please explain

9 years ago | edited 9 years ago


What is this “undeundetectedtected”. I have no idea of it.. can any one please explain.

9 years ago


It’s a very rare and valuable thing called a “hint”…

9 years ago


Very big hint at that. Think undeundetectedtected

9 years ago


Just think about the code for a minute and apply the concepts of VPN, even though VPN’s have nothing to do with it just imagine what you do when you “encapsulate” a code instead of IP traffic. At least that’s how I understood it. COcodeDE. I really hope that helped.

9 years ago | edited 9 years ago


I think I could also use a little bit of an explanation of the undetected hint. Among the various ways I tried that “worked” but didn’t count, I thought I was following that hint with this:

<SCR<script>IPT> <script>alert('HackThis!!');</script> </SCR</script>IPT>

Margus [modulo-]
9 years ago


Hi there.

@Kp00n7a I think this would fall under the classification of a spoiler :)
You are on the right track but reread the task: “execute exactly this code”
In this case “exactly” also applies to the case of the code. So see what parts get stripped away and what you are left with.

9 years ago


Sorry about that, I have hidden the spoiler. I thought it was filtering out <> and / but using a case-insensitive attack displays the prompt. So does that mean its filtering the string “script”? Ah hell, I’m not really sure what I’m looking for. I feel like a mosquito, looking for the sun but crashing into light bulbs instead.

Margus [modulo-]
9 years ago


Just keep trying and take it slow and steady. Patience really is a virtue with many of these.

If you think it is the string “script” then try to submit that and see how it is handled.
Trial and error will get you some way in understanding ho the sanitation works.

9 years ago


I think I see that it’s filtering >> < > and / … not “script” in the jquery script but I' not really grasping how to manipulate that script. I thought I’d manipulate the cookie utilizing tamper data but when I open it I don’t see the opportunity.

Margus [modulo-]
9 years ago


First of all, which cookie? Are you sure you fully see the difference between different types of parameters in a request and cookies? Or was it just a typo?

You do not need to do anything more than enter the correct kind of data into the form.

Does the script filter simply <> or does it take more than that to trigger it?

Try different inputs and see what gets stripped away and how.

Then think how you could have the input different so that the script would think it has done its job well

9 years ago


Yow, I can’t believe how much I was overthinking that. Or how close I actually was with the try in my first post. I got it through trial and error; I’ll admit I still don’t know exactly how the solution worked.

Margus [modulo-]
9 years ago


I’d rather not go into much more detail here, but check out the solutions section and there is likely some good explanation there. Or PM me.

You must be logged in to reply to this discussion. Login
1 of 12

This site only uses cookies that are essential for the functionality of this website. Cookies are not used for tracking or marketing purposes.

By using our site, you acknowledge that you have read and understand our Privacy Policy, and Terms of Service.
