i need to learn, programmes or anything i need to download to start with these realistic missions?
Sorry if that sounds stupid.

Many thanks

-- Thu Apr 02, 2020 8:49 pm --

Hi.
I downloaded firebug but its not letting me edit the html code, am i doing something wrong?
Please help :cry:
Craigs
New User
New User
 
Posts: 1
Joined: Thu Apr 02, 2020 6:55 pm
Blog: View Blog (0)


Re: Please ask questions ONLY in this topic.

Post by conscience on Sat Apr 04, 2020 10:38 am
([msg=102025]see Re: Please ask questions ONLY in this topic.[/msg])

You don't need firebug anymore as its features have been integrated into Firefox (with all major browsers supporting similar tools) out of the box.
You just need to be able to submit your crafted data to get the results you want.

Think about how the bands are ranked and what would consquently put R.I. in front of the others.
As it has been given away countless times: The best course of action is to edit something in the DOM to send the data you need to.
Let him who hath understanding reckon the number of the beast, for it is a human number: His number is 0x029A.
conscience
Poster
Poster
 
Posts: 310
Joined: Thu Jan 08, 2009 9:05 pm
Location: 127.0.0.1
Blog: View Blog (0)


Re: Please ask questions ONLY in this topic.

Post by zera66 on Mon Apr 20, 2020 11:18 am
([msg=103389]see Re: Please ask questions ONLY in this topic.[/msg])

Hey! Loving the exercises so far!

When I click the vote button I see a 302 from this endpoint: https://www.hackthissite.org/missions/r ... d=3&vote=5 in the dev tools. Just wondering if thats to be expected, or if there might be a bug in the mission.
zera66
New User
New User
 
Posts: 1
Joined: Mon Apr 20, 2020 11:13 am
Blog: View Blog (0)


I have a question

Post by G4M1K3 on Thu Jul 09, 2020 9:38 pm
([msg=106610]see I have a question[/msg])

I'm have to make this somenthing in my screen or really change that?
G4M1K3
New User
New User
 
Posts: 1
Joined: Thu Jul 09, 2020 9:36 pm
Blog: View Blog (0)


Re: I have a question

Post by pretentious on Sat Jul 11, 2020 10:14 am
([msg=106723]see Re: I have a question[/msg])

G4M1K3 wrote:I'm have to make this somenthing in my screen or really change that?

Try and really change it.
Goatboy wrote:Oh, that's simple. All you need to do is dedicate many years of your life to studying security.

IF you feel like exchanging ASCII arrays, let me know ;)
Can you say brainwashing It's a non stop disco
User avatar
pretentious
Addict
Addict
 
Posts: 1213
Joined: Wed Mar 03, 2010 12:48 am
Blog: View Blog (0)


PreviousNext

Return to (Real 1) Uncle Arnold's Local Band Review

Who is online

Users browsing this forum: No registered users and 0 guests