Page 1 of 6 1234 ... LastLast
Results 1 to 10 of 52

Thread: HaXx.Me #02 - Web Application Security, Again!

  1. #1
    MaXe's Avatar
    MaXe is offline Founder of InterN0T
    Join Date
    Jun 2008
    Location
    Denmark
    Posts
    4,140
    Blog Entries
    41
    Reputation
    270
    Rep Power
    10

    HaXx.Me #02 - Web Application Security, Again!

    Dear members of InterN0T,


    The last HaXx.Me #01 challenge aka wargame went smoothly with a lot of
    trial and error, success and failure. Now it's time for the second challenge,
    featuring more Web Application Security in order to teach you what you may
    encounter in real life scenarios as a Penetration Tester!

    The target will be announced here in this thread, on twitter and IRC, while the complete
    objectives will only be released here. There are a few rules (common sense) which has
    to be followed as well, these are mentioned below.

    Winners
    1st Place: 0daydevilz!
    2nd Place: ande & IFailStuff!
    3rd Place: sh4ka!
    4th Place: bik3te
    5th Place: Norph

    Documentation
    InterN0T:
    [1] http://bit.ly/diSgY9 (password: www.intern0t.net )
    [2] http://intern0t.blip.tv/file/4108786/



    Rules
    - It is forbidden to intentionally cause DoS conditions.
    - It is strictly forbidden to try and break out of the Xen instance.
    - Attacking other servers on the same host or network is strictly forbidden.
    - You may only attack the IP and domain announced here.
    - Avoid altering the target to deny other contest participants.
    - You may attack any service hosted on the target.
    - You may use any tool necessary to hack the target as long as you don't break the rules above.


    Hints
    - Some passwords in this wargame, may be vulnerable to dictionary attacks.
    - Check out twitter from time to time, hints may be revealed occasionally.
    - Read blogs and threads on InterN0T about Web Application Security.


    Contact
    - In case the server is down, contact Hestas or Rorok and inform them about this.
    - You can also send a PM to me or use our Contact Us form.


    Timeline
    The challenge starts some time at the 1st September 2010 (GMT+1).
    The challenge ends around the 8th September 2010 (GMT+1).


    Submissions
    In order for us to see how you managed to "crack" the server, we'd like you
    to provide some brief documentation. The layout overall doesn't matter but
    One could look at the HSIYF documentation others made, to get an idea how
    such a thing could look like.


    Challenge
    The target server will be restored from a backup each ~24 hours.



    HaXx.Me #02 Target
    Target: [The Contest is Over!]

    Objectives:

    • Gain shell access to the server and find the winning key in the root directory.

    Don't forget to have fun while you're doing this!

    If you fail, don't believe you're not good enough. Try Harder as the people
    from Offensive Security tend to say, or simply give up and wait for the full
    documentation which may include a video from InterN0T, again!



    Best regards,
    MaXe


  2. #2
    Join Date
    Jan 2010
    Location
    @buffer
    Posts
    177
    Reputation
    76
    Rep Power
    5

    Re: HaXx.Me #02 - Web Application Security, Again!

    the time have come i will not sleep to finish this one ;D
    Never make any mistaeks


  3. #3
    Join Date
    Mar 2010
    Posts
    16
    Reputation
    1
    Rep Power
    5

    Re: HaXx.Me #02 - Web Application Security, Again!

    I want to participate too. :D
    I hope i win !

  4. #4
    MaXe's Avatar
    MaXe is offline Founder of InterN0T
    Join Date
    Jun 2008
    Location
    Denmark
    Posts
    4,140
    Blog Entries
    41
    Reputation
    270
    Rep Power
    10

    Re: HaXx.Me #02 - Web Application Security, Again!

    The challenge has begun! Good luck to all of you!


  5. #5
    Join Date
    Jul 2010
    Posts
    18
    Reputation
    11
    Rep Power
    4

    Re: HaXx.Me #02 - Web Application Security, Again!

    We'll see what i can do, I am doing this for fun and fun only...some education too :P


  6. #6
    MaXe's Avatar
    MaXe is offline Founder of InterN0T
    Join Date
    Jun 2008
    Location
    Denmark
    Posts
    4,140
    Blog Entries
    41
    Reputation
    270
    Rep Power
    10

    Re: HaXx.Me #02 - Web Application Security, Again!

    Good luck l0cus! I look forward to see how everyone does

    Can't wait to see someone pwn it and tell me how they did it


  7. #7
    TheXero's Avatar
    TheXero is offline Try Harder!
    Join Date
    Sep 2008
    Location
    0x42424242
    Posts
    896
    Reputation
    291
    Rep Power
    10

    Re: HaXx.Me #02 - Web Application Security, Again!

    When you say get shell access, do you mean break into the server, or the web application?

  8. #8
    MaXe's Avatar
    MaXe is offline Founder of InterN0T
    Join Date
    Jun 2008
    Location
    Denmark
    Posts
    4,140
    Blog Entries
    41
    Reputation
    270
    Rep Power
    10

    Re: HaXx.Me #02 - Web Application Security, Again!

    Quote Originally Posted by TheXero View Post
    When you say get shell access, do you mean break into the server, or the web application?
    I mean break into the server by any means possible and go to the /root
    directory and find the winning key ;-) (A file with instructions)

    That's basically it


  9. #9
    TheXero's Avatar
    TheXero is offline Try Harder!
    Join Date
    Sep 2008
    Location
    0x42424242
    Posts
    896
    Reputation
    291
    Rep Power
    10

    Re: HaXx.Me #02 - Web Application Security, Again!

    Now I've got my Internet on my desktop again, I'll have a go tonight :D

    Don't know how much I'll be able to get done though, I'm making videos :P

  10. #10
    Join Date
    Aug 2010
    Posts
    23
    Reputation
    24
    Rep Power
    4

    Re: HaXx.Me #02 - Web Application Security, Again!

    Can you do a tutorial on how you hacked number1. Then once youve finished can you show me how you did number 2
    I program in: php, Batch, javascript, html and sql
    I am learning php, javascript, html,sql, C/C++, VB, LOLcode and java

Page 1 of 6 1234 ... LastLast

Similar Threads

  1. HaXx.Me #03 - Web App Sec for Pro's
    By MaXe in forum InterN0T Contests
    Replies: 4
    Last Post: 26th October 2010, 16:04
  2. HaXx.Me #01 - Web Application Security
    By MaXe in forum InterN0T Contests
    Replies: 25
    Last Post: 31st August 2010, 10:00
  3. Introducing "Netsparke"r, Web Application Security Scanner
    By LeXeL in forum Hacking Tools & Utilities
    Replies: 0
    Last Post: 3rd May 2010, 20:04
  4. Skipfish - Web Application Security Scanner
    By MaXe in forum Hacking Tools & Utilities
    Replies: 1
    Last Post: 22nd March 2010, 10:08
  5. N-Stalker ~ Web Application Security Scanner
    By MaXe in forum Hacking Tools & Utilities
    Replies: 0
    Last Post: 28th July 2008, 23:01

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
EvilZone py1337 SoldierX.com TheXero Get-Root HackTalk
PenTest Magazine

HatForce