Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

realistic 7


ghost's Avatar
0 0

Someone explant to my why access.php always blank after i push submit (i tried all password i found and i found and loged with administrator's password )


Mr_Cheese's Avatar
0 1

the administraotors password you got, isnt to be used on the access.php.

thats the last part of the mission.

im stuck on trying to SQL inject the access.php. i keep getting SQL syntax


ghost's Avatar
0 0

I know that admin's pwd for .htacess part, i found all teacher password but i dont known how to use it, how to login at access.php


ghost's Avatar
0 0

When i was doing this mission, i skipped finding the teachers password and logged in as admin. Then, there was another user and pass field, try logging in there. Nevermind, that doesn't work, either the username is very strange, or that login form isn't right either. I found how to get the teacher's pass, simple! Now, i need to find out how to actually log in…


Mr_Cheese's Avatar
0 1

ok, a few tips to help you do this mission, this is what i did:

  • No SQL injection
  • think admin cookies ;)
  • spoofing the referal url ;) ;) ;)
  • view / change source (duh!!)

However: i did all things mentioned: i got a "grades changed" message and a "new salary set" ($4000) message logged in the /admin/ folder

yet, it still said "go back and finish the rest of the mission"

has anyone completed it?? or is this a mission error??


ghost's Avatar
0 0

Hmm…did you edit the url to change grades, or were you able to log in as someone? If so, who? I've tried a couple people, and i am still not able to log in with any of them…


Mr_Cheese's Avatar
0 1

the admin pass, has nothing to do with the changing grades / salaries.

look on teacher list page, and see if you can change anything to get the pass.


ghost's Avatar
0 0

I am able to get the pass of the teachers, but i am not able to log in as any of them


Mr_Cheese's Avatar
0 1

yeah, you have to spoof the refer, Find out what URL it onyl accept requests from.

Then you can get the LiveHTTP extension for firefox. Thats what i used.

Also, disable your firewall when you run it (i had problems with it working)


ghost's Avatar
0 0

Yes, i have passed that part. I was at the control panel, but whenever i clicked on check private messages, change password, or change grades, i was taken to a login screen, where i thought i was to log in, but i can not log in…


Mr_Cheese's Avatar
0 1

hmmmm, that hasnt happened to me.


ghost's Avatar
0 0

Maybe i am getting the username part wrong. For the first teacher, i have tried cstonebrain@northbay.edu and cstonebrain Am i doing the user wrong, or isn't this working for me for some reason…?


Mr_Cheese's Avatar
0 1

PM me with how you found the password. and yes that is how you do the username


ghost's Avatar
0 0

Mr_Cheese wrote: However: i did all things mentioned: i got a "grades changed" message and a "new salary set" ($4000) message logged in the /admin/ folder

yet, it still said "go back and finish the rest of the mission"

has anyone completed it?? or is this a mission error??

I've got the same problem. Anyone know anything to help out?


Mr_Cheese's Avatar
0 1

i think the problem is we need to change the salary to 2000


ghost's Avatar
0 0

Mr_Cheese wrote: i think the problem is we need to change the salary to 2000

Can we get an official clarification on this Grind?


ghost's Avatar
0 0

When I change the salary to something less than $4000 but more than $2000, it says "New Salary have being set!" but it won't let me into the next part. Does the salary have to be set to something less than $2000?


ghost's Avatar
0 0

Grindordie wrote: all it need to say.. "have being set":D I got it to say that, as well as, "Grades Changed" on the grades page, but it still says "Please go back and complete all parts of the challenge!"

Is there something I still need to do or what?


ghost's Avatar
0 0

Has anyone got into the admin page yet?


ghost's Avatar
0 0

Grindordie wrote: [in the grades section] did u change the grades to whatever the mission description says?

Use your little black dot in ur hat to do some evil things to the account ur in… COUGHchange passwordCOUGH

I've done both of those … still denied on the admin page


ghost's Avatar
0 0

When I loged as admin, the site say "You must come from the admin URL to view you control panel http://admin.*********.com", need some clue, how can i "come from the admin URL" ??:(


ghost's Avatar
0 0

How do i get the admin hash?


ghost's Avatar
0 0

that's what i would like to know.

and how to get .htaccess details.


ghost's Avatar
0 0

Mr_Cheese wrote: edit the refer I tried everything but it doesn't work. It works at seljojojo comp but not from mine. I don't know what's wrong with my comp.:o


ghost's Avatar
0 0

ok i finally got it. i was on the right track all the time..

this is incredible

in contact us page , there is this di******* thing…

and i tried /home/nhbs/blah and bwah…. and whoever did this is on the right track… hint:try thinking in which dir is passwds kept, we're takling about apache server..


ghost's Avatar
0 0

so i put something after "www.helboundhackers.org/challenges/real7/home/nbhs/*********l/", or is home notincluded, or ********* not included?


ghost's Avatar
0 0

i cant even get the ref thingy, it continually tells me i have to come from the control panel, i change ref and it tells me i came from nowhere, i change it to something wrong, and it shows up as what i typed, i turn off my firewall, and it seems to work better….but it still wont let me in…

edit: i got it, it was just being ignorant with my firewall…i wonder why it works on other things, but not this challenge….