Viena hack chall lapele..

Vakar Anetix no #coders iemineejaas par vienu hack challenge lapeli. Kopaa ir 16 challenges un gandriiz visos izaicinaajumos [challenges] bija javascripti. Pie tam nesarezhgjiiti. :) Sadomaaju uzraxtiit, kaa tad es ar tiem tiku galaa. Ja negribi sabojaat sew urkjeeshanas/risinaashanas prieku taalaak nelasi.. ;p

Protams katram izaicinaajumam ir vairaaki veidi kaa iziet, es paraadiishu tikai vienu.


1. Challenge vnk apskatamies sourci un redzam

if (passwort=="easy") {

komentaaru naw..


2. Challenge atkal vnk luuram sourcee un redzam

var m1, i; m1="JavaScript"; value=prompt("Please enter password!",""); if (value==m1) { window.location=value+".htm"; i=4;

tik pat vienkaarshs kaa pirmais.. 'JavaScript' [ja kaads naw pamaniijis]


3. Challenge esam nonaakushi JavaScript.htm.. protams, kaa vienmeer luuram sourcee.. redzam..

window.location.href=String.fromCharCode(65,66,67)+".htm";

redzam, ka 65,66,67 ir Dec.. paarveidojot uz chr buus 'ABC'.. taatad ABC.htm


4. Challenge shis ir liidziigs ieprieksheejam, tikai shoreiz ir dots Hex nevis Dec..

var a=unescape("%43%4f%44%45%5a");

atkal jaarveidojot uz Chr ieguustam 'CODEZ'..


5. Challenge skatamies sourci un wtf.. ?

<!-- source code denied //-->

nju lab.. paseerchojam kaut vai peec burta 'a' un atrodam sourci ar js [javascriptu]

if(Eingabe != ((code.length)*100)/2-66) { window.location.href="denied.htm"; } else window.location.href=Eingabe+".htm";

saglabaajam uz cieto disku un nedaudz papildinam..

if(Eingabe != ((code.length)*100)/2-66) { var gy = ((code.length)*100)/2-66; alert(gy); } else window.location.href=Eingabe+".htm"; }

un wiss ok ;p


6. Challenge pie shii izaicinaajuma ir jaaizsleedz javascripti browserim.. IE.. Tools > Internet Options > Security > Custom Level .. [Active Scripting] Firebird .. Tools > Options > Web Features .. [Enable Javascript] Opera .. File > Preferences > Fonts > Multimedia .. [Enable Javascript] kad tas izdariic mieriigi luuram source un redzam..

if (passwort=="badscript") { window.location.href="nummer7.htm";

viegli tachu ;p


7. Challenge taa pat kaa ieprieksheejaa izaicinaajumaa jaadizeiblo js.. tad redzeesim

<script SRC="pass.js" LANGUAGE="JavaScript" type="text/javascript">

dodamies uz pass.js skatiities paroli..


8. Challenge joprojaam pie dizeiblotiem js redzam..

UserEingabe = window.prompt("password security level 8",""); document.location.href=UserEingabe + ".htm";

bet kauch kas naw riktiigi.. kauch kas truuxt.. dodamies apluukot vienu diru 'zemaak'.. varbuut tur kaut kas ir.. un tieshaam ieksh http://www.academy.dyndns.org/hackit8/ paraadaas failu liste.. redzam taadu failu kaa login.htm un akal bez komentaariem..


9. Challenge shoreiz sourcee redzam kaut ko garu & riebiigu.. njemam kaut vai notepadu un remuuvojam '<font color="#000000">' ar replace paliidziibu.. paraadaas jau norm texc bez liekas drazas..

Ok, this is an easy game. You just have to answer the question asked here. The Answer is the password. It doesn't contain any special characters like # + * '�"% or any other. So after you managed to make this text readable (which was not very difficult at all, right?) here comes the question: Which city is part of this page's URL. Just type it as the password and all lower case. I hope you had fun, even if it was really simple. But let's see, who didn't delete the cheap noscript-tag. Thanks to the he-crew!

linkaa redzam 'hannover' - pilseetu vaacijaa.


10. Challenge shis ir jloti liidziigs 7am izaicinaajumam.. akal jaadizeiblo js.. un sourcee redzam..

<script src="www.academy.dyndns.org/hackits/security_levels/source4.js" language="JavaScript" type="text/javascript">

taatad dodamies uz 'http://scifi.pages.at/hackits/www.academy.dyndns.org/hackits/security_levels/source4.js' un skataamies paroli..


11. Challenge shijaa izaicinaajumaa jaaievada 5 kodi [tas tachu 5u izaicinaajumu veerc izaicinaajums ;p~] .. kods ir ~ taads..

var a1="%77%68%65%72%65"; var a=document.login.a.value; var b=document.login.b.value; var b1= b.substr(2,2)+ b.substr(0,1)+ b.substr(1,2); var c1="%61%6E%64"; var c=document.login.c.value; var d1= new Array("q", "t", "1", "@", "e", "c", "67", ".", "k", "#", "u", "a", "12", "k", "p", "t", "�", "e", "&", "�", "f", "z", "s", "d", "6", "k") ; var d=document.login.d.value; var e=document.login.e.value; var f = e.substring(1,2) + e.substring (4,5)+ e.substring (6,7) + e.substring (0,1) + e.substring(5,6)+ e.substring(2,3) + e.substring(3,4); if (a== unescape(a1) && b1=="metim" && c== unescape(c1) && d== d1[22] + d1[14] + d1[11] + d1[5] + d1[17] && f=="e..m.et" ) { window.location="next.htm"; done=1;

1. kods = a1, 2. = b1, 3. = c, 4. = d, 5. = f pirmo paarveidojot ieguustam 'where' otrajaa ieguustam 'time' treshajaa 'and' ceturtajaa nolasam no masiiva 'space' un piektajaa saliekam 'meet...' tas arii it kaa wiss.. talaak tiekam veel vienaa parbaudes lapaa, bet tur naw probu..


12. Challenge shijaa izaicinjaajumaa ir jaauzraxta 4 ciparu garsh kods, kura reizinaajumam, kaa redzam sourcee, ir jaabuut 12.. nedaudz paminot ieguustam vienu deriigu kodu - 2161


13. Challenge
redzam java appletu..

<applet code="Pwd.class" archive="Pwd.zip" width="180" height="100" align="center">

[zinam ko dariit].. velkam nost un dekompileejam.. redzam

p = "event.Action";
...
if(p.equals(tf.getText()))
getAppletContext().showDocument(new URL(getDocumentBase(), p + ".htm"), "_self");

kaa redzam nebija iipashi gruutaak par otro chellendzhu ;p


14. Challenge
shoreiz logins.. sourcee redzam diezgan sarezhgjiitu javascriptu.. kaut gan iisteniibaa nemaz naw tik sarezhgjiiti.. atrodam taadu vietu

nls=nls+al.charAt(count+11);
if (nls.indexOf(tst)>-1){

un pieliekam 'document.write(nls);' .. scriptu palaidzot redzeesim, ka juuzerneims ir 'elite' un passvords 'force'


15. Challenge
atkal jaalogojas.. shoreiz tik naw vienkaarsha forma + js.. shoreiz jaameklee 'htpasswd' fails, kuru arii atrodam te - http://www.stud.uni-hannover.de/~dressler/html_auth/htpasswd
talaak jau jaadarbojas ar jtr [john the ripper]
un ieguustam, ka parole ir 'flyer'


16. Challenge
domaaju, ka peedeeejais izaicinaajums buus kaut kas gruutaaks, bet nee.. tikai citadaaks gan bija..
taatad sanjemam kodeetu textu un padomu..

Cxitpla fxe hxemj xeg pxa gx cxort gpqc xmt,
keg mxa at aqoo bptbn qh fxe nmxa gpt bxoxezc.
Apsg bxoxez qc gpt ksbnlzxemj xh gpqc vslt?

[hint: translate answer into german]

atkodeeshana ir vienkaarsha - katram burtam arbilst kaads cits burts.. kad atkodeejam ieguustam jautaajumu: 'kaadaa kraasaa ir lapas pamats'.. labi redzam, ka melns, kas vaaciski ir 'schwarz'..
varbuut nedaudz gruutaaks shis izaicinajaums bija tiem, kas nemaak vaacu valodu, bet domaaju, ka netaa jaabuut pietiekami daudz vaardniicam.. [eng > ger]

Komentāri

  • vienauga ar visu paliidziibu tiku tikai liidz 7paarbaudiijumam. talaak vairs neasaprotu...

  • laikam jau taapeec, ka biku pietruuka texc no 7aa parbaudiijuma apraxta.. tagad izlaboju..

  • can anyone send in my email,or post here, the solution of the level 11 in english?

    thanks

Pievienot komentāru