-
LVL 8 & SSI
I understand that I need to inject SSI statements, but do I need a PHP script to do it? I haven't spent any time with php for several years. If php is the way to go, then I will jump in with both feet. If not, then I'd rather not waste my time.
If you are still working on lvl 4 or 5, you might not want to read this post. I am wondering why I had to change the content-length string on lvl 5 and not on lvl 4? For some reason on lvl 5 I had to change the number to suit my email address. Was this another security measure?
-
I encoded this hint in Base64. Don't read this if you really enjoy figuring out things yerself because it comes close to a spoiler. you can decrypt it here:
http://www.antionline.com/tools-and-toys/encrypt-text/
It's about the SSI on level 8 (or what I think was level 8)
dGhlIHNpc3RlcnMgc2NyaXB0IG1ha2VzIGEgdGVtcCAuc2h0bWwgZmlsZSAobm90aWNlIHRoZSBzIGluIHNodG1sKSBhbmQgcHV0cyB5b3VyIG5hbWUgKHdpY2ggeW91IGVudGVyZWQgeW91cnNlbGYpIGluIGl0Li4uICAgc3NpID0+ICA9PiA6RA==
-
ùÑ¡”Í¥ÍÑ•ÉÌÍÉ¥Áе…*•̄ѕµÀ€¹Í¡Ñµ°™¥±”€¡¹½Ñ¥”Ñ¡”Ì¥¸Í¡Ñµ°¤…¹ÁÕÑÌå½Õȹ…µ”€¡Ý¥ å½Ô•¹Ñ•É•å½ÕÉÍ•±˜¤¥¸¥Ð¸¸¸€€Íͤ€ôø€
Nice hint! lmao
-
You sure you selected Base 64 Decode in that options list ? :p
-
hehehe I think someone that really needs the hint should try all the options just to make sure.
Or maybe a combination like ASCII to Binary then Base 64 Decode then Un-Pig Latin!
Welcome the the Hack neel's post challenge! ;)
-
neels base64 decoded fine for me!
-
I need help i cant get passed level 3 and 4 and i changed the html to <center>
<form action="http://www.hulla-balloo.com/hack/level4/level4.php" method="post">
<input type="hidden" name="to" value="[email protected]">
<input type="submit" value="Send password to Sam">
</form>
</center>
That was for level 4 but i didnt work.
Then i have no clue how to get passed level 3 at all.
Please Help Me!!!!!
-
This thread is five years old.
http://www.hulla-balloo.com
Will be your problem. My bet is that it is no longer hosted there....... 5 years is a long time in internet terms?
You need to find out where it is being hosted these days (if it still is) and substitute that address for the one above.