So……. I have no idea how to do this level, Im sorta stuck.
It all seemed easy as I was reading the source code:
HomeNews
Contact
So… ?p=admin.php But what is the next step??
Apparently, its something called “Poison NULL byte”, and after reading this http://insecure.org/news/P55-07.txt and a few videos and actually trying to do what the video said for GODNESS SAKE (TO FIGURE OUT THE LEVEL) ———– — [removed] that still doesn’t work….
What is the next step??
Edit: your url was correct, so I removed it.
I hope Flabbyrabbit will have the time to have a look at this… You had the correct solution as far as I can tell..
- daMage
The level works now as intended. Sorry for the inconvenience.
Special thanks to Flabbyrabbit, who did the actual fixing ;)
- daMage
11 years ago
0
Just tried the level again myself and it works fine for me!
The level was flawed but this has now been fixed and appears to be functioning as expected. Also to reiterate @knarf169’s point Chrome seems to be more willing to accept null bytes than firefox. If you are using firefox and having issues try using something else.
as everyone mentioned i tried in chrome and still facing the same issue
Warning: file_get_contents(admin.php) [function.file-get-contents]: failed to open stream: No such file or directory in pages on line 22
i am trying Null Byte, no use
http://www.hackthis.co.uk/levels/real/level6/?p=admin.php%00
There are 10 types of people in the world: Those who understand binary, and those who don’t
abhi1302 you are trying to go to the wrong directory. Think again. If you got this far don’t you remember a file with a php.html
You need to change some of your http://www.hackthis.co.uk/88888/99999/00000/?p=admin.php%00 to something else. Can’t say much more without giving it all away!
IDLETESTER
11 years ago | edited 11 years ago
0
Idletester is right abhi1302. You are going to the wrong directory. Can you remember how to be able to go up or down a directory?
if you were in the cmd line in windows and were on lets say C:/windows/ and you wanted to go down a directory you would use .. so how could you use something like that to solve your directory problem you are having?? The poison null byte is to stop something from happening.
Thanks @IDLETESTER and @ANONRA you both are right this level is cleared now but by looking at page source admin.php seems to be in current location.
<a href="admin.php">here it is</a>
There are 10 types of people in the world: Those who understand binary, and those who don’t
You know since idletester is sooooooooo awesome you can
Go to youtube and look at his videos, kills the fun in every thing. But hey idletester is awesome!
“When you die I will laminate you’re skeleton and pose you in the lobby.”
Veni Vidi Vici
“When you die I will laminate you’re skeleton and pose you in the lobby.”
Veni Vidi Vici
Read this article ! Maybe it should help you :-)
http://www.hackthis.co.uk/articles/common-php-attacks-directory-traversal
i bake therefore im fried!!
@idletester Thank you! Your hint was what I needed to finish this. Sadly, I’ve seen one or two web sites where this has actually worked!
We keep what we kill
abhi1302 read the warning carefully:
Warning: file_get_contents(admin.php) [function.file-get-contents]: failed to open stream: No such file or directory in pages on line 22
Roses are red,
Violets are blue,
AES(level) is bad
And I might be too