Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

realistic 1


ghost's Avatar
0 0

ok ive heard many different thing in the forums but wat oe is the best? i got the picture source and i also found the secret page do i need both :@


ghost's Avatar
0 0

If you have all the secret stuff, what do you need the picture for?


ghost's Avatar
0 0

well in one of the threads it said to find the directory of the picture


ghost's Avatar
0 0

Use the picture to find the secret stuff, and then read an article about real 1 :p


ghost's Avatar
0 0

ok i know i need to view the cookies but i try typing in javascript:alert(docu<i></i>ment.cookie); but it doesnt seem to work am i missing any thing?

if there is a spoiler plz delete


ghost's Avatar
0 0

do you have the <i></i> in it?


ghost's Avatar
0 0

yes do i hav to go to the cookies on my comp to view it?


ghost's Avatar
0 0

you might, but it works just to take the <i></i> out of it.


ghost's Avatar
0 0

to make shure im doin this right is there supposed to be a pop up box?


ghost's Avatar
0 0

to make shure im doin this right is there supposed to be a pop up box?


ghost's Avatar
0 0

you need to use javascript injection (read article) to change the cookies, I highly recommend you download and install Firefox if you havent already it makes life so much easier.

Cheers

Dantronix


ghost's Avatar
0 0

i hav firefox allready but i also downloaded a AnEC cookie editor will this help?


ghost's Avatar
0 0

hackersuicide6 wrote: yes do i hav to go to the cookies on my comp to view it?

javascript:alert(document.cookie);


ghost's Avatar
0 0

ive tried that but it come as a pop up box


ghost's Avatar
0 0

ok i got the secret files very easily( by using the HBH website spider) but now i cant login. is the password a hash? if so, wut kind of hash?


ghost's Avatar
0 0

ahahahah, you did the same thing i did, i didnt realize taht they were seriuous about the johndoe/password

password is actually, the password…but after that there's somethign you must inject to obtain Admin status. (JS) ;D


ghost's Avatar
0 0

Ahhhhhh!!!!!!!!!!!!! :@ I've found everything, parent directory, taken all neccesary information, i know what injection i have to put in to log on as admin and i know the information i place in the injection. But i'm ment to put it into somewhere other than the URL apparently so where the hell do i put it???!!!


ghost's Avatar
0 0

Never mind, i just realised there was a difference between the AuthID's i kept sticking in the editor, stuck the right one in, went to toys page and walla.


ghost's Avatar
0 0

try url again ;) humbar has to be emptyhum


ghost's Avatar
0 0

Even though i've done it, i knew the URL bar had to be empty, i'm a hacker not a l33t n00b.


ghost's Avatar
0 0

i replied before your second post came in… soz, was only trying to help :p


ghost's Avatar
0 0

Lol, I thought it was a hash too at first. Well anec will definitely help, would make thing's easier. As for the password's you are seeing on the file, maybe you need to look around a bit more.


interslice's Avatar
Member
0 0

i finished this challenge a few days ago. but the really frustrating thing was the javascript. im not saying i dont know wat injection to put in . i just dont know if you're supposed to click go and then refresh ; or click go and expect a change?

can someone tell me plzzz?