Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Realistic 5


ghost's Avatar
0 0

Hey, im at the start. I have logged in with the Jdoe, and in the emails. But how do i go abouts getting BillSmiths cookie hashs?i know about javascript injection and alerting cookies, changing cookies, but uh, with this mission i alerted the cookie, and there is nothing except the fusion_user and stuff and the phpsessid.

Any help would be appreciated


ghost's Avatar
0 0

um, ok. i read else where about decrypting the encrpyted css files. But what kind of encryption are they?


ghost's Avatar
0 0

It isn't the file exactly, look at the name of the file.


ghost's Avatar
0 0

Yeah, im having a look at the name of the file. But it doesnt mean anything to me atm lol. Could it be the hash's we need? or what?


ghost's Avatar
0 0

okay in the file manager and i got to BilSmith and change the permision to 777 and it says ok … then i go to .txt file with the list of IPs. i use one of the (theres only 2 possible) and i replace it in the htaccess part. then it says go back to the main dir and see wat is the name to report someone downloading music…. am i on the right track cuz im lost on the reporting?


ghost's Avatar
0 0

Im not even that far lol B)


ghost's Avatar
0 0

hack4u wrote: okay in the file manager and i got to BilSmith and change the permision to 777 and it says ok … then i go to .txt file with the list of IPs. i use one of the (theres only 2 possible) and i replace it in the htaccess part. then it says go back to the main dir and see wat is the name to report someone downloading music…. am i on the right track cuz im lost on the reporting?

OK , me 2 . I changed permission and IP successful . But next , I don't know what must I do . I went to the main page , there's nothing I can find ?


ghost's Avatar
0 0

Hey that makes 3 of us :(


ghost's Avatar
0 0

yeah well wat would helop would be an answer to this damm thing


ghost's Avatar
0 0

I've searched the whole thing over and over again, but I can't seem to find an option on how to report someone? Or do we have to use some sort of php-injection with a specific file?


ghost's Avatar
0 0

Any clues on how to get 2nd email?


ghost's Avatar
0 0

okay well i found the rpr*.php and it says that

We could not send you report due to the following reasons

The member does not exist or is not an administartor

so wtf?


ghost's Avatar
0 0

hmm i wonder what filename that could be hack4u rofl.


ghost's Avatar
0 0

yeah thanx but i think people already knew about that so im kind of just looking for wat to do now ;)


ghost's Avatar
0 0

hack4u wrote: yeah thanx but i think people already knew about that so im kind of just looking for wat to do now ;)

you read my mind :)

I'm guessing, void those cookies :p but I'm not sure.


ghost's Avatar
0 0

Okay so I have been working on this one for a while and I seem to be stuck at where everyone else is stuck so if anyone can drop us a hint that would be great. I have done the chmod and changed the ip back and then I'm supposed to go back to the main dir and find the user who has been d/ling the music?

This sentence doesnt make much sense to me……

"Then you need to view the main directory of eBussNet and see what is the name to report a user that has being downloading illegal music."

I have found where to report this user but I get an error that says something about not being a member or admin……

any ideas?????

aVoid


ghost's Avatar
0 0

Well, alright, the person we want to report is BillSmith, right? Because he has the illegal d/l directory, so we want to report him then? Well, did you guys/girls check the source to see where that reported file is going (being sent to)?


ghost's Avatar
0 0

well report.php is the result of filling out the form and i havent found the form to fill out. If someone could help me out there.


ghost's Avatar
0 0

Check the source for a possible commented out part in the "hidden directory."


ghost's Avatar
0 0

do you mean the ********ry tag?

I tried that but it gave me the same error as when I just view it directly.


ghost's Avatar
0 0

Hmmm, I have done everything but I don't know what it means by what is the name to report a user? When I try I get an error telling me I'm not an admin htough EDIT: Do I have to login as someone else? sanderson?