Realist

Tuesday 21 April 2020, 17:30  #1
Realist - Marabout Online
jam
jam
  • 99 posts

Hi all,

Either it is luck or i am a bad boy, i tried a few things maybe more. First, i have seen the source code and beautified with software and recognized there is a database, which i can obviously dream off, because it has been rechecked by a letter. I tried to bypass that by path truncation but it is not vulnerable. Good..
I tried XSS - stealing some cookies, but the admin seems to be dead and it will not work anyway, just for fun.. But the alert was just good one but further nearly no hope.
I tried SQL - Injection. Does not seem to work. Sqlite is good database, i like it.
Then, i have seen there is hash encryption. And yes, i have remembered the l**** comparison. It would work, if could hit the right beginnings of this token and really i tried till i noticed the time and gave up. The second thing is to update the admin’s token. I began thinking ;new game and new luck. I really used the force.. But still no answer.

Is there any hint i could have missed.
I am really good guy and i love here.
Thx for reading.

Tuesday 21 April 2020, 22:50  #2
Realist - Marabout Online
ElTouco72
  • 283 posts

hi,

You advanced well.

Maybe you should connect to irc and ask to talk with someone
then you could discuss in private without risking to spoil

Wednesday 22 April 2020, 23:30  #3
Realist - Marabout Online
jam
jam
  • 99 posts

This one was not easy, but it was good. I got it. Try harder. The timing is important.
Thx for challenge,

Wednesday 22 April 2020, 23:33  #4
[CLOSED] Realist - Marabout Online
Th1b4ud
  • 1636 posts

Great. Congratz !