Welcome to HBH! If you had an account on hellboundhacker.org you will need to reset your password using the Lost Password system before you will be able to login.

hack my site nucleocide.net


ghost's Avatar
0 0

My website is http://www.nucleocide.net. I had a problem with a hacker before and I'm trying to iron out all the kinks (I wrote the tiny CMS myself). I'm requesting that my fellow hackers attempt to hack my site by simply posting a news item on the front page. In order to do so you'll either need to login as an admin or somehow escalate your permissions. On the news post just mention your HBH name and how you did so. I'd like to limit this to injections and try not to do anything too deep and piss off my websites host.

This is just a learning experience, please don't do anything mean. I'm not sure if this violates any rules set forth by HBH and if so I'll drop this post. I'll provide any form of proof requested so that you know the site is mine.


Neo_Chalchus's Avatar
Lover of Parkour
0 0

I don't know much about mysql hacking, but I got this error by inputing an ' into the username:

Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in /home/nucleo/nucleocide.net/includes/auth.php on line 14
 
Login failed for user: &*92;.
Try Again```

 I dunno if you could use that as a way of getting in, but it might help,

NC

ghost's Avatar
0 0

Howd u fuckit up?


ghost's Avatar
0 0

Click on the users link. The format is fucked up there.


ghost's Avatar
0 0

in the gallery section, you can still use html tags.


ghost's Avatar
0 0

Yeah, iframes are fucking it up a bit. Thats what i used as my detials to mess the user page!


ghost's Avatar
0 0

I'm pretty sure I've fixed ass XSS holes. Feel free to keep looking.


ghost's Avatar
0 0

Nope the XSS holes are still there


ghost's Avatar
0 0

bots :P

this is getting more difficult.. i dont see anyway to login as you B)


ghost's Avatar
0 0

The scan lines are ugly. Lower the opacity.


ghost's Avatar
0 0

I'm loving the scan lines!


ghost's Avatar
0 0

Neo_Chalchus wrote: I don't know much about mysql hacking, but I got this error by inputing an ' into the username:

Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in /home/nucleo/nucleocide.net/includes/auth.php on line 14
 
Login failed for user: &*92;.
Try Again```

 I dunno if you could use that as a way of getting in, but it might help,

NC

Yea, that usually means its prone to the simplest attacks.