»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Off Topic Community

Reply
 
LinkBack Thread Tools Display Modes
Old 06-17-2003, 02:24 PM   #1 (permalink)
Registered User
 
sixf00t4's Avatar
 
Join Date: Aug 2002
Location: Western PA
Posts: 2,296
sixf00t4 is on a distinguished road
Send a message via ICQ to sixf00t4 Send a message via AIM to sixf00t4 Send a message via Yahoo to sixf00t4
Gaming Legal hacking (walkthrough:))

lets all work together, when you beat a level JUST POST HOW YOU DID IT!!! not the answers!!!


LEVEL 1: view the source of the document, in IE, to to view, then view source. search the top of the code and it will tell you the password.

LEVEL 2: open notepad, and open the url for the flash file. http://www.try2hack.nl/levels/level2.swf just copy and paste that into notepade to open it. you will then see a whole bunch of garbage, but the U/P are in there.

LEVEL 3: there is a line at the top that says <script src="JavaScript"></script>
if you put JavaScript into the url. http://www.try2hack.nl/levels/JavaScript you get the user and password and you see the password= and correct site and wrong site = stuff that the script on the lvl 3 page was pulling the info from.

LEVEL 4: get a java decompiler and openned the .class file in it, somewhere in there it will says "level4" well that is a file. http://www.try2hack.nl/levels/level4 if you view the source on that page it will tell you everything. BobOmega (with blazer's help i think) is a 1337 H4x0r

LEVEL 5: I quit

__________________
[url=http://joshuadhall.com]My blog[/url]

Last edited by sixf00t4; 06-17-2003 at 08:23 PM.
sixf00t4 is offline   Reply With Quote
Old 06-17-2003, 03:41 PM   #2 (permalink)
Registered User
 
Join Date: May 2003
Location: N 43.240 W 80.247
Posts: 136
Computer is on a distinguished road
I am not following you for number 2 what do you mean by open the url. and how did you get the page with the uname a pass to come up without surrounding things?
Computer is offline   Reply With Quote
Old 06-17-2003, 03:45 PM   #3 (permalink)
Registered User
 
sixf00t4's Avatar
 
Join Date: Aug 2002
Location: Western PA
Posts: 2,296
sixf00t4 is on a distinguished road
Send a message via ICQ to sixf00t4 Send a message via AIM to sixf00t4 Send a message via Yahoo to sixf00t4
you aren't supposed to click on that link. .swf are flash files that can be viewed in browsers. if you look at the level2 source it you can see that the swf file is called level2.swf and is in the same directory. that is how you know what it is and where it is. so now you need to open that file in notepad to 'read' its contents
__________________
[url=http://joshuadhall.com]My blog[/url]
sixf00t4 is offline   Reply With Quote
Old 06-17-2003, 03:55 PM   #4 (permalink)
Registered User
 
BobOmega's Avatar
 
Join Date: May 2002
Location: Youngstown (well near it) Ohio
Posts: 1,014
BobOmega is on a distinguished road
Send a message via ICQ to BobOmega Send a message via AIM to BobOmega
lvl 3 requires a little bit of javascrpt know how. try looking at the lvl 3 page where it says "If you don't get a javascript prompt to enter the password, it means your browser doesn't support JavaScript." everything you need is on there.
i used opera to get there. it pops the no java page before it goes to disney i just hit back. if you want how to do it pm me. i dont know if i should post it.
BobOmega is offline   Reply With Quote
Old 06-17-2003, 04:02 PM   #5 (permalink)
Registered User
 
Join Date: Jan 2003
Location: Orange, Mass.
Posts: 490
Blazer06 is on a distinguished road
Send a message via AIM to Blazer06
level 4 - *ahem* temp file *ahem*

level 5 - don't know yet. download dodi (do search on google). Open the exe in it, and then read the bas files. Convert the numbers to letters using the string in the exe when opend in notepad.


Blaze
Blazer06 is offline   Reply With Quote
Old 06-17-2003, 04:05 PM   #6 (permalink)
Registered User
 
BobOmega's Avatar
 
Join Date: May 2002
Location: Youngstown (well near it) Ohio
Posts: 1,014
BobOmega is on a distinguished road
Send a message via ICQ to BobOmega Send a message via AIM to BobOmega
what temp file for 4? either that or i cannot read at all.

edit nevermind. i'm dumb

Last edited by BobOmega; 06-17-2003 at 04:10 PM.
BobOmega is offline   Reply With Quote
Old 06-17-2003, 04:09 PM   #7 (permalink)
Registered User
 
sixf00t4's Avatar
 
Join Date: Aug 2002
Location: Western PA
Posts: 2,296
sixf00t4 is on a distinguished road
Send a message via ICQ to sixf00t4 Send a message via AIM to sixf00t4 Send a message via Yahoo to sixf00t4
i dont get it, it is the same page. there is nothing on the page or in the source that works password and url wise.
__________________
[url=http://joshuadhall.com]My blog[/url]
sixf00t4 is offline   Reply With Quote
Old 06-17-2003, 04:11 PM   #8 (permalink)
Registered User
 
BobOmega's Avatar
 
Join Date: May 2002
Location: Youngstown (well near it) Ohio
Posts: 1,014
BobOmega is on a distinguished road
Send a message via ICQ to BobOmega Send a message via AIM to BobOmega
well the password itself isn't on that page. where to find it is however said. thats why you need to know how the script works. its getting the user and password from somewhere else...

also after 4 is where i start to quit. i dont want to deal with VB files.
BobOmega is offline   Reply With Quote
Old 06-17-2003, 07:14 PM   #9 (permalink)
Registered User
 
Martoch's Avatar
 
Join Date: Mar 2002
Location: Ft. Walton Beach, FL
Posts: 4,056
Martoch is on a distinguished road
Send a message via AIM to Martoch
Quote:
Originally posted by BobOmega
lvl 3 requires a little bit of javascrpt know how. try looking at the lvl 3 page where it says "If you don't get a javascript prompt to enter the password, it means your browser doesn't support JavaScript." everything you need is on there.
I'm viewing that info in Notepad, hopefully it's all there...so far I've been to disneyland and I've gotten the "it isn't that easy" phony URL. I don't see what I'm missing, but then again I'm not so sure what I'm looking for. I like how the source looks like it's giving away the answers, but doesn't give away the answers (as far as I can tell anyway).

Quote:
pwd = prompt("Please enter the password for level 3:","");
if (pwd==PASSWORD){
alert("Allright!\nEntering Level 4 ...");
location.href = CORRECTSITE;
}
else {
alert("WRONG!\nBack to disneyland !!!");
location.href = WRONGSITE;
}
PASSWORD="AbCdE";
CORRECTSITE="level4-sfvfxc.xhtml";
WRONGSITE="http://www.disney.com";
Martoch is offline   Reply With Quote
Old 06-17-2003, 07:20 PM   #10 (permalink)
Registered User
 
originel's Avatar
 
Join Date: Jun 2002
Location: Texas Tech
Posts: 1,538
originel is on a distinguished road
Send a message via AIM to originel
well, like it's been said before, PASSWORD, CORRECTSITE, and WRONGSITE are being stored in another file. so you just need to find the file.

my recommendation is to read through and determine exactly what each line of code does, because what you're looking for could very easily be mistaken for something else.

EDIT: about level 5.

i'm still working on this one, but here is my feeling. i've found a decoy user/pass by going through multiple paths.

also i used dodi and have concluded that the answer is NOT in the make or main files, so it's in the form file. the problem is i can't get an ascii version of the form, so i can't do anything with it (since ms stopped using binary frm files w/ VB4). so if i can find a copy of VB3 i think i can get it. or find a way to convert it (maybe fake frms2txt to think that vb6 is actually vb3, but i don't think that will work).

my current theory is that they are using an algorithm to store the user and pass cause it isn't stored directly anywhere, i went through the exe with a hex editor and the only ascii values are either random commands or the decoy stuff.

Last edited by originel; 06-17-2003 at 07:26 PM.
originel is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 03:15 AM.