Join us on Slack!
It is the path of least resistance that makes rivers and men crooked. - Bj Palmer
Monday, August 19, 2019
Navigation
Home
 Find:
 Information:
Learn
Communicate
Submit
Shop
Challenges
 Exploit:
 Programming:
 Think:
 Track:
 Patch:
 Other:
 Need Help?
Other
Members Online
Total Online: 73
Guests Online: 70
Members Online: 3

Registered Members: 117703
Newest Member: milliedz2
Latest Articles
View Thread

HellBound Hackers | Challenges | Social engineering

Author

social 2

henry123456789
Member

Your avatar

Posts: 79
Location:
Joined: 10.02.15
Rank:
God
Posted on 07-03-16 22:37
this was told :

"but I need the log's folder, FTP root username/password and the file where the passwords are stored.","the logs folder is 1099/?","The FTP root username and password is, ","root, stringray,","and the file where the passwords are stored is,","overdata.rsg,""

The social engineer needs the FTP username and password and the file where the passwords are stored. Thus it is an FTP connection that is connecting to hellboundhackers.org via FTP and then download the file where the passwords are stored is not it ? the problem is that the ftp to hellboundhackers.org (the domain) or 77.72.3.26 the IP is closed that is we cannot connect to hellboundhackers.org via ftp . Am I wrong ? yes ? no ? correct me . Moreover , the file where the passwords are stored is overdata.rsg and I cannot get it through the normal https url I mean like this :

https://www.hellboundhackers.org/challenges/sec2/server/overdata.rsg

404 not found

https://www.hellboundhackers.org/challenges/sec2/overdata.rsg

404 not found


https://www.hellboundhackers.org/challenges/overdata.rsg

404 not found

https://www.hellboundhackers.org/overdata.rsg

404 not found

the logs.txt file has nothing readable in it except for " Admin Log"

so any hint on how to get the file where the passwords are stored

Edited by henry123456789 on 07-03-16 22:40
Author

RE: social 2

Huitzilopochtli
Member



Posts: 1621
Location:
Joined: 19.02.13
Rank:
God
Posted on 08-03-16 00:52
The FTP connection is an imaginary one connecting to server9.usa.com that's mentioned in the chat log. You're not expected to use FTP to connect anywhere, as everything takes place within the main /server/ directory of the challenge.

"and the file where the passwords are stored is overdata.rsg,"............."Sorry, I need one more data","What's the name of the.....blah"

Looks like you need "one more data" to find out where the overdata.rsg file is stored, best get looking for that data man.

Edited by Huitzilopochtli on 08-03-16 00:53