Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

blowfish.smashthestack.org help on level1


BluePain's Avatar
Member
0 0

Hello, are someone playing the root game blowfish on smasthestack? If so and if someone are past level1 can someone help me with that level? I am stuck. I dont know what to do with the script?


bl4ckc4t's Avatar
Banned
0 0

I have seen SMs name on there a few times, hes great at rooting, ask him.

BC


BluePain's Avatar
Member
0 0

Thanks I will but a Littel problem I cant find any member that are named SMs? Or have I got the situation wrong?


ghost's Avatar
0 0

I think HBH should have a war game.

Anyone else?


BluePain's Avatar
Member
0 0

I think that, but I would aslo like som tuts on that. :)


ghost's Avatar
0 0

hbh rooting game FTW :D


ghost's Avatar
0 0

yea I thought it would be a good idea seeing as we dont much in the way of rooting on this site.


ghost's Avatar
0 0

cubeman372 wrote: I think HBH should have a war game.

Anyone else?

indeed


ghost's Avatar
0 0

It would be great with some rooting lessons and challanges here =) The one we have isn't that good =P

Anyone who know a good place to find out some stuff about rooting?


ghost's Avatar
0 0

I think it's a brilliant idea to have some boxes to root for HBH.


AldarHawk's Avatar
The Manager
0 0

SMs == system_meltdown currently ranked #1 on HBH (last time I checked at least)


ghost's Avatar
0 0

I know how to do in this level you can pm me if you want. Its a simple buffer overflow. I suggest you to download from the site all papers and tutorials about c and buffer overflow before start whit challenges that are for intermediate and advanced users so dont hope to get help. Read the pdf of Gathering of Gray about c in programming section and you will learn how to exploit that level.


BluePain's Avatar
Member
0 0

AldarHawk wrote: SMs == system_meltdown currently ranked #1 on HBH (last time I checked at least)

Sorry, I dident know that.


ghost's Avatar
0 0

Dont worry, anyways I really think we should get something sorted in this area anyone got any ideas?


ghost's Avatar
0 0

well im as confused as bluepain on level1 i can buffer overflow but i cant see how to disassemble this one(gdb doesnt work) and it doesnt dump its core. help me O.o


ghost's Avatar
0 0

Hehe… This should keep me amused for a while… Thanks whoever brought this up


ghost's Avatar
0 0

can someone whos done this pm me something like how many bits after the buffer the EIP is :)


ghost's Avatar
0 0

you need to work that out :p Its all part of the challenge ;)


ghost's Avatar
0 0

damn lol im guessing its just guessing going up a byte at a time? lol and youre supposed to /bin/bash right?


BluePain's Avatar
Member
0 0

Happysmileman wrote: Hehe… This should keep me amused for a while… Thanks whoever brought this up

No, Problem :) But I cold really need some help. ;)


ghost's Avatar
0 0

Are you guys able to login to blowfish.smashthestack.org using ssh on port 2223? It gives me some error message that the host is unaccesible. :angry:


ghost's Avatar
0 0

yeah i think its down at the moment :(


ghost's Avatar
0 0

Read the part V pdf file of Gathering of Gray. Download this file from smashthestack site.

About System_Meltdown and nanoymaster, we all know what can do these too members, theyre very skilled hackers but atm in this challenge i saw only the nanonymaster tag in the index file LOL(you can see the larika tag also).

To beat this level you need a good knowledge of c, gdb, asm, bof. And remember is for advanced users so study before play.


SySTeM's Avatar
-=[TheOutlaw]=-
20 0

Larika wrote: About System_Meltdown and nanoymaster, we all know what can do these too members, theyre very skilled hackers but atm in this challenge i saw only the nanonymaster tag in the index file LOL(you can see the larika tag also).

Yes, I gave up with the shitty simulations I prefer to root a real box


ghost's Avatar
0 0

My box is still up for rooting. If simulations bore you :)


ghost's Avatar
0 0

Info please :evil:


ghost's Avatar
0 0

Im agree, i prefer real rooting and webhacks too. But im not agree whit the shitty simulations thing. Smashthestack offer very good simulation in which you can learn and test your skills about c,asm,bof etc as HBH do for other things. I dont understand why you dont consider HBH challenges shitty simulations too. When HBH will offer more rooting challenges youll leave these to us? I think not. These sites offer to us a good opportunity and support to learn a lot of things, and they deserve our respect.


bl4ckc4t's Avatar
Banned
0 0

The problem with rooting is not many ISPs like the idea of you using their lines to allow someone to hack your computer.

They tend to get a lil skiddish. (skiddish != Skiddy)

Bl4ckC4t


ghost's Avatar
0 0

If skiddish is != Skiddy what is it equal to?


SySTeM's Avatar
-=[TheOutlaw]=-
20 0

Grindordie wrote: [quote]mr noob wrote: hbh rooting game FTW :D

Actually we used to have one, we had two events. They were real machines but people couldn't hack them. (even though most services were vulnerable). During the second event, people lost interest and gave up. Thats why HBH doesnt have any more rooting challenges. [/quote]

How about bringing them back for a while? There's more members now and quite a few are keen on the idea.


ghost's Avatar
0 0

When did we have the second one????

confused


bl4ckc4t's Avatar
Banned
0 0

cubeman372 wrote: If skiddish is != Skiddy what is it equal to?

The word skiddish as in apprehensive.

BC

[edit] Damn misspelled words..[/edit]


ghost's Avatar
0 0

I see, Blackcat.

Yea it would be awesome if you would bring rooting back!


ghost's Avatar
0 0

cubeman372 wrote: My box is still up for rooting. If simulations bore you :)

^^ donate !


ghost's Avatar
0 0

If I recall, SkareCrow won that last competition, which I was very close to beating with the same SSH method.


ghost's Avatar
0 0

once you are running your virtual server then what… thats what I'm slightly confused with, do I just hand out the IP or do I need to do more setting up?