Forum
![]() | |
W3-BoT![]() 564 Messages GeekÔ$ |
the 13/12/2009 at 17h51![]() Post here for any help request on challenge Vip Web Army (in ENGLISH only !) #w3challs'Big Boss |
sisyang 11 Messages New Poster |
the 01/10/2014 at 16h44![]() hi admin. iam not familiar with french lang. sorry. in vip web army chall, i got the members id and password with *censored*. and successfully logged. and at 2nd step, the htaccess maybe needed, so i coded with *censored*. but no content is noted in the /home/VipWebArmy/www/.htaccess. with my friends help, in the file, path of the *censored* is there. but nothing. ![]() u understand my PM? thanks regards. Edit awe: I had to censor a few things to avoid spoil as this is the help forums, not afterwards ![]() « Last edition: the 01/10/2014 at 17h02 by awe » |
awe![]() 327 Messages Geek |
the 01/10/2014 at 17h07![]() Hey, so the problem is that your fullpath is wrong. There are a few ways to get it, the intended ones are from leaks that you can cause within the application. But you can still cheat a bit and look at /etc/passwd from another chall ![]() You can't open /etc/passwd from the vulnerability used in the second part, because of a hardening option, as warned in the challenge statement. My name? I've had a few. You can call me root. |
sisyang 11 Messages New Poster |
the 01/10/2014 at 17h09![]() sorry for my mistake.. for expression of the my state in detail, some afterwards stuffs are in there. and may i ask the chall is good working now?? thanks. |
awe![]() 327 Messages Geek |
the 01/10/2014 at 17h17![]() It takes a while to exploit the whole thing so I didn't test it thoroughly, but I can confirm that it's still working. My name? I've had a few. You can call me root. |
sisyang 11 Messages New Poster |
the 01/10/2014 at 17h19![]() from another chall?. plz teach me the chall number or what the chall. ![]() thanks. |
sisyang 11 Messages New Poster |
the 01/10/2014 at 17h24![]() i got the 2nd id: passwd. i passed the chall. i saw the afterwards forum. in there, the file(my full path) mentioned previously by me is inserted in the several codingins in the forum. so the challs wound be modifed from that periods?? |
awe![]() 327 Messages Geek |
the 01/10/2014 at 17h30![]() It was indeed changed a few years ago, the latest posts are using the good path though. My name? I've had a few. You can call me root. |
sisyang 11 Messages New Poster |
the 01/10/2014 at 17h46![]() Recovering the contents of the variable *censored*, which suddenly, she contains the fullpath ![]() Edit awe: no spoil once again... and I'll stop to answer as you should know (you solved the challenge, right?) and everything else is already in the afterwards. |
sisyang 11 Messages New Poster |
the 01/10/2014 at 18h20![]() OMG, i am confused with private PM. this is Forum!!!. i passed the chall by friend's answer, not by myself. so i must leared the more deep correctly. if u r in convenience, i am so sorry. and if there is problem, deletion of this forum can be done. once more, so sorry. |
bartuc![]() 6 Messages New Poster |
the 13/10/2014 at 11h58![]() Hello there, I passed the first part then I stucked on the second part for so long. I feel like I ran out of options. I tried uploading a shell, bypassing the .htaccess, search for the known directories to get a *censored*... none of them seems to work. Any insights? Thanks. ![]() Edit: I see my message is censored. I did not think that I was spoiling something. However, a simply reply with that would be nice. « Last edition: the 14/10/2014 at 14h44 by bartuc » |
MarcoChips 1 Message New Poster |
the 29/11/2016 at 16h19![]() Hi guys, today the site began to show an error each time a login or message sending is attempted. Warning: mysql_connect(): Connection refused in /home/vipwebarmy/www/index.php on line 46 Can someone fix this? Thanks in advance. |
nautilus 1 Message New Poster |
the 29/11/2017 at 21h17![]() The page seems to be broken; any request done in the contact form returns a SQL query error:
error said:
EDIT (06/12/17): still broken EDIT (11/12/17): FIXED « Last edition: the 11/12/2017 at 13h44 by nautilus » |
edcrfv 1 Message New Poster |
the 11/09/2018 at 15h38![]()
sisyang said:
|