 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Corner &#187; Hacking Skills Challenge</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/security-corner/tag/hacking-skills-challenge/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/security-corner</link>
	<description></description>
	<lastBuildDate>Sat, 25 May 2013 16:54:23 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>What a Geek puzzle!</title>
		<link>http://itknowledgeexchange.techtarget.com/security-corner/what-a-geek-puzzle/</link>
		<comments>http://itknowledgeexchange.techtarget.com/security-corner/what-a-geek-puzzle/#comments</comments>
		<pubDate>Sat, 31 Dec 2011 12:54:09 +0000</pubDate>
		<dc:creator>Ken Harthun</dc:creator>
				<category><![CDATA[Ciphers]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Hacking Skills Challenge]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-corner/what-a-geek-puzzle/</guid>
		<description><![CDATA[Can you solve this? The actual contest is over, but Sophos published a challenge recently that even stumped ME! Can you believe it? Anyway, here&#8217;s a link to the original challenge: &#8220;The #dragontattoo #sophospuzzle.&#8221; Stage One is a simple 24-character code. Here it is: =ImYndmbn1ieiBnLmJWdjJmZ All you need to do is to figure out how [...]]]></description>
				<content:encoded><![CDATA[<p>Can you solve this? The actual contest is over, but Sophos published a challenge recently that even stumped ME! Can you believe it? Anyway, here&#8217;s a link to the original challenge: &#8220;<a href="http://nakedsecurity.sophos.com/2011/12/19/try-the-christmas-sophospuzzle-and-win-a-lego-mindstorm/">The #dragontattoo #sophospuzzle</a>.&#8221;</p>
<blockquote><p>Stage One is a simple 24-character code.</p>
<p>Here it is:</p>
<pre style="text-align: center;font-size: 105%">=ImYndmbn1ieiBnLmJWdjJmZ</pre>
<p>All you need to do is to figure out how to transform this code into a URL.</p>
<p>Then follow your nose to the next stage.</p></blockquote>
<p>Believe me, it&#8217;s not easy (unless you already know how to transform the text!) Hint: The &#8220;=&#8221; gives it away if you know your Linux.</p>
<p>I&#8217;ll post the video solution on New Year&#8217;s Eve, 23:59 UTC.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-corner/what-a-geek-puzzle/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking Skills Challenge &#8211; Uncle Arnold&#8217;s Local Band Review</title>
		<link>http://itknowledgeexchange.techtarget.com/security-corner/hacking-skills-challenge-uncle-arnolds-local-band-review/</link>
		<comments>http://itknowledgeexchange.techtarget.com/security-corner/hacking-skills-challenge-uncle-arnolds-local-band-review/#comments</comments>
		<pubDate>Fri, 13 Aug 2010 17:01:31 +0000</pubDate>
		<dc:creator>Ken Harthun</dc:creator>
				<category><![CDATA[Ethical hacking]]></category>
		<category><![CDATA[Hacking Skills Challenge]]></category>
		<category><![CDATA[Scripting]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-corner/?p=831</guid>
		<description><![CDATA[With the completion of Hacking Skills Challenge #11 back in May (wow! time flies), we&#8217;ve now entered the realm of realistic missions. As always, things start out relatively easy, then escalate into the stratosphere. But first, let me point out that when you go to the site, there is always a witty, poignant or otherwise [...]]]></description>
				<content:encoded><![CDATA[<p>With the completion of <a href="http://itknowledgeexchange.techtarget.com/security-corner/wp-admin/post.php?action=edit&amp;post=722" target="_blank">Hacking Skills Challenge #11</a> back in May (wow! time flies), we&#8217;ve now entered the realm of realistic missions. As always, things start out relatively easy, then escalate into the stratosphere.</p>
<p>But first, let me point out that when you go to the site, there is always a witty, poignant or otherwise pithy, but often true, quote. Here&#8217;s the one I just encountered: &#8220;If you ask the government for permission to protest it, you deserve to  be told no.&#8221; &#8211;Manhattan Libertarian Party Chair, Jim Lesczynski.&#8221;</p>
<p>OK. So, let&#8217;s take the first challenge and see what gives: <span style="font-size: xx-small"><strong></strong></span></p>
<blockquote><p><a href="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/36/files/2010/08/real1.jpg"><img class="alignleft size-medium wp-image-830" src="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/36/files/2010/08/real1.jpg" alt="" width="200" height="149" /></a><span style="font-size: xx-small"><strong>Uncle Arnold&#8217;s Local Band Review</strong></span><br />
Your friend is being cheated out of hundreds of dollars. Help him make things even again!<br />
<strong>Difficulty rating: Easy.</strong></p></blockquote>
<p>So, here&#8217;s the challenge we get upon entering:</p>
<blockquote><p><strong>From</strong>: HeavyMetalRyan</p>
<p><strong>Message</strong>: Hey man, I need a big favour from you. Remember that website I showed you once before? <a href="http://www.hackthissite.org/missions/realistic/1/">Uncle Arnold&#8217;s Band Review Page</a>?  Well, a long time ago I made a $500 bet with a friend that my band  would be at the top of the list by the end of the year. Well, as you  already know, two of my band members have died in a horrendous car  accident&#8230; but this [expletive deleted] still insists that the bet is on!</p>
<p>I know you&#8217;re good with computers and stuff, so I was wondering, is there any way for you to hack this  website and make my band on the top of the list? My band is Raging  Inferno. Thanks a lot, man!</p></blockquote>
<p>Sounds like a plan! Let&#8217;s get into it. It&#8217;s really almost too easy.</p>
<p>Visit the site and view the page source. Note that it uses &#8220;v.php&#8221; with the GET method to record the votes. There are two hidden inputs: PHPSESSID and id; you&#8217;ll need to use both of these. What we&#8217;re going to do is use the address bar to pass a very high value to the server and move Raging Inferno to the top.</p>
<p>Copy the value of PHPSESSID and note the id value (yours may be different than what I show here). Using the values for PHPSESSID and id, construct this URL: <code>http://www.hackthissite.org/missions/realistic/1/<strong>v.php?PHPSESSID=abcaeadfc31a5c43b2534bf995c0553f&amp;id=3&amp;vote=99</strong></code> and submit it.</p>
<p>If you&#8217;ve done everything right, you&#8217;ll see a blue button on the next page that says &#8220;Go On.&#8221; Clicking that button takes you to the next mission.</p>
<p>Congratulations!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-corner/hacking-skills-challenge-uncle-arnolds-local-band-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking Skills Challenge &#8211; Level 11</title>
		<link>http://itknowledgeexchange.techtarget.com/security-corner/hacking-skills-challenge-level-11/</link>
		<comments>http://itknowledgeexchange.techtarget.com/security-corner/hacking-skills-challenge-level-11/#comments</comments>
		<pubDate>Sun, 30 May 2010 16:49:26 +0000</pubDate>
		<dc:creator>Ken Harthun</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Hacking Skills Challenge]]></category>
		<category><![CDATA[secure coding]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-corner/hacking-skills-challenge-level-11/</guid>
		<description><![CDATA[It’s again time to delve into our Hacking Skills Challenge. Our last challenge was level 10 at HackThisSite.org and that was three months ago. They say these are supposed to get increasingly difficult as we climb the ladder, but the last one was fairly easy, albeit that it required a Firefox plugin to accomplish the hack. [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/36/files/2010/05/hack11.gif"><img class="alignleft size-medium wp-image-721" style="margin-left: 10px;margin-right: 10px" src="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/36/files/2010/05/hack11.gif" alt="" width="70" height="70" /></a>It’s again time to delve into our Hacking Skills Challenge. Our last   challenge was level 10 at <a title="http://HackThisSite." href="http://hackthissite.org/" target="_blank">HackThisSite.org</a> and  that was three months  ago. They say these are supposed to get  increasingly difficult as we climb the ladder, but the last one was fairly easy, albeit that it required a Firefox plugin to accomplish the hack. Level 11 is considerably more difficult and requires a bit of thinking out of the box. Here’s the challenge:</p>
<blockquote><p>Sam decided to make a music site.  Unfortunately he does not understand  Apache.  This mission is a bit harder than the other basics.</p></blockquote>
<p>One of the biggest problems people who don&#8217;t understand Apache run into is that they end up allowing their directories to be listed. We need to keep that in mind. You&#8217;ll see why in a minute.</p>
<p>When you click on the challenge, you&#8217;re taken to a page that has a sentence similar to: <em>I love my music! &#8220;I Need You to Turn To&#8221; is the best! </em>Not much of a clue there, it seems, and where&#8217;s the password prompt? And what page are we looking at? Viewing the source produced this:</p>
<pre>I love my music!
"Someone Saved My Life Tonight" is the best!

<span class="comment">&lt;!--We even have our own collection - if you could find it!--&gt;
</span></pre>
<p>Nothing listed for the actual page being viewed which made me think that it&#8217;s straight html. So, I tried ../index.php and voila! Got a password prompt. Progress, but a few tries at guessing the password were futile. On a whim, I went back to the original URL, http://www.hackthissite.org/missions/basic/11/, and found that the song name had changed. This time I got:</p>
<pre>I love my music!
"Honky Cat" is the best!

<span class="comment">&lt;!--We even have our own collection - if you could find it!--&gt;</span></pre>
<p>So, I refreshed the page a few times and kept getting different songs. Like the two above, however, they all had one thing in common: The were songs performed by Elton John. I tried &#8220;elton&#8221; as the password, but no go, so it&#8217;s time to see if we can find .htaccess to see if we can get some answers.</p>
<p>http://www.hackthissite.org/missions/.htaccess &#8211; no go<br />
http://www.hackthissite.org/missions/basic/.htaccess &#8211; no go<br />
http://www.hackthissite.org/missions/basic/11/.htaccess &#8211; no go<br />
http://www.hackthissite.org/missions/basic/11/elton/.htaccess &#8211; no go</p>
<p>Convinced that &#8220;elton&#8221; is the key, I tried an old trick that I&#8217;ve seen before and put this in: http://www.hackthissite.org/missions/basic/11/e. I got a listing with the letters b, c, d, e, f, g, and l as other directories. Hmm. . . could it be? I tried http://www.hackthissite.org/missions/basic/11/e/l and the last letter listed was &#8220;t.&#8221; Pretty obvious now: http://www.hackthissite.org/missions/basic/11/e/l/t/o/n. Nothing listed there, but that has to be where .htaccess is located. Sure enough:</p>
<pre>IndexIgnore DaAnswer.* .htaccess
&lt;Files .htaccess&gt;
order allow,deny
allow from all
&lt;/Files&gt;</pre>
<p>Think &#8220;DaAnswer.*&#8221; might be it? Yep. http://www.hackthissite.org/missions/basic/11/e/l/t/o/n/DaAnswer gives:</p>
<pre>The answer is simple!
Just look a little harder.</pre>
<p>The answer is: simple. That&#8217;s the password.</p>
<p>Mission accomplished!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-corner/hacking-skills-challenge-level-11/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking Skills Challenge &#8211; Level 10</title>
		<link>http://itknowledgeexchange.techtarget.com/security-corner/hacking-skills-challenge-level-10/</link>
		<comments>http://itknowledgeexchange.techtarget.com/security-corner/hacking-skills-challenge-level-10/#comments</comments>
		<pubDate>Thu, 29 Apr 2010 01:18:58 +0000</pubDate>
		<dc:creator>Ken Harthun</dc:creator>
				<category><![CDATA[Ethical hacking]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Hacking Skills Challenge]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-corner/hacking-skills-challenge-level-10/</guid>
		<description><![CDATA[It&#8217;s again time to delve into our Hacking Skills Challenge. Our last challenge was level 9 at HackThisSite.org and that was three months ago. They say these are supposed to get increasingly difficult as we climb the ladder, but this one is almost too easy. Here&#8217;s the challenge: Network Security Sam has decided to hard code [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/36/files/2010/01/hack9.gif"><img class="alignleft size-medium wp-image-546" style="margin-left: 10px;margin-right: 10px" src="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/36/files/2010/01/hack9.gif" alt="" width="70" height="70" /></a>It&#8217;s again time to delve into our Hacking Skills Challenge. Our last  challenge was level 9 at <a title="http://HackThisSite." href="http://hackthissite.org/" target="_blank">HackThisSite.org</a> and that was three months  ago. They say these are supposed to get increasingly difficult as we climb the ladder, but this one is almost too easy. Here&#8217;s the challenge:</p>
<blockquote><p>Network Security Sam has decided to hard code the password into the  script. He also started to use cookies to detect if the user is  authorized to advance to the next level. When you enter the correct  password, it sets you to authorized, and if you enter an incorrect  password, it sets you to unauthorized.</p></blockquote>
<p>Ever edit a cookie? That&#8217;s all you have to do. Read the above challenge again and you&#8217;ll see that it tells you exactly how to crack it. I used a Firefox add-on called &#8220;<a href="https://addons.mozilla.org/en-US/firefox/addon/4510">Edit Cookies</a>&#8221; to accomplish it.</p>
<p>Enter some random password into the field. It won&#8217;t be the right one, of course. Now, you have a cookie set on your machine named “level11_authorized” that is set to &#8220;no.&#8221; Edit the cookie and change the content from  “no” to “yes”. After this, you can move to the next level<code></code>.</p>
<p>Mission accomplished!</p>
<p>(Note: when I went to check this again, I got a message that the site is currently under maintenance: &#8220;HackThisSite.org is temporarily offline.  We&#8217;re currently busy fixing  some erroneous code, and will have HackThisSite.org back online as soon  as possible.  Thanks for your patience! &#8211; HackThisSite Staff&#8221;)</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-corner/hacking-skills-challenge-level-10/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
