Welcome to HBH! If you had an account on hellboundhacker.org you will need to reset your password using the Lost Password system before you will be able to login.

Stuck On Real 7


ghost's Avatar
0 0

I'm stuck on finding the admin : pass hash?

I found the hidden thing in the Cac_ page and I'm not sure what to do with it?

any pointers please?

Cheers

Dantronix


ghost's Avatar
0 0

I'm stuck on the same part.


ghost's Avatar
0 0

do you know what to do with the hidden info? I have tried a few things but no joy? Hope someone is gonna help?

Cheers

Dantronix


ghost's Avatar
0 0

yes.

con**** us.

so u have

real7/con*****.php?di*******=/home/nhbs/**********

after nhbs u put apache folder that contains passwords. name is simmilar to protection file itself.


ghost's Avatar
0 0

When I try that, it still says not found…


ghost's Avatar
0 0

ditto…everything Ive ever put there gives me a not found. However, I set a cookie to the whole ?dir*= thing and I get a neat error when I hit submit. yeah, Im making it complicated, Im sure.


ghost's Avatar
0 0

I can't find the folder either


ghost's Avatar
0 0

yeah- I am stuck here too.. BLAH! Team Hack rofl!


ghost's Avatar
0 0

me=stuck too….dont understand how making it the same as it was still tells me not found….it should be found unless i am retarded and doing something wrong…which i dont think i am….


ghost's Avatar
0 0

yeah, I think we all know what the apache directories are, and where they should be….it's just this method of guess and test that blows.


ghost's Avatar
0 0

indeed. and it can be very frustrating. but u should eventually get it.


ghost's Avatar
0 0

haha, pissin me off too. Been tryin urls for about 3 days, even tried a dictionary attack on the thing. My only question is….are there more than one folder after the nbhs?


ghost's Avatar
0 0

n*

(to avoid spoilers)


ghost's Avatar
0 0

haha


ghost's Avatar
0 0

Hey I recently decided to attempt Real 7 and got up to the final part. I am sitll receiving the 404 error when I attempt post what I got from a page in the website to the URL. Can anyone help?


ghost's Avatar
0 0

Im at this same part as well . I learned where the location is . But im still trying to figure out where the exact location is . I studied up on Apache server directories . I found this :

http://www.yolinux.com/TUTORIALS/LinuxTutorialApacheAddingLoginSiteProtection.html

I keep trying variations of what i think it is from reading this forum thrread and from what ive read at that link . I post it in the url and in the box . Still nothing is working but i can guess what the final path is but nothing .

To'g go bog e' , Neqtan


ghost's Avatar
0 0

yes i am at the same part and i dont know what to do come on help us some hints wanted:(


ghost's Avatar
0 0

I think im getting closer since im not getting as many 404's :

/challenges/real7/.php?=/home/nhbs/ap*****

Still getting a not found message . But i guess thats better than a 404 .

I read seljojojo's post about the final path bieng similar to the protected .

con**** us.

so u have

real7/con*****.php?di*******=/home/nhbs/**********

after nhbs u put apache folder that contains passwords. name is simmilar to protection file itself.

So im working off of this info now .

Tog go bog e , Neqtan


ghost's Avatar
0 0

well either the missions down or I'm missing something little

i have done all the tasks, and i log in as admin on the admin dir

it redirects me more_points.php thing and it says congrats, but no points or anything. and no i haven't already done it :o:xx:


ghost's Avatar
0 0

I think there must be a bug .

I got as far as the admin panel as well and it tells me this :

You have not completed all the checkpoints. CHANGE GRADES[DONE] BECOME ADMIN[DONE] GET PASSWORDS[DONE] GET .HTACCESS DETAILS REFERER[DONE] [DONE]

But then i go about getting .htaccess details and then go back to the page where i got that info and then it says :

You have not completed all the checkpoints. CHANGE GRADES BECOME ADMIN GET PASSWORDS GET .HTACCESS DETAILS[DONE] REFERER

So i go back through and do everything . Then i get :

You have not completed all the checkpoints. CHANGE GRADES BECOME ADMIN[DONE] GET PASSWORDS GET .HTACCESS DETAILS[DONE] REFERER[DONE]

Even though i did change grades and got both of the passes other wise i wouldnt have gotten into the admin panel without one of the passes !

This is kinda funny . Not realy . But im trying to stay positive .

Tog go bog e , Neqtan


ghost's Avatar
0 0

i noticed that too. i think you have to do them in the correct order, or your cookies fu** up :/ but still it wont let me complete :|


ghost's Avatar
0 0

I got this after doing the whole thing over . I completely closed out of my browser and reloaded and started the mission from scratch .

http://www.hellboundhackers.org/challenges/real7/admin/morepoints.php

So i started from scratch , lets compare apples to apples :

#1 =

Go to the teacher page , find the vuln get the pass for the corect teacher . Look in the source for the corect id value .

#2 =

Go to the Staff access page and fill in the login form with the found info .

#3 =

Change grades . Cant quite do it from the page itself . But i found two methods that would . One was using a type of script . The other was using an offline manufacturing method .

#4 =

Change salary . Reading the intro directions lets us know what this is !

#5 =

Go to the page with the vuln to get the admin hash . I used my buddy Jack the Ripper to get the pass .

#6 =

Go to the url path where the admin login form pops up . Fill in form .

#7 =

Then the page with the [done] list apears . I was forced both times to go back and redo parts of the challenge . Finaly i got the url :

http://www.hellboundhackers.org/challenges/real7/admin/morepoints.php

But no points were awarded . There was bugs in this mission almost a year ago . That apeared to be fixed . Maby there is something wrong again . Not sure im gonna go back through it again .

To'g go bog e' , Neqtan


ghost's Avatar
0 0

DUDE, THAT IS EXACTLY MY PROBLEM! at least now i am not alone :p i am still sad tho :(


ghost's Avatar
0 0

you can pm me


ghost's Avatar
0 0

Thanks for the offer of assistance redhot . I pm'ed you with what i got .

Neqtan


ghost's Avatar
0 0

I'm stuck on finding the admin : pass hash?

but i have found the c*t.p?dy=/h/nh/pic_h**l/ i have read the forum it say have to change after ns but i not sure what is the admin folder ?


ghost's Avatar
0 0

i also did all of dat bt didnt clear da level…. :(

mst b sm bug… took me more dan 6hrs 2 solve it…:(.. still no pts!


K3174N 420's Avatar
Satan > God
0 0

why471n wrote: i also did all of dat bt didnt clear da level…. :(

mst b sm bug… took me more dan 6hrs 2 solve it…:(.. still no pts!

If anyone is a little stuck, feel free to PM me… Just DON'T write like this guy… I will tell you to fuck off. It's called English.


K3174N 420's Avatar
Satan > God
0 0

moshbat wrote: Eh-hem?

All his post was missing is an 'innit bl00d' at the end…:angry: