TryThis0ne >> Challenges >> Realistic
Proxy Mania
Viewers: :
Quick reply
Reply
New Topic
 
Avidor93




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 31




Send Email Top
Sent on: 12/07/2008, 21:44:53 Reply | Quote | Warn | Edit
I can't figure out how to sql inj when updating.
i mean, i got into the newest account and found the sql inj.
i tried to attack it from every angle I could

putting some comments (I know, Comments on ACCESS are different) is not working.

I have tried some more things..

PLEASE give me some hint how should I exploit this
Cuz i'm getting insane!: )

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 17/07/2008, 14:02:08 Reply | Quote | Warn | Edit
just copy the query, edit it and resend it...

Hertz




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 116




User MSNTop
Sent on: 17/07/2008, 14:10:07 Reply | Quote | Warn | Edit
I got the admin password.I'm logged in as a admin,i am in the Proxy Logs directory,i've found the proxy that were used at 16/10/2004 18:53,there are two proxyes and near them are the IP adresses that used that proxyes.I've tryed to submit both of them at submit score but it doesen't work.What it's wrong?:(

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 17/07/2008, 14:15:22 Reply | Quote | Warn | Edit
it's call proxy strings:

Attacker==>proxy1==>proxy2==>Target.

your luck is that the all of the proxy that the attacker used- appear in this list, just follow after the time and the date and try to find what is the original attacker ip.

Hertz




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 116




User MSNTop
Sent on: 18/07/2008, 01:58:43 Reply | Quote | Warn | Edit
Ty. Passed!

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 20/07/2008, 03:27:31 Reply | Quote | Warn | Edit
:)

rodmar




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 2




Send Email Top
Sent on: 02/03/2009, 06:26:54 Reply | Quote | Warn | Edit
Hi,
I can login as Robert but I have no ideia what to do now.
Any hint??

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 02/03/2009, 17:01:26 Reply | Quote | Warn | Edit
rodmar, exellent, loggin as robbert is the first part, not you need to find the way to log as the admin - and remember, you can't log at the admin while he in the site!

rodmar




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 2




Send Email Top
Sent on: 02/03/2009, 18:53:40 Reply | Quote | Warn | Edit
I have tried everything with the Robbert account. I even tryed to change the profile name to BILL an the mail address to my mail, so that, in the forgot.php page I would put the name BILL and receive the email address with BILL password.

The problem is that the profile changes back and I don't understand how he saves the ne information.

Help..

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 04/03/2009, 09:45:49 Reply | Quote | Warn | Edit
There isanother bug in the form- like the bug that you found in the login page!

tomer321




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 120




Send Email Top
Sent on: 06/03/2009, 16:26:51 Reply | Quote | Warn | Edit
i logged in as robert and probably know what to inject where but it doesn't work. can i send some1 who passed it the code to inject and they tell me if its good?
ps i found roberts real password by sending it to my email but i never recieved bills pass

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 06/03/2009, 16:28:30 Reply | Quote | Warn | Edit
Send it to me, and yo, read the hints!

All the times are GMT+2, ISRAEL
TryThis0ne >> Challenges >> Realistic

Quick reply
Reply
New Topic


Page generated using: 12 queries
Design by SBD © GeHeNoM.Net | Powered By Tera-Byte Forums 1.5 © JonJon & HLL
ý