Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Real 7 last part


ghost's Avatar
0 0

Ok I change the grade and have red ligne "You change grade" I change the salary to 4000$ I change the password

Now i try to exploit the C***_** page with ?dy= but I still have "Not Found" I try : ?dy=/h***/n***/admin/.htpassword ?dy=/h/n/admin/.htpasswd ?dy=/h/n/admin/.htaccess ?d*y=/h/n/conf/.htpassword etc…

somebody can it give me a hint please ?


ghost's Avatar
0 0

hey this part is very interesting because they messed up the name and the string just a little bit. Here is a hint for everyone

/h***//.h***s/

the correct amount of asterisks is in the example above, as well as the correct position for slashes !that are manditory! this is prolly a spoiler in some way but it shows that they spelled a certain directory incorrectly as well as made the file a folder… hmm…


ghost's Avatar
0 0

Thanks, I got it


ghost's Avatar
0 0

So there's a spelling mistake in this challenge? I assume it's in the last part, but I've tried most of the things I can think of (duplicate letters, underscores, etc) but nothing so far has worked. Can the spelling either be fixed or a bit more of a hint given?

EDIT: Nevermind, I got it. It's not so much a spelling mistake as it is a… well, something different.


ghost's Avatar
0 0

this thread clinched it. whew! needle in a haystack! credit those other threads too that helped a bit.:ninja:


ghost's Avatar
0 0

yeah. thanks to you too MoshBat. you're the first guy i knew about here and thought of asking for help :) (took me hours man) :D -sigh of relief- I didn't wanna lose the work i've done -cookies etc.

nothings stops you when you've got the attitude.