Follow us on Twitter!
Become the change you seek in the world. - Gandhi
Thursday, April 24, 2014
Navigation
Home
HellBoundHackers Main:
HellBoundHackers Find:
HellBoundHackers Information:
Learn
Communicate
Submit
Shop
Challenges
HellBoundHackers Exploit:
HellBoundHackers Programming:
HellBoundHackers Think:
HellBoundHackers Track:
HellBoundHackers Patch:
HellBoundHackers Other:
HellBoundHackers Need Help?
Other
Members Online
Total Online: 22
Guests Online: 19
Members Online: 3

Registered Members: 82886
Newest Member: The Slummy
Latest Articles
View Thread

HellBound Hackers | Challenges | Realistic

Author

Help with real 1 please


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 04-11-05 11:31
ok, this is what ive done:

i went to the .txt file and got password, entered user and pass in the login screen and did the JS-javascript:void(document.cookie="AuthID=XXXXXXX"Wink
but it still doesnt work! please help!


Author

RE: hmm


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 04-11-05 11:56
where are you doing your js? the whole point is to change the amount right? So you'd want to be doing this while logged in and looking at the price...

also authid isn't the only thing you need to set in cookies...what else looks important?

p.s. refresh after every javascript injection
Author

RE: Help with real 1 please


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 04-11-05 16:19
AuthID is the only thing you need to set, surely. It's the only new variable that's set upon logging in, and it's all I did to complete it.

Either way, I hope you're not injecting "JS-javascript:void"... you might of just been saying "here's the JS-," but just to be sure.


Author

RE: Help with real 1 please


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 05-11-05 07:02
no, i didn't put the JS- in the url bar. I wasn't logged in when I did the javascript, i thought you needed it to login?


Author

RE: Help with real 1 please


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 25-12-05 03:56
OK, so the AUTHID is the only part we need to inject?

For sme reason, nothing is happening Sad
Author

RE: Help with real 1 please


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 25-12-05 04:51
# No, you still need to inject the username and password.
Author

RE: Help with real 1 please


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 25-12-05 09:35
just inject everything thats then you can't be wrong


Author

RE: Help with real 1 please


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 25-12-05 18:41
Tee Hee thanks, my JS injection code was alittle messed up. I just injected everything, and it worked!
Author

RE: Help with real 1 please


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 10-03-06 13:57
How do you gain access as johndoe? I've tried js injections, I can't seem to create a cookie.

Also, if we're doing this to get access as johndoe, sureley we could just do it straight away for administrator?

I demand answers Smile

PS I have cookies for johndoe, but it won't let me in. (did it in a line, then alerted at the end and they're there....)




Edited by on 10-03-06 15:15
Author

RE: Help with real 1 please


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 10-03-06 15:35
(*May contain spoilers? You are warned!!*)


Dude - you get the Pass & user for the John Doe account. Next search for an image...
If you found what your looking for just go to the page that you want to edit (read the mission briefing!!) and use js injections. Don't know how to? Read the threads for this mission, you will get there.
Author

RE: Help with real 1 please


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 10-03-06 15:54
spyware wrote:
(*May contain spoilers? You are warned!!*)


Dude - you get the Pass & user for the John Doe account. Next search for an image...
If you found what your looking for just go to the page that you want to edit (read the mission briefing!!) and use js injections. Don't know how to? Read the threads for this mission, you will get there.


*confused* I have the usename and pass for john doe, and administrator... I just can't get in as johndoe. Everything after that I could probably work out. How do I first log in as john doe? I have tried to cain the password, but nothing...


Author

RE: Help with real 1 please

Mr_Cheese




Posts: 2468
Location: Brighton, UK
Joined: 30.11.04
Rank:
Uber Elite
Posted on 10-03-06 15:56
the password wont work. we havnt scripted a working login system for this challenge, because we want people to use javascript injection and edit their cookies.

so the only way to "log in" as john doe, is to edit your cookies.


http://www.hellboundhackers.org/
Author

RE: Help with real 1 please


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 10-03-06 16:06
Mr_Cheese wrote:
the password wont work. we havnt scripted a working login system for this challenge, because we want people to use javascript injection and edit their cookies.

so the only way to "log in" as john doe, is to edit your cookies.


In that case I have edited my cookies, but still nothing. I am confused. I have used the obvious username, password, sessionid as the cookie names... But still no access...

Mr Cheese, please may I pm you with my javascript alert screenshot?




Edited by on 10-03-06 16:13
Author

RE: Help with real 1 please


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 10-03-06 22:23
Damn Pfft Just login as Johndoe! In the mission descryption the pass for the john-account is given! Read your mission objectives!

You only need to JS-Inject the stuff for the admin...
Author

RE: Help with real 1 please


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 10-03-06 22:52
OMG I'm such a noob. I did try that, but with caps like JohnDoe. Silly me.
Thank you so much for all your help.

Didn't help that mr cheese said the loging form didn't work, I gave up trying.


Author

RE: Help with real 1 please

AldarHawk
Member



Posts: 1690
Location: Canada
Joined: 26.01.06
Rank:
Hacker Level 1
Posted on 13-03-06 14:09
I worked on this for a very long time...Word of advice to the wise....READ READ READ!!!

I did not read! and it took me FAR too long!

Ohh well...I got it now!


Just ask Yahoo!Taboo! http://www.erikwestlake.com