Welcome to HBH! If you had an account on hellboundhacker.org you will need to reset your password using the Lost Password system before you will be able to login.

session pointers


ghost's Avatar
0 0

as in, i need them….heh I have 90 points so its obvious which challenges i have got. I am looking through articles on hbh about cookies and sessions, reading what links members have posted online, and googled until my eyes bleed.

I have scoured the source code hoping to see some type of admin related session info, and nothing. From what I gather the only way to get another useres session info is to trick them into handing it to you, but I am not sure that this can be implemented here.

lost for sure.

And as for the last part, any reading related to **s would be appreciated.

You are awesome (regardless of who you are ;-) )


ghost's Avatar
0 0

I'm having trouble with the session exploit too i don't know where i should be looking and hints/suggestions would be GREAT :D

skathgh420


crashbird's Avatar
-=CodeGuru=-
0 0

you can pm me. And i sure will reply to you. (Still feel dumb..)


ghost's Avatar
0 0

MoshBat wrote: Sure, knowledge of PHP Sessions would help, and I am presuming they've looked.

they didnt look too hard:

http://us.php.net/manual/en/intro.session.php

1st result on google for 'php session'. i understand that the word 'propagated' might be a bit too big for the members here, tho. (it means that its there)

ur right, tho… i dont code in php at all. obviously


ghost's Avatar
0 0

MoshBat wrote: And you haven't completed the challenge, so really, you can't give other help. ur right… challenge knowledge > practical knowledge.