Network Security Sam is going down with the ship - he's determined to keep obscuring the password file, no matter how many times people manage to recover it. This time the file is saved in /var/www/hackthissite.org/html/missions/basic/9/.In the last level, however, in my attempt to limit people to using server side includes to display the directory listing to level 8 only, I have mistakenly screwed up somewhere.. there is a way to get the obscured level 9 password. See if you can figure out how...This level seems a lot trickier then it actually is, and it helps to have an understanding of how the script validates the user's input. The script finds the first occurance of '<--', and looks to see what follows directly after it.Its clearly stated that we cannot see the directory listing in level 8 because the password we enter is filtered.But its also stated that
"in my attempt to limit people to using server side includes to display the directory listing to level 8 only,"
which means we can still see directory listing on level 8.
go back to level 8 and modifiy the command we used in previous level to
<!--#exec cmd="ls ../../9"-->
Now, we could see the files of level 9 listed,use the obscured looking file and goto the file using url as we did in previous level. GOTCHA!!!<
Password
Comments
Post a Comment