Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 48 guests and 3 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Hacking Contest by OffSec
EH-Net
May 22, 2013, 06:35:21 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: 1 ... 3 4 [5] 6   Go Down
  Print  
Author Topic: Hacking Contest by OffSec  (Read 36470 times)
0 Members and 1 Guest are viewing this topic.
pizza1337
Full Member
***
Offline Offline

Posts: 156

Resource is Power.


View Profile
« Reply #60 on: May 09, 2010, 12:02:34 AM »

I cant get past noob filter, i get access to WAF but i dont know what to do after that..

http://www.securityfocus.com/archive/1/508124/30/0/threaded  < i dont understand this..
Logged

Knowledge Resource is Power.
Equix3n-
Sr. Member
****
Offline Offline

Posts: 386



View Profile
« Reply #61 on: May 09, 2010, 12:04:57 AM »

I too am not able to clear phase1. Contact Ketchup on IRC perhaps he might help you.
Logged
Equix3n-
Sr. Member
****
Offline Offline

Posts: 386



View Profile
« Reply #62 on: May 09, 2010, 04:35:36 AM »

Anyone else from EHNet pwned phase 1? I see Ketchup and xXxKrisxXx only.
I'm still not able to authenticate to the website.
Logged
j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #63 on: May 09, 2010, 04:37:27 AM »

nice to see people are trying hard! just got back from holiday so i'm dying to see how people are doing. too bad phase 1 is slow for some people, but i guess it will be better after the "noob filter".
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
zeroflaw
Full Member
***
Offline Offline

Posts: 208



View Profile
« Reply #64 on: May 09, 2010, 04:40:25 AM »

I've tried for a bit last night. And now I'm gonna try again lol. Don't have much time for this, cause of exams going on.

I'm not sure if I should look for some server misconfiguration or bypass the login script  Undecided
Logged

ZF
Equix3n-
Sr. Member
****
Offline Offline

Posts: 386



View Profile
« Reply #65 on: May 09, 2010, 04:48:23 AM »

@zeroflaw
My attempts too have been sporadic. I believe you've to firstly authenticate to the website and then exploit a vulnerability in the dotDefender WAF. I started password guessing 1/2 hr. ago. Don't know how much time will it take.

@j0rDy
I'm a noob. This contest is a proof of that.
« Last Edit: May 09, 2010, 04:50:37 AM by Equix3n- » Logged
zeroflaw
Full Member
***
Offline Offline

Posts: 208



View Profile
« Reply #66 on: May 09, 2010, 06:36:24 AM »

Oh lol, didn't realise I was actually hitting the WAF Embarrassed

I just want to pwn the noob filter now  Tongue
Logged

ZF
pizza1337
Full Member
***
Offline Offline

Posts: 156

Resource is Power.


View Profile
« Reply #67 on: May 09, 2010, 08:07:58 AM »

me too.
Logged

Knowledge Resource is Power.
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #68 on: May 09, 2010, 09:58:34 PM »

I officially got my butt kicked, big time, and I loved every minute of it.   I thought it was a tough challenge, although I expected nothing less.   I realized how weak my FU is and how much work I need on exploit development.  If nothing else, this should motivate me. 

There were a few EH.net members in IRC, trying to get through it.  Hopefully everyone had a blast like I did.

P.S.  Mark, I read your article (and the links your provided) on SEH Exploits about 10 times this weekend. Smiley 
Logged

~~~~~~~~~~~~~~
Ketchup
pizza1337
Full Member
***
Offline Offline

Posts: 156

Resource is Power.


View Profile
« Reply #69 on: May 09, 2010, 10:18:59 PM »

I officially got my butt kicked, big time, and I loved every minute of it.   I thought it was a tough challenge, although I expected nothing less.   I realized how weak my FU is and how much work I need on exploit development.  If nothing else, this should motivate me. 

There were a few EH.net members in IRC, trying to get through it.  Hopefully everyone had a blast like I did.

P.S.  Mark, I read your article (and the links your provided) on SEH Exploits about 10 times this weekend. Smiley 

dude, you did good job.
I couldn't even get past phase 1, i figured out how to do it this morning, but it was too late.
I am not very good at web applications.
Logged

Knowledge Resource is Power.
impelse
Hero Member
*****
Offline Offline

Posts: 565


View Profile WWW
« Reply #70 on: May 09, 2010, 11:10:57 PM »

Congrats Ketchup
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training

Website: http://blog.thehost1.com/
Equix3n-
Sr. Member
****
Offline Offline

Posts: 386



View Profile
« Reply #71 on: May 09, 2010, 11:49:24 PM »

Nevertheless, good job ketchup! Did you even sleep? I checked that you were on IRC the whole time. Have some rest now. You deserve it  Smiley
Logged
bamed
Newbie
*
Offline Offline

Posts: 48


View Profile WWW
« Reply #72 on: May 10, 2010, 07:40:19 AM »

It was fun, but totally kicked my butt too.  Never got past phase 1.  I didn't get much time besides Saturday morning and a little while Saturday evening to spend on it, though I did spend all weekend thinking about it.  Now I know I need to focus some study on exploiting web apps. 
On another note, I managed to get through the Google Code Jam qualification round, so the weekend wasn't a total loss!
Logged

chown -R bamed ./base
MicroJay
Full Member
***
Offline Offline

Posts: 101



View Profile
« Reply #73 on: May 10, 2010, 10:14:30 AM »

I tried...Guess I did not "Try Harder"! 
I looked at the source of the pages to try and pick something out.  "HAHAHAHA!" kept bugging me.
I kept getting the 5 minute delay.  :-(

I think I will be taking some courses this year when the time is right!  ;-)

Congrats on getting by Level 1 Ketchup and xXxKrisxXx and anyone else I forgotten!
Logged

GSEC - GCIH - GSNA - GPEN
zeroflaw
Full Member
***
Offline Offline

Posts: 208



View Profile
« Reply #74 on: May 10, 2010, 10:50:34 AM »

Well the annoying thing was that I pretty much had the solution to phase 1 thanks to What90. Lag prevented me from getting a HTTP response from the exploit  Undecided There were a few slots left and I just didn't make it.

I learned something from this though. I was trying to bypass the filter by HTTP Parameter Pollution. So I was skipping through PDF's and PPT's trying to learn as much about it as quickly as I could. Also tried a bunch of other SQL Injection vectors. And in the end I was thinking far too difficult. Though the HPP techniques will come in handy in the future perhaps Cool

Perhaps Ill see if I can install dotDefender and try the exploit in a lab environment Grin And I've heard there will be another contest like this in the future, so hopefully my Fu will be stronger by then Wink
Logged

ZF
Pages: 1 ... 3 4 [5] 6   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.075 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.