Hey,
I solved this level but I have no idea how the scripts work. Why is the sourcecode from admin.php only the html form and not more? Why is the file in
http://www.hackthis.co.uk/levels/real/level6/admin.php
and in
http://www.hackthis.co.uk/levels/real/admin.php.
Could someone please explain the function of the princess/admin site? How works this script and what does it do to check the password and why could I see the sourcecode if I load the file in the correct way but not if I just klick on “view sourcecode”?.
Best regards,
Mojito
Hi Mojito,
I’m still trying to solve this level. I found the admin.php asking for the password only under /levels/real/level6/, the other ones
http://www.hackthis.co.uk/levels/real/admin.php and
http://www.hackthis.co.uk/levels/real/level6/pages/admin.php
are just copies of the levels index overview page http://www.hackthis.co.uk/levels/
I tried another way, and gave the princess home page navigator different input, like
http://www.hackthis.co.uk/levels/real/level6/?p=admin
This shows an interesting error message:
“Warning: file_get_contents(admin.html) [function.file-get-contents]: failed to open stream: No such file or directory in pages on line 22”
Are you sure you found the pw by looking at the source code of admin.php?
I could really use a little hint here..
Regards, Matrox
I’d like to know how you solved the level too… it seems to me that you don’t really understand how it works, but still managed to pass it. Did you watch a video about it?
- daMage
Ah - seems I was on the right track there. I didn’t know how to point the p= to the right file. Googled it, found a video.
But I still cannot retrieve the admin.php source.. The ../ part doesn’t work.
“Warning: file_get_contents(../admin.php) [function.file-get-contents]: failed to open stream: No such file or directory in pages on line 22 ”
Regards, Matrox
when the time has come , I shall rise and conquer the world
when the time has come , I shall rise and conquer the world
14 Year Old WhiT3 HaT HAcK3R LoV3 LiF3!!
if you read the rest of this thread, it answers it as well as can be answered without breaking forum rules…
read, think, analyse, learn, apply.
Some mornings it’s not worth chewing through the straps.