Questions and Answers

How do I collect points?

  • +5
    Chosen as best answer
  • +1
    Posted answer
  • +1
    Posted question
  • +1
    Thumb up
  • -1
    Thumb down
1

by gaussian in Challenge Help about October 5 open - report

Realistic 1 help

I cannot find the password file. I can access the login page using the info from nmap.  I read up on directory traversal but I am stuck now. I try to traverse to /../../etc/passwd but the site says psychomarine made php include() coding flaw. After this I tried to find clues by view page source but I am not finding anything. any help would be appreciated.

 

 

 

 

Thanks.

Answers: 2 • Score 0 • Views: 194
Browse by
  • 9

    by MRNCT about October 27

    You guys are on the right track. Just keep trying, maybe use some filter evasion or stuff similar to that.

    • Score: 0
  • 2

    by Keeper about October 6

    I'm in the same spot as you, i am using dirb to try and bust open all the directories and see what's hidden. Will let you know how it comes along. I haven't been back to the site in a while and there have been others that have asked this question, I thought i would chime in here because we are in the same boat.

    • Score: 0
You must login to post an answer.