as the search.php is only to search inside the file directory, have a look into the file directory. just type file/ after basic9 in the url. u will be taken to a directory listing. there u will find the file need to be opened. if u enter the file directly, it will run the file. but you have to open it to read, not run. so open in a different (just read about null byte poisoning) here. now u will be asked to enter the second level. if you enter the second, level a php file will be saved as html file. so u can read the source(use firefox). now save the username and the password. then sumbit them in the right place to login. u will be added 30 points.
Ans:
- open the location, http://www.hellboundhackers.org/challenges/basic9/files/
- now enter the file need to be open(login.php) in the search box in the search.php page. but it will run. now u have some knowledge about null byte poisoning.
- enter following without cotes in the search box of the search.php. "login.php"
- the first level is over. a link will appear, that asks u for enter the second level. just click it
- ones.html file will be opened. view the source of the file with firefox. because, chrome won't show the password. in the source, u can find the username and password.
- copy it and enter it at the starting page of this challenge, www.hellboundhackers.org/challenges/basic9
- ur points will be added with 30.
I have been exploring for a little bit for any high-quality articles or weblog posts on this sort of area . Exploring in Yahoo I finally stumbled upon this website. Studying this info So i? satisfied to show that I have a very excellent uncanny feeling I found out just what I needed. I so much indisputably will make sure to do not forget this site and provides it a glance regularly.
ReplyDeleteFor More Info:
onlinehacker4hire @ gmail . com
If you are looking for a professional hacker to provide hacking solutions on (Wizardbrixton @ gmail.com )
ReplyDelete-Social media hacks
-Company Email hacks
-Phone hacks
-Email hack: Gmail, AOL, Yahoo mail, Proton-mail etc,
-Mobile phone (call and text message Hacking are available also)
-ATM hack,
-Account hack
-Spy on a cheating Husband/wife
-Retrieval of lost documents
-School result upgrading
-Bitcoin recovering
-Hack into bitcoin with large coins
-Binary option funds recovery and lot more, search no further.
I fully recommend you to contact him he will help you recovered all data you have lost on a phone and helped in tracking the phone till it was found, contact him ( Wizardbrixton@gmail.com) Whatsapps : (+1- /807-23 ) 4-0428 ;)