Welcome to HBH! If you had an account on hellboundhacker.org you will need to reset your password using the Lost Password system before you will be able to login.

JacaScript 9 :S


daiiani's Avatar
Banned
0 0

Can someone help, or i know u can.. I found this password " + unescape(p-a) + unescape

But i realy dont know what to do with it :S Im not to good at this, as u see, but i learn fast so plz help me =)


ghost's Avatar
0 0

You have requested the password, but our servers are too busy to respond

Either Wait For That Many Seconds…LOL Or Change The Timer…


ghost's Avatar
0 0

Dude, unescape has nothing to do with password. It is made only to fool you. Check the variables and change something. (Javascript injection). PM me if you want more


ghost's Avatar
0 0

If I'm giving to much, edit this post. Okay, first, read this: http://nexodyne.com/showthread.php?t=14736 We could maybe use the void to change a variable. So find the variable with the number that is counting down, change it to a low number, and voila!


ghost's Avatar
0 0

Thank you very much. Great article on javascript injection. To be fair it's the only one I've read, but It helped a lot. ta.


Uber0n's Avatar
Member
0 0

XanLoves wrote: Great article on javascript injection. To be fair it's the only one I've read, but It helped a lot.

Well if it was the first one you read and it helped you, it must've been a good article :)


ghost's Avatar
0 0

It was indeed good, but in comparison to others it could well be rubbish.

:p


ghost's Avatar
0 0

Okay, so I've edited the JavaScript and opened it to find the page with the password… however, when I try to submit the password, I get taken to a page that says:

"Malformed Request Please check that no referer spoofing applications are active and try again."

Am I supposed to get that page? Am I doing something wrong? :angry:


ghost's Avatar
0 0

i did this one awhile ago, and have it saved to my hard drive still with the way i did it,, and i tried it again to see, and i got that malformed request last time, and i changed somehting, but i dont rememebr what I changed… to make it not do that… Oh well


ghost's Avatar
0 0

ahhh js 9 is the only js i havent beaten and its killing me.

i set the variable to zero, a form appears with a "Your password is: [spoiler]"

then i look thru the source and find a "Howslf?asy but its not the right password

gaaa

ne1 got a tip?


ghost's Avatar
0 0

DigitalFire wrote: ahhh js 9 is the only js i havent beaten and its killing me.

i set the variable to zero, a form appears with a "Your password is: [spoiler]"

then i look thru the source and find a "Howslf?asy but its not the right password

gaaa

ne1 got a tip?

Lol this challenge is so incredibly easy, you're clearly overthing it big time. Look in the source, find the variable that's 'attached' to the number value you see on the page, and then use a javascript injection to change the value of that variable to 0. Voila.


ghost's Avatar
0 0

i just used firebug.. thats how easy that mission was… though i must admit it took me a few minutes to figure out what i was doing.


ghost's Avatar
0 0

so easy lol even though it took me some time :)