Page 1 of 3 123 LastLast
Results 1 to 10 of 26

Thread: HaXx.Me #01 - Web Application Security

  1. #1
    MaXe's Avatar
    MaXe is offline Founder of InterN0T
    Join Date
    Jun 2008
    Location
    Denmark
    Posts
    4,140
    Blog Entries
    41
    Reputation
    270
    Rep Power
    10

    HaXx.Me #01 - Web Application Security

    Dear members of InterN0T,


    As previously announced (http://forum.intern0t.net/intern0t-n...rity-team.html) we're setting
    up a Web Application Security challenge for all of those out there who are interested
    in trying out their hacker skills on a real live (and legal) target.

    The target will be announced here in this thread, on twitter and IRC, while the complete
    objectives will only be released here. There are a few rules (common sense) which has
    to be followed as well, these are mentioned below.

    Winners
    Users: ande & IFailStuff
    Site: EvilZone

    Documentation

    ande & IFailStuff:
    http://evilzone.org/intern0t/intern0t.txt
    http://evilzone.org/intern0t/2010-08...atermarked.png
    http://evilzone.org/intern0t/2010-08...atermarked.png
    http://evilzone.org/intern0t/2010-08...atermarked.png
    http://evilzone.org/intern0t/2010-08...atermarked.png
    http://evilzone.org/intern0t/2010-08...atermarked.png
    http://evilzone.org/intern0t/2010-08...atermarked.png

    InterN0T:
    http://intern0t.blip.tv/file/4033285/


    Rules
    - It is forbidden to intentionally cause DoS conditions.
    - It is strictly forbidden to try and break out of the Xen instance.
    - Attacking other servers on the same host or network is strictly forbidden.
    - You may only attack the IP and domain announced here.
    - Avoid altering the target to deny other contest participants.
    - You may attack any service hosted on the target, but avoid SSH.
    - You may use any tool necessary to hack the target as long as you don't break the rules above.


    Hints
    - Do not waste your time trying to bruteforce passwords.
    - Check out twitter from time to time, hints may be revealed occasionally.
    - Read blogs and threads on InterN0T about Web Application Security.


    Contact
    - In case the server is down, contact Hestas or Rorok and inform them about this.
    - I will be available on #intern0t at irc.darkscience.ws most of the day. (I may be afk too though.)


    Timeline
    The challenge starts some time at Saturday the 31st July 2010 (GMT+1).
    The challenge ends around the 7th of August 2010 (GMT+1). If enough sub-
    missions has been received then the challenge may end before.


    Submissions
    In order for us to see how you managed to "crack" the server, we'd like you
    to provide some brief documentation. The layout overall doesn't matter but
    One could look at the HSIYF documentation others made, to get an idea how
    such a thing could look like.


    Challenge
    The target server will be restored from a backup each ~24 hours.
    Topics such as: File-types, data encoding and decoding, linux and more will be included.


    HaXx.Me #01 Target
    Target: [THE CONTEST HAS ENDED]

    Objectives:

    • Find and gain access to "The Administration" section.
    (This is only viewable by Administrators and no-one else.)
    • Find the hidden thread which contains an "answer code".
    • Optional: Write documentation on how you hacked the server!


    Don't forget to have fun while you're doing this!

    If you fail, don't believe you're not good enough. Try Harder as the people
    from Offensive Security tend to say, or simply give up and wait for the full
    documentation which may include a video from InterN0T.



    Best regards,
    MaXe


  2. #2
    Join Date
    Aug 2009
    Posts
    66
    Reputation
    53
    Rep Power
    6

    Re: HaXx.Me #01 - Web Application Security

    Can't wait to get started!
    A Friends photography: http://www.flickr.com/shandirenae
    Xires: Windows has become an OS produced by Microsoft, built by PlaySkool and themed by Crayola

  3. #3
    Join Date
    May 2010
    Location
    In Singapore Baby!
    Posts
    213
    Reputation
    56
    Rep Power
    5

    Re: HaXx.Me #01 - Web Application Security

    When you say advanced, what do you mean by that? Just out of interest; I was thinking of attempting this but now I think it may be a bit beyond my current level.

  4. #4
    Join Date
    Aug 2009
    Posts
    66
    Reputation
    53
    Rep Power
    6

    Re: HaXx.Me #01 - Web Application Security

    Quote Originally Posted by tekwizz123 View Post
    When you say advanced, what do you mean by that? Just out of interest; I was thinking of attempting this but now I think it may be a bit beyond my current level.
    It won't hurt to try!
    Think of it as a learning experience.
    A Friends photography: http://www.flickr.com/shandirenae
    Xires: Windows has become an OS produced by Microsoft, built by PlaySkool and themed by Crayola

  5. #5
    MaXe's Avatar
    MaXe is offline Founder of InterN0T
    Join Date
    Jun 2008
    Location
    Denmark
    Posts
    4,140
    Blog Entries
    41
    Reputation
    270
    Rep Power
    10

    Re: HaXx.Me #01 - Web Application Security

    Updated with the target! Good luck to anyone!


  6. #6
    Join Date
    Jan 2010
    Location
    @buffer
    Posts
    177
    Reputation
    76
    Rep Power
    5

    Re: HaXx.Me #01 - Web Application Security

    Timeline
    The challenge starts some time at Saturday the 31st July 2010 (GMT+1).
    The challenge ends around the 7th of July 2010 (GMT+1). If enough sub-
    missions has been received then the challenge may end before.
    is that date correct i guess it august?
    Never make any mistaeks


  7. #7
    Join Date
    Aug 2009
    Posts
    66
    Reputation
    53
    Rep Power
    6

    Re: HaXx.Me #01 - Web Application Security

    Quote Originally Posted by LeXeL View Post
    is that date correct i guess it august?
    hehe good eye.
    A Friends photography: http://www.flickr.com/shandirenae
    Xires: Windows has become an OS produced by Microsoft, built by PlaySkool and themed by Crayola

  8. #8
    MaXe's Avatar
    MaXe is offline Founder of InterN0T
    Join Date
    Jun 2008
    Location
    Denmark
    Posts
    4,140
    Blog Entries
    41
    Reputation
    270
    Rep Power
    10

    Re: HaXx.Me #01 - Web Application Security

    Thanks for the note LeXeL, will update the thread now.


  9. #9
    Join Date
    Jun 2009
    Location
    Canada Eh
    Posts
    87
    Reputation
    93
    Rep Power
    7

    Re: HaXx.Me #01 - Web Application Security

    Quote Originally Posted by MaXe View Post
    Thanks for the note LeXeL, will update the thread now.
    I have essentially defeated it maxe, though I wont disclose any of mah information ;D
    Quote Originally Posted by System
    HitThemLow knows what he says, but as you can tell he is not the best at putting it in a manner that... Everyone appreciates. lol

  10. #10
    MaXe's Avatar
    MaXe is offline Founder of InterN0T
    Join Date
    Jun 2008
    Location
    Denmark
    Posts
    4,140
    Blog Entries
    41
    Reputation
    270
    Rep Power
    10

    Re: HaXx.Me #01 - Web Application Security

    Hmm, I haven't seen any proof yet though. I'd like to see some


Page 1 of 3 123 LastLast

Similar Threads

  1. HaXx.Me #03 - Web App Sec for Pro's
    By MaXe in forum InterN0T Contests
    Replies: 4
    Last Post: 26th October 2010, 16:04
  2. HaXx.Me #02 - Web Application Security, Again!
    By MaXe in forum InterN0T Contests
    Replies: 51
    Last Post: 30th September 2010, 14:25
  3. Introducing "Netsparke"r, Web Application Security Scanner
    By LeXeL in forum Hacking Tools & Utilities
    Replies: 0
    Last Post: 3rd May 2010, 20:04
  4. Skipfish - Web Application Security Scanner
    By MaXe in forum Hacking Tools & Utilities
    Replies: 1
    Last Post: 22nd March 2010, 10:08
  5. N-Stalker ~ Web Application Security Scanner
    By MaXe in forum Hacking Tools & Utilities
    Replies: 0
    Last Post: 28th July 2008, 23:01

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
EvilZone py1337 SoldierX.com TheXero Get-Root HackTalk
PenTest Magazine

HatForce