Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 48 guests and 3 members online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Hacking Contest by OffSec
EH-Net
May 22, 2013, 06:35:21 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Hacking Contest by OffSec
Pages:
1
...
3
4
[
5
]
6
Go Down
« previous
next »
Print
Author
Topic: Hacking Contest by OffSec (Read 36470 times)
0 Members and 1 Guest are viewing this topic.
pizza1337
Full Member
Offline
Posts: 156
Resource is Power.
Re: Hacking Contest by OffSec
«
Reply #60 on:
May 09, 2010, 12:02:34 AM »
I cant get past noob filter, i get access to WAF but i dont know what to do after that..
http://www.securityfocus.com/archive/1/508124/30/0/threaded
< i dont understand this..
Logged
Knowledge
Resource is Power.
Equix3n-
Sr. Member
Offline
Posts: 386
Re: Hacking Contest by OffSec
«
Reply #61 on:
May 09, 2010, 12:04:57 AM »
I too am not able to clear phase1. Contact Ketchup on IRC perhaps he might help you.
Logged
Equix3n-
Sr. Member
Offline
Posts: 386
Re: Hacking Contest by OffSec
«
Reply #62 on:
May 09, 2010, 04:35:36 AM »
Anyone else from EHNet pwned phase 1? I see Ketchup and xXxKrisxXx only.
I'm still not able to authenticate to the website.
Logged
j0rDy
Hero Member
Offline
Posts: 590
Re: Hacking Contest by OffSec
«
Reply #63 on:
May 09, 2010, 04:37:27 AM »
nice to see people are trying hard! just got back from holiday so i'm dying to see how people are doing. too bad phase 1 is slow for some people, but i guess it will be better after the "noob filter".
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
zeroflaw
Full Member
Offline
Posts: 208
Re: Hacking Contest by OffSec
«
Reply #64 on:
May 09, 2010, 04:40:25 AM »
I've tried for a bit last night. And now I'm gonna try again lol. Don't have much time for this, cause of exams going on.
I'm not sure if I should look for some server misconfiguration or bypass the login script
Logged
ZF
Equix3n-
Sr. Member
Offline
Posts: 386
Re: Hacking Contest by OffSec
«
Reply #65 on:
May 09, 2010, 04:48:23 AM »
@zeroflaw
My attempts too have been sporadic. I believe you've to firstly authenticate to the website and then exploit a vulnerability in the dotDefender WAF. I started password guessing 1/2 hr. ago. Don't know how much time will it take.
@j0rDy
I'm a noob. This contest is a proof of that.
«
Last Edit: May 09, 2010, 04:50:37 AM by Equix3n-
»
Logged
zeroflaw
Full Member
Offline
Posts: 208
Re: Hacking Contest by OffSec
«
Reply #66 on:
May 09, 2010, 06:36:24 AM »
Oh lol, didn't realise I was actually hitting the WAF
I just want to pwn the noob filter now
Logged
ZF
pizza1337
Full Member
Offline
Posts: 156
Resource is Power.
Re: Hacking Contest by OffSec
«
Reply #67 on:
May 09, 2010, 08:07:58 AM »
me too.
Logged
Knowledge
Resource is Power.
Ketchup
Hero Member
Offline
Posts: 1021
Re: Hacking Contest by OffSec
«
Reply #68 on:
May 09, 2010, 09:58:34 PM »
I officially got my butt kicked, big time, and I loved every minute of it. I thought it was a tough challenge, although I expected nothing less. I realized how weak my FU is and how much work I need on exploit development. If nothing else, this should motivate me.
There were a few EH.net members in IRC, trying to get through it. Hopefully everyone had a blast like I did.
P.S. Mark, I read your article (and the links your provided) on SEH Exploits about 10 times this weekend.
Logged
~~~~~~~~~~~~~~
Ketchup
pizza1337
Full Member
Offline
Posts: 156
Resource is Power.
Re: Hacking Contest by OffSec
«
Reply #69 on:
May 09, 2010, 10:18:59 PM »
Quote from: Ketchup on May 09, 2010, 09:58:34 PM
I officially got my butt kicked, big time, and I loved every minute of it. I thought it was a tough challenge, although I expected nothing less. I realized how weak my FU is and how much work I need on exploit development. If nothing else, this should motivate me.
There were a few EH.net members in IRC, trying to get through it. Hopefully everyone had a blast like I did.
P.S. Mark, I read your article (and the links your provided) on SEH Exploits about 10 times this weekend.
dude, you did good job.
I couldn't even get past phase 1, i figured out how to do it this morning, but it was too late.
I am not very good at web applications.
Logged
Knowledge
Resource is Power.
impelse
Hero Member
Offline
Posts: 565
Re: Hacking Contest by OffSec
«
Reply #70 on:
May 09, 2010, 11:10:57 PM »
Congrats Ketchup
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
Equix3n-
Sr. Member
Offline
Posts: 386
Re: Hacking Contest by OffSec
«
Reply #71 on:
May 09, 2010, 11:49:24 PM »
Nevertheless, good job ketchup! Did you even sleep? I checked that you were on IRC the whole time. Have some rest now. You deserve it
Logged
bamed
Newbie
Offline
Posts: 48
Re: Hacking Contest by OffSec
«
Reply #72 on:
May 10, 2010, 07:40:19 AM »
It was fun, but totally kicked my butt too. Never got past phase 1. I didn't get much time besides Saturday morning and a little while Saturday evening to spend on it, though I did spend all weekend thinking about it. Now I know I need to focus some study on exploiting web apps.
On another note, I managed to get through the Google Code Jam qualification round, so the weekend wasn't a total loss!
Logged
chown -R bamed ./base
MicroJay
Full Member
Offline
Posts: 101
Re: Hacking Contest by OffSec
«
Reply #73 on:
May 10, 2010, 10:14:30 AM »
I tried...Guess I did not "Try Harder"!
I looked at the source of the pages to try and pick something out. "HAHAHAHA!" kept bugging me.
I kept getting the 5 minute delay. :-(
I think I will be taking some courses this year when the time is right! ;-)
Congrats on getting by Level 1 Ketchup and xXxKrisxXx and anyone else I forgotten!
Logged
GSEC - GCIH - GSNA - GPEN
zeroflaw
Full Member
Offline
Posts: 208
Re: Hacking Contest by OffSec
«
Reply #74 on:
May 10, 2010, 10:50:34 AM »
Well the annoying thing was that I pretty much had the solution to phase 1 thanks to What90. Lag prevented me from getting a HTTP response from the exploit
There were a few slots left and I just didn't make it.
I learned something from this though. I was trying to bypass the filter by HTTP Parameter Pollution. So I was skipping through PDF's and PPT's trying to learn as much about it as quickly as I could. Also tried a bunch of other SQL Injection vectors. And in the end I was thinking far too difficult. Though the HPP techniques will come in handy in the future perhaps
Perhaps Ill see if I can install dotDefender and try the exploit in a lab environment
And I've heard there will be another contest like this in the future, so hopefully my Fu will be stronger by then
Logged
ZF
Pages:
1
...
3
4
[
5
]
6
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: This is meant to give professional landscapers Nike Blazer Uk
(0) by
Loyatoitada
ChicagoCon 2007
: Just as with A Better World Cheap Air Max Sale
(0) by
Loyatoitada
ChicagoCon 2007
: which along with its raise Louis Vuitton
(0) by
Loyatoitada
News Items and General Discussion About EH-Net
: Sunday Super Bowl Champion Brendon Ayanbadejo Nike Blazer Uk
(0) by
Loyatoitada
News Items and General Discussion About EH-Net
: It Louis Vuitton Pas Cher
(0) by
Loyatoitada
ChicagoCon 2007
: s go over the three places most inventory accumulates Nike Blazers Sale
(0) by
Loyatoitada
News Items and General Discussion About EH-Net
: Or you could try to partner with them or someone else Cheap Air Max Sale
(0) by
Loyatoitada
News from the Outside World
: Google Dropping Windows For Internal Use
(10) by
Loyatoitada
Special Events
: [Article]-Video: Deep Dive into Red Teaming with the Metasploit Framework
(4) by
BeecyGorror
Security
: christian louboutin cheap artic5843
(0) by
fufig388
Special Events
: [Article]-Survey of Hacking Movies: Framing the Debate on the Gateway Drug into the H...
(14) by
BeecyGorror
/root
: [Article]-Course Review: CPT by InfoSec Institute
(1) by
BeecyGorror
Ethical Hacktivism
: Paranoid parents messing with routers
(21) by
BeecyGorror
Compliance, Regulations & Standards
: SABSA - Sherwood Applied Business Security Architecture
(1) by
BeecyGorror
News Items and General Discussion About EH-Net
: What does EthicalHacker.net bring you?
(12) by
BeecyGorror
News Items and General Discussion About EH-Net
: Burberry UK,2013 Burberry Safety-valve Online Available in London
(13) by
BeecyGorror
News Items and General Discussion About EH-Net
: louis vuitton handbags mhf
(0) by
Vamscoora
Calendar Of Events
: ChicagoCon 2008f
(3) by
BeecyGorror
News Items and General Discussion About EH-Net
: "Free Monthly Giveaways" - Details
(22) by
BeecyGorror
ChicagoCon 2007
: s going to be critical to have universal identity in order for these systems to talk ...
(0) by
Loyatoitada
Malware
: New zero-day exploit for Internet Explorer 7, 8, and 9 on Windows XP, Vista & 7
(13) by
BeecyGorror
Special Events
: [Article]-Webcast: Deep Dive into Red Teaming with the Metasploit Framework
(19) by
BeecyGorror
News Items and General Discussion About EH-Net
: but it needs more help: they Sac Louis Vuitton
(0) by
Loyatoitada
Greetings
: but the desperate effort that comes from being hopeful Nike Blazers Uk
(0) by
Loyatoitada
ChicagoCon 2007
: waterfall Cheap Air Max Sale
(0) by
Loyatoitada
News Items and General Discussion About EH-Net
: The advent of the web happened slowly Nike Blazer Uk
(0) by
Loyatoitada
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.