Help with real 1 please
No, you still need to inject the username and password.
How do you gain access as johndoe? I've tried js injections, I can't seem to create a cookie.
Also, if we're doing this to get access as johndoe, sureley we could just do it straight away for administrator?
I demand answers :)
PS I have cookies for johndoe, but it won't let me in. (did it in a line, then alerted at the end and they're there….)
(May contain spoilers? You are warned!!)
Dude - you get the Pass & user for the John Doe account. Next search for an image… If you found what your looking for just go to the page that you want to edit (read the mission briefing!!) and use js injections. Don't know how to? Read the threads for this mission, you will get there.
spyware wrote: (May contain spoilers? You are warned!!)
Dude - you get the Pass & user for the John Doe account. Next search for an image… If you found what your looking for just go to the page that you want to edit (read the mission briefing!!) and use js injections. Don't know how to? Read the threads for this mission, you will get there.
confused I have the usename and pass for john doe, and administrator… I just can't get in as johndoe. Everything after that I could probably work out. How do I first log in as john doe? I have tried to cain the password, but nothing…
Mr_Cheese wrote: the password wont work. we havnt scripted a working login system for this challenge, because we want people to use javascript injection and edit their cookies.
so the only way to "log in" as john doe, is to edit your cookies.
In that case I have edited my cookies, but still nothing. I am confused. I have used the obvious username, password, sessionid as the cookie names… But still no access…
Mr Cheese, please may I pm you with my javascript alert screenshot?