Skip to main content

Hack This Site Javascript Mission 4

Faith is trying to trick you... she knows that you're tired after all the math works... 
 So, we are facing another java-script challenge.whatever the challenge, we should check all our previous knowledge here.Type in something and hit Check Password.It alerts "Rawr, nope, try again!". Lets view the source code.Right click and select view source.Now right click on the check password button and inspect,we saw the following code,
<button onclick="javascript:check(document.getElementById('pass').value)">Check Password</button>
Now we know that whatever we type is send to check function.Go to the  source code we already viewed and search for check.

GOT THIS SCRIPT:

<script language="Javascript"> RawrRawr = "moo";
function check(x)
{
        "+RawrRawr+" == "hack_this_site"
if (x == ""+RawrRawr+"")
        {
alert("Rawr! win!");
                window.location = "../../../missions/javascript/4/?lvl_password="+x;
        } else {
alert("Rawr, nope, try again!");
}
}

</script>
====================
This is the most cunning part, it misleads us.For people like you and me when we take a quick glance we see our password is compared with ""+RawrRawr+"" and more over in the above line this is written:
 "+RawrRawr+" == "hack_this_site"
this is enough to mislead.If you watch it closely actually x is not compared with +RawrRawr+ more over  its compared with RawrRawr in the start and end "" is added with it but "" is null so we only need value of RawrRawr and you can clearly see the value in the script itself.!

Comments

Popular posts from this blog

Hack This Site Basic 8

Sam remains confident that an obscured password file is still the best idea, but he screwed up with the calendar program. Sam has saved the unencrypted password file in /var/www/hackthissite.org/html/missions/basic/8/  However, Sam's young daughter Stephanie has just learned to program in PHP. She's talented for her age, but she knows nothing about security. She recently learned about saving files, and she wrote a script to demonstrate her ability. So, we know the password is stored in some obscured password file.  Lets try the same code as we did in level 7. But the code 'ls' is not treated as command. so lets try it differently. Try with aaa;<!--ls--> it also failed but got a message: If you are trying to use server side includes to solve the challenge, you are on the right track: but I have limited the commands allowed to ones relevant towards finding the password file for security reasons(because there will always be that one person who decides to ...

Hack This Site! Basic 4

This time Sam hardcoded the password into the script. However, the password is long and complex, and Sam is often forgetful. So he wrote a script that would email his password to him auto And below this,There is a button for sending password to Sam's email.What we should do? right click on the button ,if you are in google chrome ,select > inspect . Now on right side you could see the script of that button. In this script you could see, <input type="hidden" name="to" value="sam@hackthissite.org"> Got any idea? yea , all you have to do is change the email to whatever  email you registered in Hackthis site ! Now check your mail,there must be the password you needed! Keep going!

Hack This Site Basic 11

Sam decided to make a music site. Unfortunately he does not understand Apache. This mission is a bit harder than the other basics. As you may have noticed! when we visit this level all we are given with is some line about song.This line changes on each refresh.From this we assume that this is not the real page we need to visit.But how we find our requirement? There is a tool in Kali Linux called 'Dirb'. But for now Iam using an online service for this >> URL FUZZER << . First we give the url and search for files with .php extension. select start scan.Wait for scan to finish. So,we have found a file.Now visit it as: https://www.hackthissite.org/missions/basic/11/index.php There is our login page.still we are stuck!we don't have the password or any hint in the source code of this page. Lets run another scan on the URL Fuzzer ,this time for directories  Same way start scan and wait for it to finish. There are two possible directori...