Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

Security Challenge II (Web Hacking Intermediate)

Options
  • 11-05-2011 1:23am
    #1
    Closed Accounts Posts: 20,759 ✭✭✭✭


    Rules.

    No need for brute forcing or exploits. No DoS attacks, or attacks on the network. Will be monitoring logs - anyone going outside the challenge will be blacklisted.

    Challenge: http://republicofhack.dyndns.org/

    Best of luck. I'd estimate the challenge to be of medium difficulty, more difficult than my previous challenge - but not as difficult as Damo's last challenge.


«1

Comments

  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    Sweet, will take a look at it after work.


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    Cool :)

    Also can I add, there is no need for any automated scanners. This challenge is doable manually, and requires nothing beyond a few browser addons.


  • Closed Accounts Posts: 18,966 ✭✭✭✭syklops


    Is it still up? Im getting connection timed out..... :(


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    Server is backup, sorry about that.


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    1 completed so far :)


  • Advertisement
  • Closed Accounts Posts: 18,966 ✭✭✭✭syklops


    Stuck on the login screen


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    syklops wrote: »
    Stuck on the login screen
    You'll need to figure out how it's validated and what exactly is validating it
    .


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    done and done, nice challenge! :-)


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    Congrats Damo :) Glad you liked it.


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    Anyone else trying this?


  • Advertisement
  • Closed Accounts Posts: 2,486 ✭✭✭Redshift


    Is it possible to get SQLi through the WAF? I've tried various ways of encoding it :/ it's detected when plain but when encoded I cant determine if anything is being executed becuase I cant see any feedback


  • Closed Accounts Posts: 18,966 ✭✭✭✭syklops


    Redshift wrote: »
    Is it possible to get SQLi through the WAF? I've tried various ways of encoding it :/ it's detected when plain but when encoded I cant determine if anything is being executed becuase I cant see any feedback

    RedShift:
    I believe that SQLi is not necessary. Its something else...


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    Redshift wrote: »
    Is it possible to get SQLi through the WAF? I've tried various ways of encoding it :/ it's detected when plain but when encoded I cant determine if anything is being executed becuase I cant see any feedback
    If you stuck on the WAF itself, try the most basic query and narrow it down until you find how its detected. You won't have to do complicated encodings.


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    Redshift:
    You're doing well, it's not a tough WAF - I promise. Google WAF evasion and see if you can find anything.


  • Closed Accounts Posts: 2,486 ✭✭✭Redshift


    Am I right in saying that I can't use union at all as it's filtered and instead of going after password hashes I should try for a file using another keyword which is not filtered.
    Sorry if i'm not making sense.

    Will have another look tomorrow, have to get up for work :/


  • Registered Users Posts: 36 chuckleberryfin


    Thanks for this, spent a bit too much time on
    checking the tables
    but was fun.


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    Redshift wrote: »
    Am I right in saying that I can't use union at all as it's filtered and instead of going after password hashes I should try for a file using another keyword which is not filtered.
    Sorry if i'm not making sense.

    Will have another look tomorrow, have to get up for work :/
    You can use it but you need to evade the filter :) After that, there's another part - you'll see when you get there


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    Thanks for this, spent a bit too much time on
    checking the tables
    but was fun.

    congrats! :)


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    Server will be down for a few hours.


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    Back up again :)


  • Advertisement
  • Closed Accounts Posts: 18,966 ✭✭✭✭syklops


    Its no good now, is it? Where was it at 8am this morning when I had time to throw sh1t at it? :mad:

    Seriously though its a great challenge. If I could only figure out where the Womens auxiliary air force came into it.


  • Registered Users Posts: 367 ✭✭900913


    Great challenge. I found one part really difficult.


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    900913 wrote: »
    Great challenge. I found one part really difficult.

    Msg me which part =)

    And congrats!


  • Closed Accounts Posts: 5,082 ✭✭✭Pygmalion


    Thanks for this, spent a bit too much time on
    checking the tables
    but was fun.

    Same, I spent pretty much all last night trying to
    Find usernames/passwords in the SQL database
    , had a look at the
    WAF evasion
    today and got it within a few minutes :P.
    Also, apologies if my method of getting table and column names counted as brute-forcing or was a bit excessive, that was before I had a look at the WAF evasion and that was the only way I could think of to get them :P

    Also since 900913 is down as "900913 cheated" in the HoF, is there an interesting story behind this or something?
    Would be interesting to see how he did it if so :P


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    I sent him a message asking about that, I'm awaiting a response :)


  • Registered Users Posts: 367 ✭✭900913


    I used an application(acunetix http editor) instead of a firefox plugin to postdata


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    There is some server abuse, if it continues I will take it offline. This is the only warning. I hosted this challenge for people to have fun, and not to abuse it.


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    Server offline on account of misbehaviour. Will be examining the logs and certain people will be blacklisted from future events.

    Successfully completed challenge:
    sk
    Damo2k
    netjester
    chuckleberryfinn
    900913
    Pygmalion


  • Closed Accounts Posts: 2,486 ✭✭✭Redshift


    Arrgh, just had that excited feeling of I think I know how to do this and just as I hit submit Bam Server gone.
    Damn you whoever was fooling about:mad:


  • Advertisement
  • Registered Users Posts: 379 ✭✭jim_bob


    me too, although i doubt i was as close:o

    any chance of bring it back


Advertisement