<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Axino.net &#187; hackthissite</title>
	<atom:link href="http://www.axino.net/tag/hackthissite/feed" rel="self" type="application/rss+xml" />
	<link>http://www.axino.net</link>
	<description>The other side of atom.</description>
	<lastBuildDate>Thu, 15 Jul 2010 12:45:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Javascript Missions 2 :: Disable Javascript</title>
		<link>http://www.axino.net/tutorial/2010/01/javascript-missions-2-disable-javascript</link>
		<comments>http://www.axino.net/tutorial/2010/01/javascript-missions-2-disable-javascript#comments</comments>
		<pubDate>Wed, 06 Jan 2010 00:54:35 +0000</pubDate>
		<dc:creator>Arxleol</dc:creator>
				<category><![CDATA[hackthissite.org]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[tutorial]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackthissite]]></category>
		<category><![CDATA[how to]]></category>
		<category><![CDATA[solution]]></category>

		<guid isPermaLink="false">http://www.axino.net/?p=739</guid>
		<description><![CDATA[In the second javascript mission we have to disable javascript to login or solve mission. Mission introduction: Disable Javascript faith had made a redirect script and logout with javascript to keep hackers away In order to disable javascript in Firefox you have to go to Tools-&#62;Options&#8230; and then Content tab. And uncheck the box next to Enable [...]]]></description>
			<content:encoded><![CDATA[<p>In the second javascript mission we have to disable javascript to login or solve mission.</p>
<p><span id="more-739"></span></p>
<p>Mission introduction:</p>
<blockquote><p><span style="font-size: xx-small;"><strong>Disable Javascript</strong></span><br />
faith had made a redirect script and logout with javascript to keep hackers away</p></blockquote>
<p>In order to disable javascript in Firefox you have to go to<strong> Tools-&gt;Options&#8230;</strong> and then <strong>Content </strong>tab. And <strong>uncheck the box</strong> next to <strong>Enable javascript</strong>.</p>
<p><img class="aligncenter" title="Javascript enable" src="http://i46.tinypic.com/25p1gxt.jpg" alt="" width="534" height="499" /></p>
<p>Now you should click on the link Take this challenge, and after that win this challenge.<strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.axino.net/tutorial/2009/06/javascript-missions-1-idiot-test" rel="bookmark" title="Saturday 20.06.2009">Javascript Missions 1 :: Idiot Test</a></li>
<li><a href="http://www.axino.net/tutorial/2009/11/basic-web-hacking-7-double-login" rel="bookmark" title="Tuesday 10.11.2009">Basic web hacking 7 :: double login</a></li>
<li><a href="http://www.axino.net/tutorial/2010/05/javascript-missions-5-escape" rel="bookmark" title="Wednesday 19.05.2010">Javascript Missions 5 :: Escape!</a></li>
<li><a href="http://www.axino.net/tutorial/2009/02/hackthissiteorg-basic-1-password-is" rel="bookmark" title="Sunday 01.02.2009">hackthissite.org basic 1 :: password is</a></li>
<li><a href="http://www.axino.net/tutorial/2009/11/basic-web-hacking-9-null-poison-byte" rel="bookmark" title="Tuesday 17.11.2009">Basic web hacking 9 :: null poison byte</a></li>
</ul>
<p><!-- Similar Posts took 4.592 ms --></p>
 <img src="http://www.axino.net/wordpress/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=739" width="1" height="1" style="display: none;" />]]></content:encoded>
			<wfw:commentRss>http://www.axino.net/tutorial/2010/01/javascript-missions-2-disable-javascript/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>hackthissite.org extbasic 8 :: Perl is a bitch sometimes</title>
		<link>http://www.axino.net/tutorial/2010/01/hackthissite-org-extbasic-8-perl-is-a-bitch-sometimes</link>
		<comments>http://www.axino.net/tutorial/2010/01/hackthissite-org-extbasic-8-perl-is-a-bitch-sometimes#comments</comments>
		<pubDate>Tue, 05 Jan 2010 02:01:47 +0000</pubDate>
		<dc:creator>Arxleol</dc:creator>
				<category><![CDATA[hackthissite.org]]></category>
		<category><![CDATA[perl]]></category>
		<category><![CDATA[tutorial]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackthissite]]></category>
		<category><![CDATA[how to]]></category>
		<category><![CDATA[solution]]></category>
		<category><![CDATA[Visual basic]]></category>

		<guid isPermaLink="false">http://www.axino.net/?p=736</guid>
		<description><![CDATA[So our very dear Billy decided to work some code in perl. Introduction to mission gives us clue that Billy is used to Visual Basic code and therefore we probably need to search for difference in the code, that in fact is syntax similar to VB. So Bill Gates was tired of VisualBasic and now [...]]]></description>
			<content:encoded><![CDATA[<p>So our very dear Billy decided to work some code in perl.</p>
<p><span id="more-736"></span></p>
<p>Introduction to mission gives us clue that Billy is used to Visual Basic code and therefore we probably need to search for difference in the code, that in fact is syntax similar to VB.</p>
<blockquote><p>So Bill Gates was tired of VisualBasic and now did some Perl, too bad; this script has a security flaw that allows everyone access to the company records! Fix the flaw for him!</p></blockquote>
<p>Source code we have to examine:</p>
<blockquote>

<div class="wp_syntax"><div class="code"><pre class="perl" style="font-family:monospace;"><span style="color: #666666; font-style: italic;">#!/usr/bin/perl</span>
&nbsp;
<span style="color: #339933;">&lt;</span>a href<span style="color: #339933;">=</span><span style="color: #ff0000;">&quot;http://perldoc.perl.org/functions/chomp.html&quot;</span><span style="color: #339933;">&gt;</span>chomp<span style="color: #339933;">&lt;/</span>a<span style="color: #339933;">&gt;</span><span style="color: #009900;">&#40;</span><span style="color: #b1b100;">my</span> <span style="color: #0000ff;">$User</span> <span style="color: #339933;">=</span> <span style="color: #ff0000;">`/usr/bin/whoami`</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span>
&nbsp;
<span style="color: #339933;">&lt;</span>a href<span style="color: #339933;">=</span><span style="color: #ff0000;">&quot;http://perldoc.perl.org/functions/print.html&quot;</span><span style="color: #339933;">&gt;</span>print<span style="color: #339933;">&lt;/</span>a<span style="color: #339933;">&gt;</span> <span style="color: #ff0000;">&quot;Checking your access level...<span style="color: #000099; font-weight: bold;">\n</span>&quot;</span><span style="color: #339933;">;</span>
&nbsp;
<span style="color: #b1b100;">if</span> <span style="color: #009900;">&#40;</span><span style="color: #0000ff;">$User</span> <span style="color: #339933;">==</span> <span style="color: #ff0000;">'BillGates'</span><span style="color: #009900;">&#41;</span>
<span style="color: #009900;">&#123;</span>
<span style="color: #339933;">&lt;</span>a href<span style="color: #339933;">=</span><span style="color: #ff0000;">&quot;http://perldoc.perl.org/functions/print.html&quot;</span><span style="color: #339933;">&gt;</span>print<span style="color: #339933;">&lt;/</span>a<span style="color: #339933;">&gt;</span> <span style="color: #ff0000;">&quot;Authorized! Here are the company records:<span style="color: #000099; font-weight: bold;">\n</span>&quot;</span> <span style="color: #339933;">.</span> <span style="color: #ff0000;">`cat /home/BillGates/CompanyRecords.db`</span><span style="color: #339933;">;</span>
<span style="color: #339933;">&lt;</span>a href<span style="color: #339933;">=</span><span style="color: #ff0000;">&quot;http://perldoc.perl.org/functions/die.html&quot;</span><span style="color: #339933;">&gt;</span>die<span style="color: #339933;">&lt;/</span>a<span style="color: #339933;">&gt;</span><span style="color: #009900;">&#40;</span><span style="color: #ff0000;">&quot;Closing...<span style="color: #000099; font-weight: bold;">\n</span>&quot;</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span>
<span style="color: #009900;">&#125;</span>
&nbsp;
<span style="color: #339933;">&lt;</span>a href<span style="color: #339933;">=</span><span style="color: #ff0000;">&quot;http://perldoc.perl.org/functions/die.html&quot;</span><span style="color: #339933;">&gt;</span>die<span style="color: #339933;">&lt;/</span>a<span style="color: #339933;">&gt;</span><span style="color: #009900;">&#40;</span><span style="color: #ff0000;">&quot;You're not authorized!<span style="color: #000099; font-weight: bold;">\n</span>&quot;</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span></pre></div></div>

</blockquote>
<p>Examining source code brought the following line of code to my notice.</p>
<blockquote>

<div class="wp_syntax"><div class="code"><pre class="perl" style="font-family:monospace;"><span style="color: #b1b100;">if</span> <span style="color: #009900;">&#40;</span><span style="color: #0000ff;">$User</span> <span style="color: #339933;">==</span> <span style="color: #ff0000;">'BillGates'</span><span style="color: #009900;">&#41;</span></pre></div></div>

</blockquote>
<p>So we have to check whether in <strong>perl </strong><strong>Strings </strong>are <strong>compared </strong>with<strong> &#8220;==&#8221; </strong>syntax. From the <a href="http://www.shlomifish.org/lecture/Perl/Newbies/lecture1/conditionals/string.html" target="_blank">list of perl comparators</a> you will notice that Billy should have used <strong>eq</strong> instead of &#8220;==&#8221;.</p>
<p>So solution is:</p>
<blockquote>

<div class="wp_syntax"><div class="code"><pre class="perl" style="font-family:monospace;"><span style="color: #b1b100;">if</span> <span style="color: #009900;">&#40;</span><span style="color: #0000ff;">$User</span> <span style="color: #b1b100;">eq</span> <span style="color: #ff0000;">'BillGates'</span><span style="color: #009900;">&#41;</span></pre></div></div>

</blockquote>
<p><strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.axino.net/tutorial/2009/11/basic-web-hacking-11-user-agents-ii" rel="bookmark" title="Thursday 19.11.2009">Basic web hacking 11 :: User Agents II</a></li>
<li><a href="http://www.axino.net/tutorial/2010/06/javascript-challenge-13-cookie" rel="bookmark" title="Wednesday 09.06.2010">JavaScript Challenge 13 :: Cookie</a></li>
<li><a href="http://www.axino.net/tutorial/2009/11/basic-web-hacking-12-include-me-in" rel="bookmark" title="Saturday 21.11.2009">Basic web hacking 12 :: include me in</a></li>
<li><a href="http://www.axino.net/tutorial/2010/05/hack-test-com-7-examine-source-code" rel="bookmark" title="Friday 14.05.2010">hack-test.com 7 :: examine source code</a></li>
<li><a href="http://www.axino.net/tutorial/2009/12/how-to-use-netbeans-and-google-code" rel="bookmark" title="Monday 28.12.2009">How to use Netbeans and Google code</a></li>
</ul>
<p><!-- Similar Posts took 4.883 ms --></p>
 <img src="http://www.axino.net/wordpress/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=736" width="1" height="1" style="display: none;" />]]></content:encoded>
			<wfw:commentRss>http://www.axino.net/tutorial/2010/01/hackthissite-org-extbasic-8-perl-is-a-bitch-sometimes/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>hackthissite.org extbasic 6 :: Sucky Sysadmin</title>
		<link>http://www.axino.net/tutorial/2010/01/hackthissite-org-extbasic-6-sucky-sysadmin</link>
		<comments>http://www.axino.net/tutorial/2010/01/hackthissite-org-extbasic-6-sucky-sysadmin#comments</comments>
		<pubDate>Mon, 04 Jan 2010 20:25:08 +0000</pubDate>
		<dc:creator>Arxleol</dc:creator>
				<category><![CDATA[hackthissite.org]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[tutorial]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackthissite]]></category>
		<category><![CDATA[how to]]></category>
		<category><![CDATA[solution]]></category>

		<guid isPermaLink="false">http://www.axino.net/?p=732</guid>
		<description><![CDATA[In the 6th extended basic mission, we have to use exploit of php server configured to use global variables. Mission introduction: This site in run by a new sysadmin who does not know much about web configuration The script is located at http://moo.com/moo.php Attempt to make the script think you are authed by entering the correct [...]]]></description>
			<content:encoded><![CDATA[<p>In the 6th extended basic mission, we have to use exploit of php server configured to use global variables.</p>
<p><span id="more-732"></span></p>
<p>Mission introduction:</p>
<blockquote><p>This site in run by a new sysadmin who does not know much about <a id="KonaLink0" href="http://www.hackthissite.org/missions/extbasic/template.php?lvl=6#" target="undefined"><span>web</span></a> configuration<br />
The script is located at http://moo.com/moo.php</p>
<p>Attempt to make the script think you are authed by entering the correct URI.</p></blockquote>
<blockquote><p>Here is the script (me.php):</p></blockquote>
<p>Script we have to exploit:</p>
<blockquote>

<div class="wp_syntax"><div class="code"><pre class="php" style="font-family:monospace;"><span style="color: #339933;">&amp;</span>lt<span style="color: #339933;">;</span>?php
<span style="color: #000088;">$user</span> <span style="color: #339933;">=</span> <span style="color: #000088;">$_GET</span><span style="color: #009900;">&#91;</span><span style="color: #0000ff;">'user'</span><span style="color: #009900;">&#93;</span><span style="color: #339933;">;</span>
<span style="color: #000088;">$pass</span> <span style="color: #339933;">=</span> <span style="color: #000088;">$_GET</span><span style="color: #009900;">&#91;</span><span style="color: #0000ff;">'pass'</span><span style="color: #009900;">&#93;</span><span style="color: #339933;">;</span>
<span style="color: #b1b100;">if</span> <span style="color: #009900;">&#40;</span>isAuthed<span style="color: #009900;">&#40;</span><span style="color: #000088;">$user</span><span style="color: #339933;">,</span><span style="color: #000088;">$pass</span><span style="color: #009900;">&#41;</span><span style="color: #009900;">&#41;</span>
<span style="color: #009900;">&#123;</span>
<span style="color: #000088;">$passed</span><span style="color: #339933;">=</span><span style="color: #009900; font-weight: bold;">TRUE</span><span style="color: #339933;">;</span>
<span style="color: #009900;">&#125;</span>
<span style="color: #b1b100;">if</span> <span style="color: #009900;">&#40;</span><span style="color: #000088;">$passed</span><span style="color: #339933;">==</span><span style="color: #009900; font-weight: bold;">TRUE</span><span style="color: #009900;">&#41;</span>
<span style="color: #009900;">&#123;</span>
<span style="color: #b1b100;">echo</span> <span style="color: #0000ff;">'you win'</span><span style="color: #339933;">;</span>
<span style="color: #009900;">&#125;</span>
?<span style="color: #339933;">&amp;</span>gt<span style="color: #339933;">;</span>
<span style="color: #339933;">&amp;</span>lt<span style="color: #339933;">;</span>form action<span style="color: #339933;">=</span><span style="color: #0000ff;">&quot;me.php&quot;</span> method<span style="color: #339933;">=</span><span style="color: #0000ff;">&quot;get&quot;</span><span style="color: #339933;">&amp;</span>gt<span style="color: #339933;">;</span>
<span style="color: #339933;">&amp;</span>lt<span style="color: #339933;">;</span>input type<span style="color: #339933;">=</span><span style="color: #0000ff;">&quot;text&quot;</span> name<span style="color: #339933;">=</span><span style="color: #0000ff;">&quot;user&quot;</span> <span style="color: #339933;">/&amp;</span>gt<span style="color: #339933;">;</span>
<span style="color: #339933;">&amp;</span>lt<span style="color: #339933;">;</span>input type<span style="color: #339933;">=</span><span style="color: #0000ff;">&quot;password&quot;</span> name<span style="color: #339933;">=</span><span style="color: #0000ff;">&quot;pass&quot;</span> <span style="color: #339933;">/&amp;</span>gt<span style="color: #339933;">;</span>
<span style="color: #339933;">&amp;</span>lt<span style="color: #339933;">;/</span>form<span style="color: #339933;">&amp;</span>gt<span style="color: #339933;">;</span>
<span style="color: #339933;">&amp;</span>lt<span style="color: #339933;">;</span>?php
<span style="color: #000000; font-weight: bold;">function</span> isAuthed<span style="color: #009900;">&#40;</span><span style="color: #000088;">$a</span><span style="color: #339933;">,</span><span style="color: #000088;">$b</span><span style="color: #009900;">&#41;</span>
<span style="color: #009900;">&#123;</span>
<span style="color: #b1b100;">return</span> <span style="color: #009900; font-weight: bold;">FALSE</span><span style="color: #339933;">;</span>
<span style="color: #009900;">&#125;</span>
?<span style="color: #339933;">&amp;</span>gt<span style="color: #339933;">;</span></pre></div></div>

</blockquote>
<p>Now notice that form is passing parameters trough <strong>get method</strong>. This means that if server is not configured correctly or using global variables we can change any other variable in the code by entering it in the URL. However, before we proceed we have to exam code.</p>
<p>Method<strong> isAuthed</strong> always returns <strong>FALSE</strong>.  Therefore we cannot enter combination of username and password that will authenticate us. The third variable <strong>$passed</strong> is in fact control variable. If this variable is set to <strong>TRUE </strong>we win. Now we have to figure out how to change URL to change variable passed to TRUE.</p>
<p>From introduction we know that script is located on: <strong> http://moo.com/moo.php </strong>so to pass variable trough GET we attach <strong>?passed=somevalue</strong>. And passed will have value <strong>somevalue</strong>.</p>
<p>So the final URL is:</p>
<blockquote><p>http://moo.com/moo.php?passed=TRUE</p></blockquote>
<p><strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.axino.net/tutorial/2009/03/hackthissiteorg-basic-2-password-is-not" rel="bookmark" title="Wednesday 11.03.2009">hackthissite.org basic 2 :: password is not</a></li>
<li><a href="http://www.axino.net/hack/hellboundhackersorg/2009/11/basic-web-hacking-5-asterix-the-wildcard" rel="bookmark" title="Monday 09.11.2009">Basic web hacking 5 :: asterix the wildcard</a></li>
<li><a href="http://www.axino.net/tutorial/2009/05/keylogger-in-c-hooking-and-unhooking-keyboard-hook" rel="bookmark" title="Thursday 07.05.2009">Keylogger in C# :: Hooking and unhooking keyboard hook</a></li>
<li><a href="http://www.axino.net/tutorial/2009/09/basic-web-hacking-1-simple-enter-pass" rel="bookmark" title="Tuesday 29.09.2009">Basic Web Hacking 1 :: Simple Enter Pass</a></li>
<li><a href="http://www.axino.net/hack/hackertestnet/2009/01/hackertestnet-level-2" rel="bookmark" title="Thursday 08.01.2009">hackertest.net level 2 :: Analysis Sherlock</a></li>
</ul>
<p><!-- Similar Posts took 5.708 ms --></p>
 <img src="http://www.axino.net/wordpress/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=732" width="1" height="1" style="display: none;" />]]></content:encoded>
			<wfw:commentRss>http://www.axino.net/tutorial/2010/01/hackthissite-org-extbasic-6-sucky-sysadmin/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>hackthissite.org extbasic 4 :: Finda Fake 2</title>
		<link>http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-4-finda-fake-2</link>
		<comments>http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-4-finda-fake-2#comments</comments>
		<pubDate>Sun, 27 Dec 2009 09:15:21 +0000</pubDate>
		<dc:creator>Arxleol</dc:creator>
				<category><![CDATA[hackthissite.org]]></category>
		<category><![CDATA[tutorial]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackthissite]]></category>
		<category><![CDATA[how to]]></category>
		<category><![CDATA[solution]]></category>

		<guid isPermaLink="false">http://www.axino.net/?p=715</guid>
		<description><![CDATA[In extended basic mission 4 we will again try to decypher unfamiliar language. Very similar to the one from the previous mission. Notice in the introduction of the mission the very last line: Often times you will need to decipher a language which you can not find on google, or is encrypted in some way [...]]]></description>
			<content:encoded><![CDATA[<p>In extended basic mission 4 we will again try to decypher unfamiliar language. Very similar to the one from the <a href="http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-3-finda-fake-1" target="_blank">previous mission</a>.</p>
<p><span id="more-715"></span></p>
<p>Notice in the introduction of the mission the very last line:</p>
<blockquote><p>Often times you will need to decipher a language which you can not find on google, or is encrypted in some way<br />
I have made up a language for you to decipher.  This is slightly harder.  What is the output of this program?<br />
This is a REAL language with REAL rules.  This is practice for obfustication or encrypted functions.</p>
<p>{user types 6,7}</p></blockquote>
<p>Doesn&#8217;t it resambles <strong>call to function</strong> with <strong>parameters 6 and 7</strong>!</p>
<p>Now function would look like the following:</p>
<pre>BEGIN F.ake
var int as in
int var as in
out var int
</pre>
<p><strong>BEGIN F.ake</strong> is the beginning of the function execution.</p>
<p><strong>var int as in</strong> represents assignment of first parameter to variable <strong>var</strong></p>
<p><strong>int var as in</strong> represents assignment of second parameter to variable <strong>int</strong></p>
<p><strong>out var int</strong> represents output of variables <strong>var</strong> and <strong>int</strong> in this case it is 67<strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-3-finda-fake-1" rel="bookmark" title="Saturday 26.12.2009">hackthissite.org extbasic 3 :: Finda Fake 1</a></li>
<li><a href="http://www.axino.net/tutorial/2010/01/hackthissite-org-extbasic-6-sucky-sysadmin" rel="bookmark" title="Monday 04.01.2010">hackthissite.org extbasic 6 :: Sucky Sysadmin</a></li>
<li><a href="http://www.axino.net/hack/hackertestnet/2009/01/hackertestnet-level-1" rel="bookmark" title="Wednesday 07.01.2009">hackertest.net level 1 :: Cover up basics</a></li>
<li><a href="http://www.axino.net/hack/hackertestnet/2009/01/hackertestnet-level-2" rel="bookmark" title="Thursday 08.01.2009">hackertest.net level 2 :: Analysis Sherlock</a></li>
<li><a href="http://www.axino.net/hack/hackertestnet/2009/01/hackertestnet-level-3" rel="bookmark" title="Sunday 11.01.2009">hackertest.net level 3 :: Same but different</a></li>
</ul>
<p><!-- Similar Posts took 5.631 ms --></p>
 <img src="http://www.axino.net/wordpress/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=715" width="1" height="1" style="display: none;" />]]></content:encoded>
			<wfw:commentRss>http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-4-finda-fake-2/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>hackthissite.org extbasic 3 :: Finda Fake 1</title>
		<link>http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-3-finda-fake-1</link>
		<comments>http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-3-finda-fake-1#comments</comments>
		<pubDate>Fri, 25 Dec 2009 23:47:15 +0000</pubDate>
		<dc:creator>Arxleol</dc:creator>
				<category><![CDATA[hackthissite.org]]></category>
		<category><![CDATA[tutorial]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackthissite]]></category>
		<category><![CDATA[how to]]></category>
		<category><![CDATA[solution]]></category>

		<guid isPermaLink="false">http://www.axino.net/?p=711</guid>
		<description><![CDATA[Well as it is said in the introduction of this mission. Many times you will have to decypher something unusual and this is excelent excercise to make yourself acquinted with stuff. Often times you will need to decipher a language which you can not find on google, or is encrypted in some way I have [...]]]></description>
			<content:encoded><![CDATA[<p>Well as it is said in the introduction of this mission. Many times you will have to decypher something unusual and this is excelent excercise to make yourself acquinted with stuff.</p>
<p><span id="more-711"></span></p>
<blockquote><p>Often times you will need to decipher a language which you can not find on google, or is encrypted in some way<br />
I have made up a language for you to decipher.  What is the output of this program?</p></blockquote>
<p>Obscure source code we have to figure out is:</p>
<pre>BEGIN notr.eal
CREATE int AS 2
DESTROY int AS 0
ANS var AS Create + TO
out TO
</pre>
<p>However you have to notice that it is not similar to any language you might know. Let&#8217;s anlyise it line by line of course the way I figure it out.</p>
<p><strong>BEGIN notr.eal</strong> represents beginning of the function</p>
<p><strong>CREATE int AS 2</strong> as far as I see it is adding 2 to the variable <strong>int</strong></p>
<p><strong>DESTROY int AS 0 </strong>is adding 0 to the variable <strong>int</strong></p>
<p><strong>ANS var AS Create + TO </strong>reading the last value from the stack and that is 20 and passing it inverse to the variable <strong>TO</strong> which has now value 02</p>
<p><strong>out TO</strong> is outputting <strong>02</strong> out.<strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-4-finda-fake-2" rel="bookmark" title="Sunday 27.12.2009">hackthissite.org extbasic 4 :: Finda Fake 2</a></li>
<li><a href="http://www.axino.net/hack/hackertestnet/2009/01/hackertestnet-level-1" rel="bookmark" title="Wednesday 07.01.2009">hackertest.net level 1 :: Cover up basics</a></li>
<li><a href="http://www.axino.net/tutorial/2010/01/hackthissite-org-extbasic-6-sucky-sysadmin" rel="bookmark" title="Monday 04.01.2010">hackthissite.org extbasic 6 :: Sucky Sysadmin</a></li>
<li><a href="http://www.axino.net/tutorial/2010/05/javascript-challenge-7-jump-over" rel="bookmark" title="Sunday 30.05.2010">JavaScript Challenge 7 :: Jump over</a></li>
<li><a href="http://www.axino.net/tutorial/2009/03/hackthissiteorg-basic-2-password-is-not" rel="bookmark" title="Wednesday 11.03.2009">hackthissite.org basic 2 :: password is not</a></li>
</ul>
<p><!-- Similar Posts took 5.596 ms --></p>
 <img src="http://www.axino.net/wordpress/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=711" width="1" height="1" style="display: none;" />]]></content:encoded>
			<wfw:commentRss>http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-3-finda-fake-1/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>hackthissite.org extbasic 2 :: Extension blocking</title>
		<link>http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-2-extension-blocking</link>
		<comments>http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-2-extension-blocking#comments</comments>
		<pubDate>Fri, 25 Dec 2009 22:58:04 +0000</pubDate>
		<dc:creator>Arxleol</dc:creator>
				<category><![CDATA[hackthissite.org]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[tutorial]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackthissite]]></category>
		<category><![CDATA[how to]]></category>
		<category><![CDATA[solution]]></category>

		<guid isPermaLink="false">http://www.axino.net/?p=707</guid>
		<description><![CDATA[Second extended basic mission is somewhat simple. Let&#8217;s solve it In introduction: You have this function, provide the value which must be POST-ed as filename to obtain the desired results: Get the source code of hackthissite.org/index.php here is the function: We have to  find vulnerability in the following code: &#160; So we have to find [...]]]></description>
			<content:encoded><![CDATA[<p>Second extended basic mission is somewhat simple. Let&#8217;s solve it <img src='http://www.axino.net/wordpress/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p><span id="more-707"></span></p>
<p>In introduction:</p>
<blockquote><p>You have this function, provide the value which must be POST-ed as filename to obtain the desired results:<br />
Get the source code of hackthissite.org/index.php<br />
here is the function:</p></blockquote>
<p>We have to  find vulnerability in the following code:</p>

<div class="wp_syntax"><div class="code"><pre class="php" style="font-family:monospace;">&nbsp;</pre></div></div>

<p>So we have to find way to see code of the file on server. From the source code we may see that file to be opened is created merging strings using the name of the file and extension. So we have to enter correct name in the box to see file. Basically correct name is <strong>index </strong>since .php will be attached later in function call.</p>
<p>Now the problem is to solve how to traverse us into the root directory. We will do this by putting <strong>../../</strong> in front of the index. Since ../ returns us one directory back.</p>
<p>Because if you try to put anything in the box you will obtain URL similar to the following one:</p>
<blockquote><p>http://www.hackthissite.org/missions/extbasic/template.php?lvl=2&amp;pass=</p></blockquote>
<p>So you may notice that we are in the directory <strong>missions/extbasic/</strong>. Using ../ will return us two directories back to root directory.</p>
<p>So final combined solution is:</p>
<blockquote><p>../../index</p></blockquote>
<p><strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.axino.net/tutorial/2009/12/hackthissite-org-basic-11-music-collection" rel="bookmark" title="Monday 21.12.2009">hackthissite.org basic 11 :: Music collection</a></li>
<li><a href="http://www.axino.net/tutorial/2009/07/hackthissite-org-basic-8-ssi" rel="bookmark" title="Friday 03.07.2009">hackthissite.org basic 8 :: SSI</a></li>
<li><a href="http://www.axino.net/tutorial/2009/07/hackthissite-org-basic-9-tricky-easy-not" rel="bookmark" title="Sunday 05.07.2009">hackthissite.org basic 9 :: tricky easy not</a></li>
<li><a href="http://www.axino.net/tutorials" rel="bookmark" title="Wednesday 07.01.2009">Tutorials</a></li>
<li><a href="http://www.axino.net/tutorial/2010/05/hackthissite-org-application-3-127-0-0-1" rel="bookmark" title="Thursday 27.05.2010">hackthissite.org Application 3 :: 127.0.0.1</a></li>
</ul>
<p><!-- Similar Posts took 5.503 ms --></p>
 <img src="http://www.axino.net/wordpress/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=707" width="1" height="1" style="display: none;" />]]></content:encoded>
			<wfw:commentRss>http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-2-extension-blocking/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>hackthissite.org extbasic 1 :: Over and out?</title>
		<link>http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-1-over-and-out</link>
		<comments>http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-1-over-and-out#comments</comments>
		<pubDate>Wed, 23 Dec 2009 22:19:34 +0000</pubDate>
		<dc:creator>Arxleol</dc:creator>
				<category><![CDATA[C]]></category>
		<category><![CDATA[hackthissite.org]]></category>
		<category><![CDATA[tutorial]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackthissite]]></category>
		<category><![CDATA[how to]]></category>
		<category><![CDATA[pointer]]></category>
		<category><![CDATA[solution]]></category>

		<guid isPermaLink="false">http://www.axino.net/?p=704</guid>
		<description><![CDATA[First mission in the series of extended basic missions on hackthissite.org is more then simple; Introduction is also fairly easy. You have to give input to a C program which gives you the length of the string. How would you crash it? here is the function: void blah(char *str) { char lol[200]; strcpy(lol, str); } [...]]]></description>
			<content:encoded><![CDATA[<p>First mission in the series of extended basic missions on hackthissite.org is more then simple;</p>
<p><span id="more-704"></span></p>
<p>Introduction is also fairly easy.</p>
<blockquote><p>You have to give input to a C program which gives you the length of the string. How would you crash it?<br />
here is the function:<br />
<span style="font-family: monospace;"><span style="font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;"><br />
</span></span></p>
<div><code> void blah(char *str)<br />
{<br />
char lol[200];<br />
strcpy(lol, str);<br />
}<br />
</code></div>
</blockquote>
<p>Now you have to understand some of <strong>C</strong> to understand this Here we have short function that accepts string as array of chars or to be exact pointer on the first character in the series.</p>
<p>First line of code defines new array with length of<strong> 200 characters</strong>.</p>
<p>Second line of code copies <strong>str</strong> array into <strong>lol</strong> array. However, if str array is longer then lol array program will crash. So you simply have to enter more then 200 characters into the text box and you will crash it.</p>
<p>Here is sample string with 201 characters <img src='http://www.axino.net/wordpress/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<blockquote><p>123451234512345123451234512345123451234512345123451234512345123451234512345123451234512345123451234512345123451234512345123451234512345123451234512345123451234512345123451234512345123451234512345123459</p></blockquote>
<blockquote></blockquote>
<p>With regards,</p>
<p>Ax<strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.axino.net/tutorial/2010/05/javascript-missions-3-math-time" rel="bookmark" title="Monday 17.05.2010">Javascript Missions 3 :: Math time</a></li>
<li><a href="http://www.axino.net/tutorial/2009/06/how-to-obtain-get-parameters-from-url-with-javascript" rel="bookmark" title="Tuesday 09.06.2009">How to obtain get parameters from URL with javascript</a></li>
<li><a href="http://www.axino.net/hack/2009/10/keylogger-in-c-saving-content" rel="bookmark" title="Tuesday 27.10.2009">Keylogger in C# :: Saving content</a></li>
<li><a href="http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-4-finda-fake-2" rel="bookmark" title="Sunday 27.12.2009">hackthissite.org extbasic 4 :: Finda Fake 2</a></li>
<li><a href="http://www.axino.net/tutorial/2010/03/hack-test-com-3-link-colour" rel="bookmark" title="Saturday 20.03.2010">hack-test.com 3 :: link colour</a></li>
</ul>
<p><!-- Similar Posts took 5.818 ms --></p>
 <img src="http://www.axino.net/wordpress/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=704" width="1" height="1" style="display: none;" />]]></content:encoded>
			<wfw:commentRss>http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-1-over-and-out/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>hackthissite.org solutions to all basic missions</title>
		<link>http://www.axino.net/hack/hack-this-site/2009/12/hackthissite-org-solutions-to-all-basic-missions</link>
		<comments>http://www.axino.net/hack/hack-this-site/2009/12/hackthissite-org-solutions-to-all-basic-missions#comments</comments>
		<pubDate>Mon, 21 Dec 2009 19:30:56 +0000</pubDate>
		<dc:creator>Arxleol</dc:creator>
				<category><![CDATA[hackthissite.org]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackthissite]]></category>

		<guid isPermaLink="false">http://www.axino.net/?p=700</guid>
		<description><![CDATA[Here is the list to solutions of all basic missions on hackthissite.org hackthissite.org basic 1 :: password is hackthissite.org basic 2 :: password is not hackthissite.org basic 3 :: password.php hackthissite.org basic 4 :: email to admin hackthissite.org basic 5 :: email to admin II hackthissite.org basic 6 :: encryption system hackthissite.org basic 7 :: [...]]]></description>
			<content:encoded><![CDATA[<p>Here is the list to solutions of all basic missions on hackthissite.org</p>
<p><span id="more-700"></span></p>
<p><a href="http://www.axino.net/tutorial/2009/02/hackthissiteorg-basic-1-password-is"><span style="color: #000000;"><span style="text-decoration: none;"><span style="color: #ffffff;">hackthissite.org basic 1 :: password is</span></span></span></a></p>
<p><a href="http://www.axino.net/tutorial/2009/03/hackthissiteorg-basic-2-password-is-not"><span style="color: #000000;"><span style="text-decoration: none;"><span style="color: #ffffff;">hackthissite.org basic 2 :: password is not</span></span></span></a></p>
<p><a href="http://www.axino.net/tutorial/2009/03/hackthissiteorg-basic-3-passwordphp"><span style="color: #000000;"><span style="text-decoration: none;"><span style="color: #ffffff;">hackthissite.org basic 3 :: password.php</span></span></span></a></p>
<p><a href="http://www.axino.net/tutorial/2009/06/hackthissiteorg-basic-4-email-to-admin"><span style="color: #000000;"><span style="text-decoration: none;"><span style="color: #ffffff;">hackthissite.org basic 4 :: email to admin</span></span></span></a></p>
<p><a href="http://www.axino.net/tutorial/2009/06/hackthissiteorg-basic-5-email-to-admin-ii"><span style="color: #000000;"><span style="text-decoration: none;"><span style="color: #ffffff;">hackthissite.org basic 5 :: email to admin II</span></span></span></a></p>
<p><a href="http://www.axino.net/tutorial/2009/06/hackthissiteorg-basic-6-encryption-system"><span style="color: #000000;"><span style="text-decoration: none;"><span style="color: #ffffff;">hackthissite.org basic 6 :: encryption system</span></span></span></a></p>
<p><a href="http://www.axino.net/tutorial/2009/07/hackthissite-org-basic-7-calendar-is-it"><span style="color: #000000;"><span style="text-decoration: none;"><span style="color: #ffffff;">hackthissite.org basic 7 :: calendar is it!</span></span></span></a></p>
<p><a href="http://www.axino.net/tutorial/2009/07/hackthissite-org-basic-8-ssi"><span style="color: #000000;"><span style="text-decoration: none;"><span style="color: #ffffff;">hackthissite.org basic 8 :: SSI</span></span></span></a></p>
<p><a href="http://www.axino.net/tutorial/2009/07/hackthissite-org-basic-9-tricky-easy-not"><span style="color: #000000;"><span style="text-decoration: none;"><span style="color: #ffffff;">hackthissite.org basic 9 :: tricky easy not</span></span></span></a></p>
<p><a href="http://www.axino.net/hack/hack-this-site/2009/09/hackthissite-org-basic-10-my-cookie-your-cookie"><span style="color: #000000;"><span style="text-decoration: none;"><span style="color: #ffffff;">hackthissite.org basic 10 :: My cookie your cookie</span></span></span></a></p>
<p><a href="http://www.axino.net/tutorial/2009/12/hackthissite-org-basic-11-music-collection"><span style="color: #000000;"><span style="text-decoration: none;"><span style="color: #ffffff;">hackthissite.org basic 11 :: Music collection</span></span></span></a></p>
<p><span style="color: #000000;"><span style="text-decoration: none;">Have fun learning and solving missions.</span></span><strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.axino.net/tutorials" rel="bookmark" title="Wednesday 07.01.2009">Tutorials</a></li>
<li><a href="http://www.axino.net/tutorial/2009/03/hackthissiteorg-basic-3-passwordphp" rel="bookmark" title="Thursday 12.03.2009">hackthissite.org basic 3 :: password.php</a></li>
<li><a href="http://www.axino.net/tutorial/2009/12/hackthissite-org-basic-11-music-collection" rel="bookmark" title="Monday 21.12.2009">hackthissite.org basic 11 :: Music collection</a></li>
<li><a href="http://www.axino.net/tutorial/2009/07/hackthissite-org-basic-7-calendar-is-it" rel="bookmark" title="Wednesday 01.07.2009">hackthissite.org basic 7 :: calendar is it!</a></li>
<li><a href="http://www.axino.net/tutorial/2009/11/basic-web-hacking-7-double-login" rel="bookmark" title="Tuesday 10.11.2009">Basic web hacking 7 :: double login</a></li>
</ul>
<p><!-- Similar Posts took 5.673 ms --></p>
 <img src="http://www.axino.net/wordpress/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=700" width="1" height="1" style="display: none;" />]]></content:encoded>
			<wfw:commentRss>http://www.axino.net/hack/hack-this-site/2009/12/hackthissite-org-solutions-to-all-basic-missions/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>hackthissite.org basic 11 :: Music collection</title>
		<link>http://www.axino.net/tutorial/2009/12/hackthissite-org-basic-11-music-collection</link>
		<comments>http://www.axino.net/tutorial/2009/12/hackthissite-org-basic-11-music-collection#comments</comments>
		<pubDate>Mon, 21 Dec 2009 19:19:27 +0000</pubDate>
		<dc:creator>Arxleol</dc:creator>
				<category><![CDATA[hackthissite.org]]></category>
		<category><![CDATA[tutorial]]></category>
		<category><![CDATA[apache]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackthissite]]></category>
		<category><![CDATA[how to]]></category>
		<category><![CDATA[solution]]></category>

		<guid isPermaLink="false">http://www.axino.net/?p=697</guid>
		<description><![CDATA[Very unsolvable mission according to the hackthissite forums. And many people tried to solve it by searching hints and similar. Maybe even mission introduction in the beginning was a bit fuzzy. Sam decided to make a music site. Unfortunately he does not understand Apache. This mission is a bit harder than the other basics. Now [...]]]></description>
			<content:encoded><![CDATA[<p>Very unsolvable mission according to the hackthissite forums. And many people tried to solve it by searching hints and similar. Maybe even mission introduction in the beginning was a bit fuzzy.</p>
<p><span id="more-697"></span></p>
<blockquote><p>Sam decided to make a music site. Unfortunately he does not understand Apache. This mission is a bit harder than the other basics.</p></blockquote>
<p>Now when you open the first page you will receive message similar to this one:</p>
<blockquote><p>I love my music! &#8220;Lovesick &#8221; is the best!</p></blockquote>
<p>Sooner or later you will figure out that all these songs are written by <a href="http://en.wikipedia.org/wiki/Elton_John" target="_blank">Elton John</a>.</p>
<p>Next step for me was to try <strong>index.php</strong> since it basically is default web page, and in case it is not up on default settings we should see content of the web folder directory. If you enter following URL you will have ability to enter answer but what answer is we will find later on.</p>
<blockquote><p>http://www.hackthissite.org/missions/basic/11/index.php</p></blockquote>
<p>Now we have to find correct directory listings. And after drill down trough forums I found hint that one should do his abc&#8217;s. So after several attempts I managed to find out the following directory:</p>
<blockquote><p>http://www.hackthissite.org/missions/basic/11/e/l/t/o/n/</p></blockquote>
<p>Another thing since there was nothing listed was to check .htaccess file.</p>
<blockquote><p>http://www.hackthissite.org/missions/basic/11/e/l/t/o/n/.htaccess</p>
<pre>IndexIgnore DaAnswer.* .htaccess

order allow,deny
allow from all</pre>
</blockquote>
<p>From this file we are able to figure out that DaAnswer directory is hidden from directory structure. So let&#8217;s traverse to that directory. On the following URL:</p>
<blockquote><p>http://www.hackthissite.org/missions/basic/11/e/l/t/o/n/DaAnswer</p></blockquote>
<p>You will find something similar to the following sentence:</p>
<blockquote><p>The answer is <strong>somewhere close</strong>! Just look a little harder.</p></blockquote>
<p>Notice that in this case answer is: <strong>somewhere close</strong> <img src='http://www.axino.net/wordpress/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  they were playing some trick on us.<strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.axino.net/tutorial/2009/12/hackthissite-org-extbasic-2-extension-blocking" rel="bookmark" title="Friday 25.12.2009">hackthissite.org extbasic 2 :: Extension blocking</a></li>
<li><a href="http://www.axino.net/tutorial/2009/11/basic-web-hacking-12-include-me-in" rel="bookmark" title="Saturday 21.11.2009">Basic web hacking 12 :: include me in</a></li>
<li><a href="http://www.axino.net/tutorial/2009/07/hackthissite-org-basic-9-tricky-easy-not" rel="bookmark" title="Sunday 05.07.2009">hackthissite.org basic 9 :: tricky easy not</a></li>
<li><a href="http://www.axino.net/tutorial/2009/03/hackthissiteorg-basic-3-passwordphp" rel="bookmark" title="Thursday 12.03.2009">hackthissite.org basic 3 :: password.php</a></li>
<li><a href="http://www.axino.net/hack/hack-this-site/2009/12/hackthissite-org-solutions-to-all-basic-missions" rel="bookmark" title="Monday 21.12.2009">hackthissite.org solutions to all basic missions</a></li>
</ul>
<p><!-- Similar Posts took 5.846 ms --></p>
 <img src="http://www.axino.net/wordpress/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=697" width="1" height="1" style="display: none;" />]]></content:encoded>
			<wfw:commentRss>http://www.axino.net/tutorial/2009/12/hackthissite-org-basic-11-music-collection/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>hackthissite.org basic 10 :: My cookie your cookie</title>
		<link>http://www.axino.net/hack/hack-this-site/2009/09/hackthissite-org-basic-10-my-cookie-your-cookie</link>
		<comments>http://www.axino.net/hack/hack-this-site/2009/09/hackthissite-org-basic-10-my-cookie-your-cookie#comments</comments>
		<pubDate>Fri, 25 Sep 2009 20:59:28 +0000</pubDate>
		<dc:creator>Arxleol</dc:creator>
				<category><![CDATA[hackthissite.org]]></category>
		<category><![CDATA[cookies]]></category>
		<category><![CDATA[hackthissite]]></category>
		<category><![CDATA[how to]]></category>
		<category><![CDATA[solution]]></category>
		<category><![CDATA[tutorial]]></category>

		<guid isPermaLink="false">http://www.axino.net/?p=469</guid>
		<description><![CDATA[OK this one might be hard to get. But in the end it is really simple, the biggest problem is how to figure out what should you use. If you tried several things from previous hackthissite.org missions you probably figured that nothing will work here. So you came here to find new approach. And here [...]]]></description>
			<content:encoded><![CDATA[<p>OK this one might be hard to get. But in the end it is really simple, the biggest problem is how to figure out what should you use.</p>
<p><span id="more-469"></span>If you tried several things from previous hackthissite.org missions you probably figured that nothing will work here. So you came here to find new approach. And here it is! If you haven&#8217;t figured out from the very name of this mission what you should do is use cookies.</p>
<p><a href="http://en.wikipedia.org/wiki/HTTP_cookie" target="_blank">Cookies</a> are small  chunks of data saved on your computer by remote server you are accessing. You can read more on provided web site.</p>
<p>Also I suggest using following tools to complete this mission.</p>
<p>First one is <a href="http://getfirebug.com/" target="_blank">Firebug</a>, highly usable development tool for firefox. Second one is <a href="http://www.softwareishard.com/blog/firecookie/" target="_blank">Firecookie </a>this one is extension on Firefox extension. So you&#8217;ll have to install both plugins.</p>
<p>Now when you are ready open firebug tab named cookies and refresh page of 10th mission. When you&#8217;ve done that search for cookie named: <strong>level10_authorized</strong> when you find this cookie you may notice that value it contains is <strong>No</strong>, so just double click on cookie name and change value to <strong>Yes</strong> and continue with any password.</p>
<p>You should be now authorized <img src='http://www.axino.net/wordpress/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> <strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.axino.net/tutorial/2010/06/javascript-challenge-13-cookie" rel="bookmark" title="Wednesday 09.06.2010">JavaScript Challenge 13 :: Cookie</a></li>
<li><a href="http://www.axino.net/tutorial/2009/11/basic-web-hacking-7-double-login" rel="bookmark" title="Tuesday 10.11.2009">Basic web hacking 7 :: double login</a></li>
<li><a href="http://www.axino.net/tutorial/2010/01/basic-web-hacking-13-forgotten-george" rel="bookmark" title="Friday 08.01.2010">Basic Web Hacking 13 :: Forgotten George</a></li>
<li><a href="http://www.axino.net/tutorial/2010/05/javascript-missions-7-js-obfuscation-ftw" rel="bookmark" title="Saturday 22.05.2010">Javascript Missions 7 :: JS Obfuscation. FTW!</a></li>
<li><a href="http://www.axino.net/tutorial/2009/06/hackthissiteorg-basic-5-email-to-admin-ii" rel="bookmark" title="Thursday 25.06.2009">hackthissite.org basic 5 :: email to admin II</a></li>
</ul>
<p><!-- Similar Posts took 7.572 ms --></p>
 <img src="http://www.axino.net/wordpress/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=469" width="1" height="1" style="display: none;" />]]></content:encoded>
			<wfw:commentRss>http://www.axino.net/hack/hack-this-site/2009/09/hackthissite-org-basic-10-my-cookie-your-cookie/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
