Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Help on realistic one


ghost's Avatar
0 0

ok im new to dis hashing stuff so i dont know what to do. I found out johndoes encrypted password but how do i log in as him? how do i decrypt his password? from reading the forums i think i know how to finish off the mission but i need to be signed in as johndoe first

please: hints and websites that help only no spoilers


ghost's Avatar
0 0

Do more of the basic challenges. Read more articles. If you don't know how to do something look it up on Google.


ghost's Avatar
0 0

yea i jus wanna kno wut has to be done do i have do decrypt his pass or make a cookie for johndoe, i figured once signed in as john doe i cud change cookies to be adminsitrator but how to change the cookie to get access as johndoe i umm the txt file gives his username decypted pass and session id when i add all of these and press refresh nuthoin happens


ghost's Avatar
0 0

Learn some javascript (googling for javascript:alert and javascript:void will be good i think) , n you should be pretty familiar with the source of the pages and stuff… u can decrypt john's pass with a program Cain and Abel , then when u login as him, u can change ur cookies to become admin..(That's how i solved it)


ghost's Avatar
0 0

Thank you i neede to know about cain and abel i already kno js injection

EDIT = can u explian how ot use cain and abel i made a text file that includes

username: johndoe password: 5193cc*f*7

what to do now?


ghost's Avatar
0 0

SPOILFUL

ok find out what hash it is….. coughb4 SIP hashes in cracker's listcough , right click chose add to list and add the password string. Then right click on it and dictionary attack it (the first in the list),Only check Lowercase, Uppercase and As Is , add to the list the wordlist(it's in a directory in cain's directory) and click start, and in 8 seconds … VOILA! u got the pass :) Tell me if it works, n if u have msn, add me, my hotmail is on my profile..


ghost's Avatar
0 0

lol thanks it worked it makes me maddd to find out wut da pass really is dam i could of guessed that


ghost's Avatar
0 0

Lol happens lots :P Anyway good luck in the others challenges :D


Mr_Cheese's Avatar
0 1

dont decrypt the password. Logging in as the admin wont work. This mission is designed to teach people to change their cookies.


ghost's Avatar
0 0

she only decrypted john's pass , logged in as him, and then changed her cookies to become admin, i don't think that's wrong or non-educational :P or sthg, she did 2 things in 1..