wargame 1 (2/5/2010)

Questions? Stuck? post here....
Post Reply
User avatar
Kirk
suck-o enforcer
suck-o enforcer
Posts: 547
Joined: 25 Apr 2009, 16:00
14
Contact:

wargame 1 (2/5/2010)

Post by Kirk »

so for wargame one i have to get root access to the site. but i am not allowed to scan suck-o.net.
I looked for a thread that would help me understand what it is exactly i am suppose to do but there isnt one.

The first thing i did was to install the FF add on firebug. i want to know what the code says.

Keep in mind guys that i have never hacked anything. i am lower than a skiddie here. i understand concepts and theory but lack hands on training. so any help would be awesome.

User avatar
computathug
Administrator
Administrator
Posts: 2693
Joined: 29 Mar 2007, 16:00
17
Location: UK
Contact:

Post by computathug »

Read the through the posts Kirk, check the sticky thread for wargame 1 and check through the other posts. The answer is there just keep reading. read about what an sql, XSS injection is. look and see how the browser reacts as each page changes.

Good luck 8)
The devil can cite Scripture for his purpose.
-- William Shakespeare, "The Merchant of Venice"
https://tshirt-memes.com

User avatar
Gogeta70
^_^
^_^
Posts: 3275
Joined: 25 Jun 2005, 16:00
18

Post by Gogeta70 »

Yeah, look up XSS, and malformed urls. ^_^
¯\_(ツ)_/¯ It works on my machine...

User avatar
DNR
Digital Mercenary
Digital Mercenary
Posts: 6114
Joined: 24 Feb 2006, 17:00
18
Location: Michigan USA
Contact:

Post by DNR »

Kirk, not much info or entry will be gained by scanning the server or trying to brute force something. The tricks are usually using a defect in the applications to exploit itself, so it is more of a software attack.

this prevents problems with scanning and such that tick off the ISPs. The key is to look at the configurations.

Check out the older wargame results, you'll find a common theme.

We will also have Puzzles on the suck-o 2v - stories and files to decipher to decode the answers. An example will be a wireshark file for members to download and read to explain what the capture found.

DNR
-
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.

User avatar
Kirk
suck-o enforcer
suck-o enforcer
Posts: 547
Joined: 25 Apr 2009, 16:00
14
Contact:

Post by Kirk »

@DNR that all sounds exciting as hell. cant wait for suck-o v2 to come out.

Finished wargame one. I know how i did it but not too sure of why it works exactly.

User avatar
Gogeta70
^_^
^_^
Posts: 3275
Joined: 25 Jun 2005, 16:00
18

Post by Gogeta70 »

Did you send the completion code to an admin?

Anyway, i can't say too much, but almost all web applications (made in php) are completely dependent on user input. So, the basis behind all of these wargames is a user sending unexpected input...
¯\_(ツ)_/¯ It works on my machine...

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

validated....congrats Kirk... :D
Image

Post Reply