Realist

Sunday 18 January 2015, 23:14  #1
Realist P0wn3d
Illi31
  • 1 posts

I´ve tryed the P0wn3d Challenge of the Realist Section now for a Couple of Days. I did a lot of research about the Simple CMS (Data Structur etc) and have tryed a lot of ways to solve the Problem.
I read the French Forum as well and know what type of "Attack" is used to solve the Challenge but i´m a little bit Stuck and tought that maybe someone can help me a bit.

As i said i think im Generaly on the right way but need a little help / hint.

Thanks

Monday 29 June 2015, 01:19  #2
Realist P0wn3d
Mister_Bert0ni
  • 9 posts

Hey guyz,I will hope then somebody give me some hint how use LFI in this task.I greatly understand that we need to include such files as ../cmsimple/adm.php or ../cmsimple/config.php,and we must use null byte.But I can’t understand how to use the LFI here? What delimiter are using to split the dirs? Maybe : ??
Plz give some hint

Monday 29 June 2015, 01:40  #3
Realist P0wn3d
myrti
  • 2 posts

Hi,

have you tried to look at the source code of cmsimple? You should be able to find it online and maybe it will give you an idea on how to proceed further.

regards
myrti

Monday 29 June 2015, 09:43  #4
Realist P0wn3d
Mister_Bert0ni
  • 9 posts

Yes, I download cmsimple 3.0 from official site and see cms structure and view source code,but I am not able to find where site use rule with replace "/" to ":" in include function.
Sorry bro,maybe I do something wrong?

Wednesday 17 January 2018, 22:36  #5
Realist P0wn3d
caseyvsilver
  • 4 posts

It took me a while to figure this one out but i can tell their that you need focus on the LFI paticulary ?sl=, if you look for CMS vuln search in google you will find a popular one that should help you.

Thursday 30 April 2020, 02:25  #6
Realist P0wn3d
Jiniasu
  • 1 posts

Hi all,

I need some help on this challenge. Can someone go in private message to give me some clue please ? :)
(I think i’ve taken the classic clue "check the source code", "find the CVE", etc... But it seems it’s not enough for me 😢 )

Thank you :)