Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Level1


ghost's Avatar
0 0

i got the

Username Password AuthID

i tried some javascript injections but i cant get it to work


ghost's Avatar
0 0

Have you tried looking at the original cookie before JS injection? You'll notive two of those are unnecessary.


ghost's Avatar
0 0

Ok, i change the AuthID and i get this message at the bottom of the page

You are logged in as: john doe Warning: Cannot modify header information - headers already sent by (output started at /home/hbh/public_html/challenges/real1/index.php:21) in /home/hbh/public_html/challenges/real1/index.php on line 40

am i doing it right, just something wrong with HBH server?


ghost's Avatar
0 0

Worked for me, send me a pm with what you did and i'll try and find any mistake you may have done.


ghost's Avatar
0 0

Yeah, that "shit" doesn't affect what you have to do - just what's originally set. You'd see johndoe's AuthID, but instead you see nothing. Just assume there was a value for AuthID that corresponded to johndoe, and act appropriately.