Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Stuck On Real 7


ghost's Avatar
0 0

I'm stuck on finding the admin : pass hash?

I found the hidden thing in the Cac_ page and I'm not sure what to do with it?

any pointers please?

Cheers

Dantronix


ghost's Avatar
0 0

I'm stuck on the same part.


ghost's Avatar
0 0

do you know what to do with the hidden info? I have tried a few things but no joy? Hope someone is gonna help?

Cheers

Dantronix


ghost's Avatar
0 0

yes.

con**** us.

so u have

real7/con*****.php?di*******=/home/nhbs/**********

after nhbs u put apache folder that contains passwords. name is simmilar to protection file itself.


ghost's Avatar
0 0

When I try that, it still says not found…


ghost's Avatar
0 0

ditto…everything Ive ever put there gives me a not found. However, I set a cookie to the whole ?dir*= thing and I get a neat error when I hit submit. yeah, Im making it complicated, Im sure.


ghost's Avatar
0 0

I can't find the folder either


ghost's Avatar
0 0

yeah- I am stuck here too.. BLAH! Team Hack rofl!


ghost's Avatar
0 0

me=stuck too….dont understand how making it the same as it was still tells me not found….it should be found unless i am retarded and doing something wrong…which i dont think i am….


ghost's Avatar
0 0

yeah, I think we all know what the apache directories are, and where they should be….it's just this method of guess and test that blows.


ghost's Avatar
0 0

indeed. and it can be very frustrating. but u should eventually get it.


ghost's Avatar
0 0

haha, pissin me off too. Been tryin urls for about 3 days, even tried a dictionary attack on the thing. My only question is….are there more than one folder after the nbhs?


ghost's Avatar
0 0

n*

(to avoid spoilers)


ghost's Avatar
0 0

haha


ghost's Avatar
0 0

Hey I recently decided to attempt Real 7 and got up to the final part. I am sitll receiving the 404 error when I attempt post what I got from a page in the website to the URL. Can anyone help?


ghost's Avatar
0 0

Im at this same part as well . I learned where the location is . But im still trying to figure out where the exact location is . I studied up on Apache server directories . I found this :

http://www.yolinux.com/TUTORIALS/LinuxTutorialApacheAddingLoginSiteProtection.html

I keep trying variations of what i think it is from reading this forum thrread and from what ive read at that link . I post it in the url and in the box . Still nothing is working but i can guess what the final path is but nothing .

To'g go bog e' , Neqtan


ghost's Avatar
0 0

yes i am at the same part and i dont know what to do come on help us some hints wanted:(


ghost's Avatar
0 0

I think im getting closer since im not getting as many 404's :

/challenges/real7/.php?=/home/nhbs/ap*****

Still getting a not found message . But i guess thats better than a 404 .

I read seljojojo's post about the final path bieng similar to the protected .

con**** us.

so u have

real7/con*****.php?di*******=/home/nhbs/**********

after nhbs u put apache folder that contains passwords. name is simmilar to protection file itself.

So im working off of this info now .

Tog go bog e , Neqtan


ghost's Avatar
0 0

well either the missions down or I'm missing something little

i have done all the tasks, and i log in as admin on the admin dir

it redirects me more_points.php thing and it says congrats, but no points or anything. and no i haven't already done it :o:xx:


ghost's Avatar
0 0

I think there must be a bug .

I got as far as the admin panel as well and it tells me this :

You have not completed all the checkpoints. CHANGE GRADES[DONE] BECOME ADMIN[DONE] GET PASSWORDS[DONE] GET .HTACCESS DETAILS REFERER[DONE] [DONE]

But then i go about getting .htaccess details and then go back to the page where i got that info and then it says :

You have not completed all the checkpoints. CHANGE GRADES BECOME ADMIN GET PASSWORDS GET .HTACCESS DETAILS[DONE] REFERER

So i go back through and do everything . Then i get :

You have not completed all the checkpoints. CHANGE GRADES BECOME ADMIN[DONE] GET PASSWORDS GET .HTACCESS DETAILS[DONE] REFERER[DONE]

Even though i did change grades and got both of the passes other wise i wouldnt have gotten into the admin panel without one of the passes !

This is kinda funny . Not realy . But im trying to stay positive .

Tog go bog e , Neqtan


ghost's Avatar
0 0

i noticed that too. i think you have to do them in the correct order, or your cookies fu** up :/ but still it wont let me complete :|


ghost's Avatar
0 0

I got this after doing the whole thing over . I completely closed out of my browser and reloaded and started the mission from scratch .

http://www.hellboundhackers.org/challenges/real7/admin/morepoints.php

So i started from scratch , lets compare apples to apples :

#1 =

Go to the teacher page , find the vuln get the pass for the corect teacher . Look in the source for the corect id value .

#2 =

Go to the Staff access page and fill in the login form with the found info .

#3 =

Change grades . Cant quite do it from the page itself . But i found two methods that would . One was using a type of script . The other was using an offline manufacturing method .

#4 =

Change salary . Reading the intro directions lets us know what this is !

#5 =

Go to the page with the vuln to get the admin hash . I used my buddy Jack the Ripper to get the pass .

#6 =

Go to the url path where the admin login form pops up . Fill in form .

#7 =

Then the page with the [done] list apears . I was forced both times to go back and redo parts of the challenge . Finaly i got the url :

http://www.hellboundhackers.org/challenges/real7/admin/morepoints.php

But no points were awarded . There was bugs in this mission almost a year ago . That apeared to be fixed . Maby there is something wrong again . Not sure im gonna go back through it again .

To'g go bog e' , Neqtan


ghost's Avatar
0 0

DUDE, THAT IS EXACTLY MY PROBLEM! at least now i am not alone :p i am still sad tho :(


ghost's Avatar
0 0

you can pm me


ghost's Avatar
0 0

Thanks for the offer of assistance redhot . I pm'ed you with what i got .

Neqtan


ghost's Avatar
0 0

I'm stuck on finding the admin : pass hash?

but i have found the c*t.p?dy=/h/nh/pic_h**l/ i have read the forum it say have to change after ns but i not sure what is the admin folder ?


ghost's Avatar
0 0

i also did all of dat bt didnt clear da level…. :(

mst b sm bug… took me more dan 6hrs 2 solve it…:(.. still no pts!


K3174N 420's Avatar
Satan > God
0 0

why471n wrote: i also did all of dat bt didnt clear da level…. :(

mst b sm bug… took me more dan 6hrs 2 solve it…:(.. still no pts!

If anyone is a little stuck, feel free to PM me… Just DON'T write like this guy… I will tell you to fuck off. It's called English.


K3174N 420's Avatar
Satan > God
0 0

moshbat wrote: Eh-hem?

All his post was missing is an 'innit bl00d' at the end…:angry: