Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

basic 27 help


ghost's Avatar
0 0

I know that the program filter the words: script , javascript…. i used a lot of xss injection to bypass the filter but it doesn;t work… ( thanks for your advise Futility, but i'm still stuck with it!!:@)

maybe i save it to my pc and i change the program ( i don;t now!!!!) any help or hint??:(


ghost's Avatar
0 0

maybe using meta-characters inside the script???:(


ghost's Avatar
0 0

dovis wrote: maybe using meta-characters inside the script???:(

You're way overthinking it. If that's what you came up after reading my post (before I removed it…I imagine you read it) and mosh's post…damn that's pretty bad. Where the hell did you get meta-characters from chocolate bar? :right:


ghost's Avatar
0 0

you have to make it say script, but it removes script… Odd, perhaps you could trick it into saying script somehow with methods mentioned earlier in this post


ghost's Avatar
0 0

i just did this in 10 seconds flat. this is basically a logic task haha and the chocolate thingy really gives it away.


ghost's Avatar
0 0

**———BIG SPOILER!!!!!!–––––

it takes away script so what would happen if you put a letter befor and after script?


ghost's Avatar
0 0

**———BIG SPOILER!!!!!!–––––

it takes away script so what would happen if you put a letter befor and after script?


ghost's Avatar
0 0

just have to think. how can you make it say the word "script" by removing the word "script"


shadowls's Avatar
You Like this!
90 0

If you write the the script tags, "<>" it will not filter it. But if you write the word "script" you can see if filters it. So what you want to do is find some way for scr!!!ipt not get filtered.


RedDragon's Avatar
Member
0 0

moshbat wrote: I'll type you a diagram…

here is your chocolate bar: ABBA Here is your chocolate bar after you've eaten the middle half: AA

Get it yet?

lol nice hint ! got it now ! thx ;)


breakDance's Avatar
Member
0 0

i'm stuck on this challenge.. i try to use the hint that others give..but still not working.. then..i try to convert script in hexadecimel..but it just display the hex & nothing happen..:(


yours31f's Avatar
Retired
10 0

Ok think about it logically. take 5 minutes away from the computer, then come back and reread these hints, they are actually VERY telling.


ghost's Avatar
0 0

Ok, think about what the SCRIPT filter, then think about how to bypass the problem… It's really easy… however, follow yours31f advice! ;)


ghost's Avatar
0 0

moshbat wrote: I'll type you a diagram…

here is your chocolate bar: ABBA Here is your chocolate bar after you've eaten the middle half: AA

This is a massive help. I didnt get it at first either but it really is good.


ghost's Avatar
0 0

i would agree, the chocolate told all. If you can't figure it out from the previous hints then you need to stop over thinking it.

took me 2 minutes to do dispite my constant typo's and syntax errors


ghost's Avatar
0 0

Take a break and try again! ;)


ghost's Avatar
0 0

I just got it! Thanks for the hints guys mucho helpful. :D


ghost's Avatar
0 0

Glad that u got it! :D


breakDance's Avatar
Member
0 0

fuser help me to beat this challenge.. i don't think i can't beat this challenge if i think on my own..hehehe.. thank to him..and the others..

actually when i read about the chocolate (hint)..i think that i should cut the word 'script'..make it more short like scrpt or else.. i try many possibilities..but still can't beat it… then..i read some tutorial..show how to make it by convert 'script' into html entities..unfortunately..it's not the right way to beat this challenge…huhu..

although i can't beat this challenge by myself..but i'm glad that i learn something new..:D


ghost's Avatar
0 0

Its actually really easy and kinda stupid once you figure it out :p but nice concept. Wonder if that would work on any sites. (besides this one)


Uber0n's Avatar
Member
0 0

skathgh420 wrote: Wonder if that would work on any sites. (besides this one) It does ;)


ghost's Avatar
0 0

chocolate bars….good hint!


ghost's Avatar
0 0

m stuck i tried everything Sorry Admins I know its a spoiler but i need help.

spoiler removed but it as:- <>alert(1)</> i tried few more things like:- spoiler removed but still output is same:(


kaden's Avatar
Out-Of-Idea's Man!
20 0

well seeing as this thread is 2 years old you would have been better off makng a new thread/pm'ing someone.

also, dont post huge spoilers =.="

you basicly have it… when you type in <script>alert(1)</script>, EXACTLY what is filtered..

think about it.

and remove the spoilers…


ghost's Avatar
0 0

Tnx kaden and spoiler removed too


dami3n's Avatar
Member
5 0

Rofl, finally got this one. I thought it might have been something to do with nested strings but obviously it just doesnt allow you to enter <script> this is a tough one if you think about it too much you will kick yourself when you get the answer. Ill give you one hint for people who still scratch there head. Force it to say script. <sscripts> - See what it does now go from there.


troll3rsk8tr's Avatar
Member
0 0

RedDragon wrote: [quote]moshbat wrote: I'll type you a diagram…

here is your chocolate bar: ABBA Here is your chocolate bar after you've eaten the middle half: AA

Get it yet?

After staring at it for 15 minutes it finally clickedthumbs up


ghost's Avatar
0 0

Think of it like this: SERVER: "STATE PASSWORD AS PRODUCT OF 42" USER: Answer must be, "8!" USER: *types an, "8" SERVER: I FILTER ALL BUT THE THIRD DIGIT USER: Ah, HA! USER: *types 12833 SERVER: ACCESS GRANTED