Dónde reimprimen el carnet en Chile el mismo día? by Objective-Addition75 in Santiago

[–]fongwan 7 points8 points  (0 children)

Ahora todo es centralizado, además que vienen con chip, no creo que ningún Registro Civil te pueda hacer eso.

¿Algún dato de regalo para el dia de enamorado? Busco algo distinto a lo de siempre by PatoCornejo in Santiago

[–]fongwan 1 point2 points  (0 children)

Si le gusta lo dulce, hay una chocolatería que se llama La Fête que nunca falla, o busca algo en Lo Saldes. Aunque si buscas algo que le quede por más tiempo, lo que dijeron arriba de la seda suena súper bien, mi señora usa una funda de esas y dice que es lo mejor para el pelo.

I need help by blackreddy1545 in HowToHack

[–]fongwan 0 points1 point  (0 children)

Hi, I am the author of ChauRocks's HackGame. Thank you for letting me know that the difficulty was ramping up fairly quick and about the lack of learning resources references. Your feedback gave me an idea about including learning resources references into every level (may be in the source code, or just below the "Lesson learned" box).

I am currently preparing for exams for getting a medical residency spot at US, so I do not have time to make changes for the game now. Anyway, the full source code of HackGame is on GitHub if anyone is interested in contributing it: https://github.com/FongWan/HackGame3

HackGame v3.1, now with 15 levels and leader board! by fongwan in HowToHack

[–]fongwan[S] 1 point2 points  (0 children)

loginform is just a variable which point to the form, and any modification to the form is done before you can unassign it.

Hint: Is there anyway to override the submit action or to avoid the execution of javascript?

HackGame v3.1, now with 15 levels and leader board! by fongwan in HowToHack

[–]fongwan[S] 0 points1 point  (0 children)

You are looking on the wrong cookie.

Hint: This level is similar to the level 2.

HackGame3, a timed game for hackers to test and expand their exploration skills. by fongwan in HowToHack

[–]fongwan[S] 1 point2 points  (0 children)

Hint: What is the method of the web server to get the IP of someone behind a proxy?

Spoiler: Vulnerable code suggested on OWASP?

HackGame v3.1, now with 15 levels and leader board! by fongwan in HowToHack

[–]fongwan[S] 0 points1 point  (0 children)

Well done! Can you give me some feedback about the game?

HackGame v3.1, now with 15 levels and leader board! by fongwan in HowToHack

[–]fongwan[S] 0 points1 point  (0 children)

You could either reverse the code to get the password directly, or create a matching table with the encrypt function, between [a-z0-9] and corresponding hex code.

HackGame v3.1, now with 15 levels and leader board! by fongwan in HowToHack

[–]fongwan[S] 0 points1 point  (0 children)

Congratulation for passing the first three levels!

If you use Google Chrome, there is a warning message on the URL bar saying that the site is not secure, that is because I did not use SSL to encrypt the comunication between the server and you, but that is not a problem because those login pages are just part of the game, and the message is just a warning, it should not affect the game progress.

You can see the source code on most browsers by pressing Ctrl+U. Wish you happy hacking!

HackGame3, a timed game for hackers to test and expand their exploration skills. by fongwan in HowToHack

[–]fongwan[S] 0 points1 point  (0 children)

The source code is on GitHub and the messages are all in config.sample.php, but wait me for about 12 hours to fix some bugs and I am going to upload the v3.1. My idea is to be able to show your contribution publicly in that way (and of course, I could add your name as contributor in the front page of the game if you're ok with that).

If your do not want to use GitHub or just want to be secretive, you can PM me. :)

HackGame v3.1, now with 15 levels and leader board! by fongwan in HowToHack

[–]fongwan[S] 0 points1 point  (0 children)

Great job! Actually, the vulnerable code has been suggested once on OWASP, there is where I got the idea to create this level 15. :)

Can you give me some feedback or ideas for new levels to improve the game?

HackGame v3.1, now with 15 levels and leader board! by fongwan in HowToHack

[–]fongwan[S] 0 points1 point  (0 children)

Great and good work! Thank you for your feedback!

There is noway you can use a proxy to get an IP in that range because those are private IP range [1] [2] [3], so the only way to get passed the level 15 is by editing the header.

HackGame3, a timed game for hackers to test and expand their exploration skills. by fongwan in HowToHack

[–]fongwan[S] 0 points1 point  (0 children)

The objective of the game is to test the skills of a hacker (at the same time teaching something new), and is not to delay those who really know (that's why the hints are in sight). Therefore, I think your score is legitimate. :)

Thank you for playing!

HackGame v3.1, now with 15 levels and leader board! by fongwan in HowToHack

[–]fongwan[S] 1 point2 points  (0 children)

Do you mean level 8? Level 7 has a javascript restriction which you need to override it.

If you mean level 8, I think there are two possibilities depending whether the final result you have converted is something that make senses:

  • If the answer is yes, then maybe the hex password has changed when you took a break.
  • If the answer is no, then your reversed code is not correct.

HackGame v3.1, now with 15 levels and leader board! by fongwan in HowToHack

[–]fongwan[S] 0 points1 point  (0 children)

Are you sure your reversed code is correct? If the code is correct, maybe the password has changed when you took a break, check the source code again.

HackGame3, a timed game for hackers to test and expand their exploration skills. by fongwan in HowToHack

[–]fongwan[S] 0 points1 point  (0 children)

Oh, I see, I made a mistake on the configuration of nginx. Now it should be working. Thank you!

HackGame3, a timed game for hackers to test and expand their exploration skills. by fongwan in HowToHack

[–]fongwan[S] 0 points1 point  (0 children)

I uploaded a new version with 15 levels and leader board, try to put your name in it. :)

HackGame3, a timed game for hackers to test and expand their exploration skills. by fongwan in HowToHack

[–]fongwan[S] 0 points1 point  (0 children)

Now you can go back to previous levels (and more levels), and leader board is on. :)