Level 5
As before, we can use the credentials obtained from the previous post to log in to Level 5. Upon doing so, we are presented with the following screen:
We can see that there appears to be something that is not allowing us to login. My first thought (again, proved to be correct [woo-hoo]) was that a cookie was the cause. Let's take a look at what cookies are being used by the site. I use a Chrome extension called Edit This Cookie (thanks for the catch, Murilo!) to do this:
We can immediately see a cookie called 'loggedin', which is currently 0 (for False). Let's just change this to a '1' and see what happens:
Now, let's just reload the page:
Awesome. Just as we hoped, the challenge believes we are logged in, and returns the password for natas6 to us, which we can use to log in to the next challenge. More writeups to come.
Related Posts
TP-Link http/tftp backdoor
18 Oct 20130About the TP-Link Router TP-Link TL-WDR4300 is a popular dual band WiFi, SOHO class router. Test...Read more »
Upload shell with Tamper Data
15 Oct 20130Upload shell with Tamper Data How to upload your PHP shell through Tamper Data Many times yo...Read more »
Hellbound hackers basic 1
01 Sep 20132Hellbound hackers basic 1 start with this link:https://www.hellboundhackers.org/challenges/basic1/in...Read more »
Finding websites vulnerable to sql injection without using dorks
28 Aug 201301, First open up a proxied browser and visit http://punkspider.hyperiongray.com/ 2, Enter th...Read more »
Padding Orale Attack
22 Aug 20130Victim: http://bigc.vn/ Kiểm tra lỗi Padding Orale View source: ...Read more »
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment
Click to see the code!
To insert emoticon you must added at least one space before the code.