Advertisement
Help Keep Boards Alive. Support us by going ad free today. See here: https://subscriptions.boards.ie/.
If we do not hit our goal we will be forced to close the site.

Current status: https://keepboardsalive.com/

Annual subs are best for most impact. If you are still undecided on going Ad Free - you can also donate using the Paypal Donate option. All contribution helps. Thank you.
https://www.boards.ie/group/1878-subscribers-forum

Private Group for paid up members of Boards.ie. Join the club.

Security Challenge 1 re-visited.

  • 01-02-2012 11:33PM
    #1
    Closed Accounts Posts: 2,267 ✭✭✭


    Decided to put this back up for people who missed it. If your stuck, you can look through the old threads. The old threads also contain a solution if your really stuck. Passwords and stuff have been changed since.


    The other challenges aren't suitable to host on free hosting.

    http://damo.clanteam.com/sch1


Comments

  • Registered Users, Registered Users 2 Posts: 367 ✭✭900913


    I enjoyed that. I could spend hours on end messing with these types of vulnerabilities.

    Thanks :-)


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    Unless I had something cached, there was no challenge to complete - Just a hall of fame page without authentication? Unless it's saved from the last time I did it? Confused..


  • Registered Users, Registered Users 2 Posts: 420 ✭✭gouche


    I had the same issue as dlofnep - clicked admin button and it allowed me to put name on Hall of Fame.

    Feel free to delete my name as I didn't actually complete the challenge:P


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    Oops, accidentally ran some "fixer" on the free hosting last night which modified some important files I had hosted. Its fixed now though.


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    Cool done. I noticed you implemented extra security on other areas of the system this time ;)


  • Advertisement
  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    dlofnep wrote: »
    Cool done. I noticed you implemented extra security on other areas of the system this time ;)

    heheh not me, that comes as part of the free web-hosting :-)


  • Registered Users, Registered Users 2 Posts: 367 ✭✭900913


    Are you going to re-visit any more of the older challenges?

    I think these challenges are great for learning, I've learned lots of new stuff the fun way :-)


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    I'm afraid the other challenges aren't really suitable to host on free webspace.


  • Closed Accounts Posts: 7,144 ✭✭✭DonkeyStyle \o/


    Thanks. Very educational. And a bit scary, which is always a good sign.
    Had JTR running for about 90 mins on 4 cores, then tried the 'all' wordlist and got it in a split second (facepalm)


  • Registered Users, Registered Users 2 Posts: 1,689 ✭✭✭JimmyCrackCorn


    I have it


    Nice one btw. Enjoyed that allot.
    Need to get wordlists off machine i packed away.


  • Advertisement
  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    I think the bigger one that comes with John the Ripper should be fine.


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    People must remember, it's just a game - so Damo will never make you jump through hoops for one very small thing such as the above.


  • Registered Users, Registered Users 2 Posts: 1,689 ✭✭✭JimmyCrackCorn


    Thanks damo complete.

    Id love to do a few more of these. Thanks for going to the effort of making it.


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    Thanks damo complete.

    Id love to do a few more of these. Thanks for going to the effort of making it.

    Feel free to try:
    http://damo.clanteam.com/sch6
    http://damo.clanteam.com/sch7


  • Registered Users, Registered Users 2 Posts: 1,689 ✭✭✭JimmyCrackCorn


    Thanks Damo.

    That's sch6 complete. Spent a while trying to get the syntax right.


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q




  • Closed Accounts Posts: 3,981 ✭✭✭[-0-]


    Got this one as well. Cheers again Damo.


  • Banned (with Prison Access) Posts: 13,016 ✭✭✭✭jank


    Bumping this as not sure if the same weakness is there?


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    Right idea, but wrong file. You cannot transverse outside my webroot.


  • Banned (with Prison Access) Posts: 13,016 ✭✭✭✭jank


    Thanks, got it after lots of cheating. Onto the second one now.


  • Advertisement
Advertisement