Realist

Friday 21 July 2017, 05:14  #1
Realist - The h@ckers l4b
jam
jam
  • 99 posts

Hello everyone,

i managed the directories with a brute force tool and found a file to gather the password of Web master. But this password was not enough to validate the challenge. So searched for cookies and saw there is something encrypted. In order to take over the session i need the following info : is there SHA1 hash and if , does it take a long time to get the result by brute forcing ?

Thx for reading and let me know more....

Monday 24 July 2017, 22:10  #2
Realist - The h@ckers l4b
jam
jam
  • 99 posts

hi,

after brute forcing the hash, i forgot the time and gave up. Either the hash is unknown or too salted. i supposed there could be more directories and files, which i dinna expect, especially the french ones.. so i gave a new chance and found no new ones.
the page property accepts all the files in /include directory but no deconnect (disconnect) with the ending php.
The problem is as i got the password for the administrateur, i could not log in cause he was already logged in. So decided to message with him but with no return. I wrote the link he should disconnect voluntarily. :)
So what i need to know, is there a special admin panel where i can log in and disconnect him, that would grant access to next level.
waiting for an answer eagerly,
thx.

Tuesday 25 July 2017, 20:54  #3
Realist - The h@ckers l4b
jam
jam
  • 99 posts

hi,

it was fairly easy to get that thing in order. I had to contact the right person for this issue.

thx,