Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 47 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Test your Hacking Skills
EH-Net
May 21, 2013, 10:35:34 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Test your Hacking Skills
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Test your Hacking Skills (Read 16568 times)
0 Members and 1 Guest are viewing this topic.
Manu Zacharia (-M-)
Sr. Member
Offline
Posts: 393
c0c0n Hacking Conference - where hackers unite
Test your Hacking Skills
«
on:
August 14, 2006, 12:52:53 AM »
Hi All,
Test your ethical hacking stills at NGSEC's games
Link:
http://quiz.ngsec.com/.
NGSEC's games are a set of security quizes useful for anyone interested in security or hacking.
At the games you'll be presented a set of challenges you'll have to solve in order to gain access to each following stage.
Enjoy the game.
Regards and best wishes
Morpheus
Logged
Manu Zacharia
MVP (Enterprise Security), ISLA-2010 (ISC)˛, C|EH, C|HFI, CCNA, MCP,
Certified ISO 27001:2005 Lead Auditor
There are 3 roads to spoil; women, gambling & hacking. The most pleasant with women, the quickest with gambling, but the surest is hacking - c0c0n
jimbob
Guest
Re: Test your Hacking Skills
«
Reply #1 on:
August 16, 2006, 04:08:09 AM »
Thanks Morpheus, that was pretty fun
There are also some challenging wargames at pulltheplug.org.
http://www.pulltheplug.org/wargames/index.html
Regards,
Jim
Logged
LSOChris
Guest
Re: Test your Hacking Skills
«
Reply #2 on:
August 19, 2006, 01:50:39 PM »
how is everyone doing on the web app 1 challenge?
Logged
jimbob
Guest
Re: Test your Hacking Skills
«
Reply #3 on:
August 19, 2006, 05:35:41 PM »
Quote from: LSOChris on August 19, 2006, 01:50:39 PM
how is everyone doing on the web app 1 challenge?
It was fairly easy, but that's not to say I didn't learn anything along the way. The levels do not necessarily get harder as they go up, it really depends on your current knowledge and experience.
Jim
Logged
Kai
Newbie
Offline
Posts: 4
Re: Test your Hacking Skills
«
Reply #4 on:
August 30, 2006, 12:05:02 PM »
Hey, Anyone passed level2. I have some problems with my telnet. When I telnet to server, I can't see anything. (Sorry about noob question, I am a newbie
Logged
LSOChris
Guest
Re: Test your Hacking Skills
«
Reply #5 on:
August 30, 2006, 11:53:39 PM »
which game?
Logged
Kai
Newbie
Offline
Posts: 4
Re: Test your Hacking Skills
«
Reply #6 on:
August 31, 2006, 06:19:17 AM »
level 2- game1.
Logged
jimbob
Guest
Re: Test your Hacking Skills
«
Reply #7 on:
August 31, 2006, 06:47:25 AM »
I've completed level 10, so I can't get to level 2. If you post the URL I'll take another look and help out. I will stop short of giving you the answer though.
Check out the tip on each page, this often gives a vital clue.
Jim
Logged
LSOChris
Guest
Re: Test your Hacking Skills
«
Reply #8 on:
September 03, 2006, 02:49:27 PM »
what did you use to disassemble the binary in level10?
Logged
jimbob
Guest
Re: Test your Hacking Skills
«
Reply #9 on:
September 05, 2006, 05:56:08 AM »
Quote from: LSOChris on September 03, 2006, 02:49:27 PM
what did you use to disassemble the binary in level10?
The binary is encrypted. You'll need to find a way to decrypt it before you can do your analysis.
Jim
Logged
LSOChris
Guest
Re: Test your Hacking Skills
«
Reply #10 on:
September 05, 2006, 02:50:48 PM »
yeah i know that, what tool did you use to unencrypt it...
there used to be a TESO tool to do it and it seems to be encrypted with it, i did a quick search and didnt come up with the tool, but if there is a newer better tool out there i would be willing to give that a try.
Logged
mn_kthompson
Jr. Member
Offline
Posts: 58
Re: Test your Hacking Skills
«
Reply #11 on:
September 21, 2006, 08:31:50 AM »
I just started them yesterday, and I'm having some difficulty with level 5 of game 1. This is the first SQL injection challenge in the game. I've looked over the psuedo code and injected the SQL that I believe would cause rows to come back, but I keep getting an error on the next page. Unfortunately the error is rather generic and could mean a whole host of things. I think I'm close to solving this, but I just need a push in the right direction. Can anyone lend some assistance?
Logged
LSOChris
Guest
Re: Test your Hacking Skills
«
Reply #12 on:
September 21, 2006, 01:58:22 PM »
http://www.carnal0wnage.com/papers/LSO-NGSEC-WebApplication-Security-Game1-answers.pdf
Logged
mn_kthompson
Jr. Member
Offline
Posts: 58
Re: Test your Hacking Skills
«
Reply #13 on:
September 21, 2006, 04:07:30 PM »
Wow, Chris, thanks for the push. I still dont really understand the answer though. If you have a moment could you explain this to me?
I was trying to send the following to the server as the username:
' or 1=1; --
I thought that would have given me a final query of
SELECT * FROM $table WHERE user='' or 1=1; --' AND pass='$password'
which should have returned the first username in the table. Why wasn't that working? Was it something I was doing wrong? Did the injected code have to be in the password field or should it also work in the username field?
Also, in the answer key you sent it appears that the solution is to basically do what I was doing, but replace every space with a quote in the password field, which would result in the following query, if I'm not mistaken
SELECT * FROM $table WHERE user='admin' AND pass='bla'or'1=1--'
or
SELECT * FROM $table WHERE user='admin' AND pass='bla'or'a'='a
Why would we want to put quotes around 1=1--? And what's up with the second one? MySQL would throw a fit if I sent that to it.
Thanks for any additional help you can provide.
Logged
pcsneaker
Jr. Member
Offline
Posts: 73
Re: Test your Hacking Skills
«
Reply #14 on:
September 22, 2006, 12:27:46 AM »
Quote
I was trying to send the following to the server as the username:
' or 1=1; --
That query works, but you have to add a space after the double dash to get it working.
Quote from: mysql reference:
In MySQL, the ‘-- ’ (double-dash) comment style requires the second dash to be followed by at least one whitespace or control character (such as a space, tab, newline, and so on)
Logged
MCSA:Security (W2k, W2k3)
MCSE:Security (W2k, W2k3)
CPTS, Network+
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Programming
: Finished Python Course in Codecademy now what?
(12) by
3xban
Network Pen Testing
: AIX Vulnerability Assessments
(1) by
3xban
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.