Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Realistic 1 - Just a few hints please.


ghost's Avatar
0 0

Well, so far i have the information on administrator and johndoe.

Iv tried logging in as johndoe but it doesnt work.

"Your user and pass didnt match our records" - iv tried all different passwords.

iv heard you need to use js injections and to look on toys.php.

just need a bit more guidence. thanks


ghost's Avatar
0 0

you dont need the username /password at all. use the AuthId. javasctipt inject it on the toys page


ghost's Avatar
0 0

<– <– <– <– Check the articles section on the left, and read one :) <– <– <– <–


ghost's Avatar
0 0

Well, this isn't a spoiler, because it is posted under Real 1's description (johndoe/password): The password to johndoe is 'password' without the single quotes (').

After you log in, you need to find a certain directory, which will give you the AuthID for the admin. Go to toys.php, and inject the AuthID, then change the price. There you go!


ghost's Avatar
0 0

ok thanks iv found that. i last ttried the injection on the login page :s il try on toys now.. thanks.


ghost's Avatar
0 0

well iv got the javascript:void(docu<i></i>ment.cookie="AuthID=******");

but when i enter it on toys.php and refresh… nothing happens at all?


ghost's Avatar
0 0

change all the variables, not just the password, and then refresh.


ghost's Avatar
0 0

sorry, what do you mean by variables? as far as i can see theres only 1 :whoa:?