TryThis0ne >> Challenges >> Web
About the OS login challange
Viewers: :
Quick reply
Reply
New Topic
 
seven




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 3




Send Email Top
Sent on: 24/09/2005, 15:18:32 Reply | Quote | Warn | Edit
I created an html and added a admin field into the form
(and of course changed the POST location).
however, I still get "Loged in successfully" and not the password

*Yeah I entered 1 in the admin field
*Yeah I checked over the temp files. found nothing

seven




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 3




Send Email Top
Sent on: 24/09/2005, 15:22:53 Reply | Quote | Warn | Edit
never mind, I passed it :)

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 24/09/2005, 22:02:33 Reply | Quote | Warn | Edit
well done! :)

SBD




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 49




Send Email Top
Sent on: 24/09/2005, 23:18:17 Reply | Quote | Warn | Edit
I did the same thing only with the right change, but nothing =\
hint?

Edit by : cp77fk4r At 24/09/2005, 22:01:41

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 25/09/2005, 00:04:21 Reply | Quote | Warn | Edit
ALERT : HINT!
When you injecting some SQL Commands you need remember what with the rest of the query!

SBD




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 49




Send Email Top
Sent on: 25/09/2005, 00:52:07 Reply | Quote | Warn | Edit
sory i mixed with 2 diffrent levels.

in the OS LOGIN there is no SQL INJ, no CP?

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 25/09/2005, 01:37:20 Reply | Quote | Warn | Edit
SBD- check it by yourself, I'll don't tell you :)

btw, this is a offtopic.

Nuuuuuu1




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 38




Send Email Top
Sent on: 27/11/2006, 16:53:08 Reply | Quote | Warn | Edit
cp, SBD is right..
y letting them think about sql injection and "the rest of the query"..
there a better way without it..
think.. it's one of the easiest, shortest web-challenges..

Edit by : Nuuuuuu1 At 29/11/2006, 23:56:14

All the times are GMT+2, ISRAEL
TryThis0ne >> Challenges >> Web

Quick reply
Reply
New Topic


Page generated using: 12 queries
Design by SBD © GeHeNoM.Net | Powered By Tera-Byte Forums 1.5 © JonJon & HLL
ý