Front Office Football Central  

Go Back   Front Office Football Central > Archives > FOFC Archive
Register FAQ Members List Calendar Mark Forums Read Statistics

Reply
 
Thread Tools
Old 10-20-2003, 09:20 PM   #1
korme
Go Reds
 
Join Date: May 2001
Location: Bloodbuzz Ohio
Try To Hack

Try2Hack

See how far you can get.


I quickly got stuck on level 2.

korme is offline   Reply With Quote
Old 10-20-2003, 09:50 PM   #2
mckerney
Coordinator
 
Join Date: Oct 2000
Got level 2.
mckerney is offline   Reply With Quote
Old 10-20-2003, 10:13 PM   #3
Joe Canadian
College Prospect
 
Join Date: Jan 2003
Location: St. John's, Newfoundland, Canada
I'm stuck on Level 2
__________________
Steve Davis (Joe Canadian)
GO LEAFS GO!!
GO FOG DEVILS GO!!
LETS GO JAYS!!
EHM 2005 DYNASTY: A New Philosophy in Toronto!
Joe Canadian is offline   Reply With Quote
Old 10-20-2003, 10:19 PM   #4
VPI97
Hokie, Hokie, Hokie, Hi
 
Join Date: Mar 2001
Location: Kennesaw, GA
On level 4
VPI97 is offline   Reply With Quote
Old 10-20-2003, 10:19 PM   #5
Joe Canadian
College Prospect
 
Join Date: Jan 2003
Location: St. John's, Newfoundland, Canada
Anyone wanna PM me a hint for Level 2?
__________________
Steve Davis (Joe Canadian)
GO LEAFS GO!!
GO FOG DEVILS GO!!
LETS GO JAYS!!
EHM 2005 DYNASTY: A New Philosophy in Toronto!
Joe Canadian is offline   Reply With Quote
Old 10-20-2003, 10:20 PM   #6
Philliesfan980
Banned
 
Join Date: Feb 2003
Location: Exton, PA
What the hell is up with this? I can't even get past level one.. I tried everything I can think of, whats the trick?
Philliesfan980 is offline   Reply With Quote
Old 10-20-2003, 10:29 PM   #7
Aesyrqwe
High School JV
 
Join Date: Feb 2003
Location: Indiana
I feel smart, i suck with computers, but got to level 2

-Aes-
__________________
Go Bears!
#8 Grossman
#33 Tillman
Aesyrqwe is offline   Reply With Quote
Old 10-20-2003, 10:30 PM   #8
korme
Go Reds
 
Join Date: May 2001
Location: Bloodbuzz Ohio
try right clicking phiilies, thats the only hint i can give you for level 1
korme is offline   Reply With Quote
Old 10-20-2003, 10:31 PM   #9
mckerney
Coordinator
 
Join Date: Oct 2000
Level one: Simple as hell. Password is right in the HTML source.
Level two: A little harder, but username/password are contained in the shockwave file.
mckerney is offline   Reply With Quote
Old 10-20-2003, 10:32 PM   #10
mckerney
Coordinator
 
Join Date: Oct 2000
I've found what I think should be the password for level 3, but it doesn't seem to work.
mckerney is offline   Reply With Quote
Old 10-20-2003, 10:33 PM   #11
VPI97
Hokie, Hokie, Hokie, Hi
 
Join Date: Mar 2001
Location: Kennesaw, GA
Quote:
Originally posted by Joe Canadian
Anyone wanna PM me a hint for Level 2?
Sent

Quote:
Originally posted by mckerney
I've found what I think should be the password for level 3, but it doesn't seem to work.
You didn't find it. Know your HTML.

Last edited by VPI97 : 10-20-2003 at 10:34 PM.
VPI97 is offline   Reply With Quote
Old 10-20-2003, 10:37 PM   #12
mckerney
Coordinator
 
Join Date: Oct 2000
Quote:
Originally posted by VPI97
Sent

You didn't find it. Know your HTML.


which is part of the problem, I don't really know HTML
mckerney is offline   Reply With Quote
Old 10-20-2003, 10:39 PM   #13
Aesyrqwe
High School JV
 
Join Date: Feb 2003
Location: Indiana
can i get a pm for level 2? just so i dont lose sleep over the damn thing..

-Aes-
__________________
Go Bears!
#8 Grossman
#33 Tillman
Aesyrqwe is offline   Reply With Quote
Old 10-20-2003, 10:40 PM   #14
VPI97
Hokie, Hokie, Hokie, Hi
 
Join Date: Mar 2001
Location: Kennesaw, GA
Quote:
Originally posted by mckerney
which is part of the problem, I don't really know HTML
But you do know what the 'src' parameter means, don't you?

Anyway, I'm at a stopping point on level 4...I think I would need a Java decompiler and I don't think I have one on this PC...and I'm too lazy to find and download one
VPI97 is offline   Reply With Quote
Old 10-20-2003, 10:46 PM   #15
Vince
Pro Starter
 
Join Date: Aug 2001
Location: Willow Glen, CA
Ok, I'm confused. Every time I try the link, I get a blank white page. Should I not be getting something else?
__________________
Every time a Dodger scores a run, an angel has its wings ripped off by a demon, and is forced to tearfully beg the demon to cauterize the wounds.The demon will refuse, and the sobbing angel will lie in a puddle of angel blood and feathers for eternity, wondering why the Dodgers are allowed to score runs.Thats not me talking: thats science. McCoveyChronicles.com.
Vince is offline   Reply With Quote
Old 10-20-2003, 10:47 PM   #16
mckerney
Coordinator
 
Join Date: Oct 2000
Quote:
Originally posted by VPI97
But you do know what the 'src' parameter means, don't you?


Well, no.

Here's what I'm looking at, tell me how far off I am:

pwd = prompt("Please enter the password for level 3:","");
if (pwd==PASSWORD){
alert("Allright!\nEntering Level 4 ...");
location.href = CORRECTSITE;


......

PASSWORD="AbCdE";
CORRECTSITE="level4-sfvfxc.xhtml";
mckerney is offline   Reply With Quote
Old 10-20-2003, 10:50 PM   #17
VPI97
Hokie, Hokie, Hokie, Hi
 
Join Date: Mar 2001
Location: Kennesaw, GA
I'll try to be subtle (unless you want the answer straight out)...you're looking at script when you read that code...how do you tell what language the script is written in? ...and is that the only script on the page?
VPI97 is offline   Reply With Quote
Old 10-20-2003, 10:53 PM   #18
Vince
Pro Starter
 
Join Date: Aug 2001
Location: Willow Glen, CA
Heh, I'm a quick one.
__________________
Every time a Dodger scores a run, an angel has its wings ripped off by a demon, and is forced to tearfully beg the demon to cauterize the wounds.The demon will refuse, and the sobbing angel will lie in a puddle of angel blood and feathers for eternity, wondering why the Dodgers are allowed to score runs.Thats not me talking: thats science. McCoveyChronicles.com.
Vince is offline   Reply With Quote
Old 10-20-2003, 11:19 PM   #19
sony
High School JV
 
Join Date: May 2002
Location: Travis AFB, CA
Damn it! I stuck on Stage 2
sony is offline   Reply With Quote
Old 10-20-2003, 11:57 PM   #20
EagleFan
Hall Of Famer
 
Join Date: Nov 2000
Location: Mays Landing, NJ USA
Level 2 has me stumped. I'm looking at what I believe to be the shockwave file but I am not having any luck decoding what shoudl be the username and password.
EagleFan is offline   Reply With Quote
Old 10-21-2003, 12:01 AM   #21
mckerney
Coordinator
 
Join Date: Oct 2000
Look in your internet temp files, it should be called level2[1].swf
mckerney is offline   Reply With Quote
Old 10-21-2003, 12:01 AM   #22
Eilim
High School Varsity
 
Join Date: Oct 2002
Location: Foxboro,MA
Level 4 for me at the moment, got the class file decompiled but think I might have to dig out some of my old java books.


-Eilim
Eilim is offline   Reply With Quote
Old 10-21-2003, 12:05 AM   #23
Pumpy Tudors
Bounty Hunter
 
Join Date: Oct 2000
Location: Pittsburgh, PA
From what I've gathered (thanks to hanging out in the site's IRC chat), to get any deeper than level 4, you really need to know your programming and network stuff. It's not for those without a pretty decent computer science/programming background.

I pretty much cheated to get through the first three levels, but when I saw the correct answers, I realized that they weren't THAT hard to find (level 3 was much easier than level 2 to me, though). I doubt I could get any further without somebody holding my hand the whole way.

When I expressed my lack of knowledge to the people in the chat, they suggested I try www.hackthissite.org, and I am finding that to be at least more user-friendly, if not easier.
__________________
No, I am not Batman, and I will not repair your food processor.
Pumpy Tudors is offline   Reply With Quote
Old 10-21-2003, 12:08 AM   #24
EagleFan
Hall Of Famer
 
Join Date: Nov 2000
Location: Mays Landing, NJ USA
Do I need something to be able to open that file with. The only thing that I can open that with is IE and it just gives me the shockwave logon box that is on the web page.
EagleFan is offline   Reply With Quote
Old 10-21-2003, 12:14 AM   #25
Eilim
High School Varsity
 
Join Date: Oct 2002
Location: Foxboro,MA
I've tried a few of the "wargames" sites in the past. A friend of mine completed try2hack not too long ago and suggested I give ti a shot but I just never got around too it.

I figured this one would be somewhat tougher than most because he had brought the site up after asking me what my favorite packetsniffer was. So I'm guessing at some point this one may get a bit tricky.

-Eilim
Eilim is offline   Reply With Quote
Old 10-21-2003, 12:16 AM   #26
Eilim
High School Varsity
 
Join Date: Oct 2002
Location: Foxboro,MA
dola...


Quote:
Originally posted by EagleFan
Do I need something to be able to open that file with. The only thing that I can open that with is IE and it just gives me the shockwave logon box that is on the web page.


Your going to need to use a .swf decompiler, could probably get away with using a hex editor.


-Eilim

Last edited by Eilim : 10-21-2003 at 12:16 AM.
Eilim is offline   Reply With Quote
Old 10-21-2003, 12:16 AM   #27
VPI97
Hokie, Hokie, Hokie, Hi
 
Join Date: Mar 2001
Location: Kennesaw, GA
Quote:
Originally posted by EagleFan
The only thing that I can open that with is IE
No it's not. In fact, you can open it with something you've already used in this exercise.
Quote:
Originally posted by Eilim
Your going to need to use a .swf decompiler, could probably get away with using a hex editor.
It's a lot easier than that.

Last edited by VPI97 : 10-21-2003 at 12:17 AM.
VPI97 is offline   Reply With Quote
Old 10-21-2003, 12:20 AM   #28
Eilim
High School Varsity
 
Join Date: Oct 2002
Location: Foxboro,MA
Good call, VPI97. Didn't even think of that. Guess I've gotten lazy with all my toys. Just checked it out and had to laugh at myself for overlooking that one.

-Eilim
Eilim is offline   Reply With Quote
Old 10-21-2003, 12:39 AM   #29
sterlingice
Hall Of Famer
 
Join Date: Apr 2002
Location: Back in Houston!
Ok, so everyone doesn't have to run out and get a Java Decompiler, here's the Java for 4. I need to get back to homework, but anyone else, knock yourself out:

Quote:
// Decompiled by DJ v3.5.5.77 Copyright 2003 Atanas Neshkov Date: 10/21/2003 12:31:51 AM
// Home Page : http://members.fortunecity.com/neshkov/dj.html - Check often for new version!
// Decompiler options: packimports(3)
// Source File Name: PasswdLevel4.java

import java.applet.Applet;
import java.applet.AppletContext;
import java.awt.*;
import java.awt.event.ActionEvent;
import java.awt.event.ActionListener;
import java.io.*;
import java.net.MalformedURLException;
import java.net.URL;
import java.util.EventObject;

public class PasswdLevel4 extends Applet
implements ActionListener
{

public PasswdLevel4()
{
inuser = new String[22];
totno = 0;
countConn = null;
countData = null;
inURL = null;
txtlogin = new TextField();
label1 = new Label();
label2 = new Label();
label3 = new Label();
txtpass = new TextField();
lblstatus = new Label();
ButOk = new Button();
ButReset = new Button();
lbltitle = new Label();
}

void ButOk_ActionPerformed(ActionEvent actionevent)
{
boolean flag = false;
for(int i = 1; i <= totno / 2; i++)
if(txtlogin.getText().trim().toUpperCase().intern() == inuser[2 * (i - 1) + 2].trim().toUpperCase().intern() && txtpass.getText().trim().toUpperCase().intern() == inuser[2 * (i - 1) + 3].trim().toUpperCase().intern())
{
lblstatus.setText("Login Success, Loading..");
flag = true;
String s = inuser[1].trim().intern();
String s1 = getParameter("targetframe");
if(s1 == null)
s1 = "_self";
try
{
finalurl = new URL(getCodeBase(), s);
}
catch(MalformedURLException _ex)
{
lblstatus.setText("Bad URL");
}
getAppletContext().showDocument(finalurl, s1);
}

if(!flag)
lblstatus.setText("Invaild Login or Password");
}

void ButReset_ActionPerformed(ActionEvent actionevent)
{
txtlogin.setText("");
txtpass.setText("");
}

public void actionPerformed(ActionEvent actionevent)
{
Object obj = actionevent.getSource();
if(obj == ButOk)
{
ButOk_ActionPerformed(actionevent);
return;
}
if(obj == ButReset)
ButReset_ActionPerformed(actionevent);
}

public void destroy()
{
ButOk.setEnabled(false);
ButReset.setEnabled(false);
txtlogin.setVisible(false);
txtpass.setVisible(false);
}

public void inFile()
{
new StringBuffer();
try
{
countConn = inURL.openStream();
countData = new BufferedReader(new InputStreamReader(countConn));
String s;
while((s = countData.readLine()) != null)
if(totno < 21)
{
totno = totno + 1;
inuser[totno] = s;
s = "";
} else
{
lblstatus.setText("Cannot Exceed 10 users, Applet fail start!");
destroy();
}
}
catch(IOException ioexception)
{
getAppletContext().showStatus("IO Error:" + ioexception.getMessage());
}
try
{
countConn.close();
countData.close();
return;
}
catch(IOException ioexception1)
{
getAppletContext().showStatus("IO Error:" + ioexception1.getMessage());
}
}

public void init()
{
setLayout(null);
setSize(361, 191);
add(txtlogin);
txtlogin.setBounds(156, 72, 132, 24);
label1.setText("Please Enter Login Name & Password");
label1.setAlignment(1);
add(label1);
label1.setFont(new Font("Dialog", 1, 12));
label1.setBounds(41, 36, 280, 24);
label2.setText("Login");
add(label2);
label2.setFont(new Font("Dialog", 1, 12));
label2.setBounds(75, 72, 36, 24);
label3.setText("Password");
add(label3);
add(txtpass);
txtpass.setEchoChar('*');
txtpass.setBounds(156, 108, 132, 24);
lblstatus.setAlignment(1);
label3.setFont(new Font("Dialog", 1, 12));
label3.setBounds(75, 108, 57, 21);
add(lblstatus);
lblstatus.setFont(new Font("Dialog", 1, 12));
lblstatus.setBounds(14, 132, 344, 24);
ButOk.setLabel("OK");
add(ButOk);
ButOk.setFont(new Font("Dialog", 1, 12));
ButOk.setBounds(105, 156, 59, 23);
ButReset.setLabel("Reset");
add(ButReset);
ButReset.setFont(new Font("Dialog", 1, 12));
ButReset.setBounds(204, 156, 59, 23);
lbltitle.setAlignment(1);
add(lbltitle);
lbltitle.setFont(new Font("Dialog", 1, 12));
lbltitle.setBounds(12, 14, 336, 24);
String s = getParameter("title");
lbltitle.setText(s);
ButOk.addActionListener(this);
ButReset.addActionListener(this);
infile = new String("level4");
try
{
inURL = new URL(getCodeBase(), infile);
}
catch(MalformedURLException _ex)
{
getAppletContext().showStatus("Bad Counter URL:" + inURL);
}
inFile();
}

private URL finalurl;
String infile;
String inuser[];
int totno;
InputStream countConn;
BufferedReader countData;
URL inURL;
TextField txtlogin;
Label label1;
Label label2;
Label label3;
TextField txtpass;
Label lblstatus;
Button ButOk;
Button ButReset;
Label lbltitle;
}

SI
__________________
Houston Hippopotami, III.3: 20th Anniversary Thread - All former HT players are encouraged to check it out!

Janos: "Only America could produce an imbecile of your caliber!"
Freakazoid: "That's because we make lots of things better than other people!"


sterlingice is offline   Reply With Quote
Old 10-21-2003, 01:07 AM   #30
rdo
n00b
 
Join Date: Oct 2000
Location: Brisbane
infile = new String("level4");

is the key line
rdo is offline   Reply With Quote
Old 10-21-2003, 01:15 AM   #31
VPI97
Hokie, Hokie, Hokie, Hi
 
Join Date: Mar 2001
Location: Kennesaw, GA
Quote:
Originally posted by rdo
infile = new String("level4");

is the key line
Bling bling
VPI97 is offline   Reply With Quote
Old 10-21-2003, 01:28 AM   #32
Solecismic
Solecismic Software
 
Join Date: Oct 2000
Location: Canton, OH
Yeah, I see that one from the code above. But I'm stuck on level 2. Any good hint would be appreciated.
Solecismic is offline   Reply With Quote
Old 10-21-2003, 01:30 AM   #33
JeeberD
General Manager
 
Join Date: Nov 2002
Location: The Town of Flower Mound
Now I remember why I changed my major from BCIS...
__________________
UTEP Miners!!!

I solemnly swear to never cheer for TO
JeeberD is offline   Reply With Quote
Old 10-21-2003, 01:38 AM   #34
mckerney
Coordinator
 
Join Date: Oct 2000
Quote:
Originally posted by Solecismic
Yeah, I see that one from the code above. But I'm stuck on level 2. Any good hint would be appreciated.


You need to look at the .swf file that has the username/password prompt. Level 2 was fairly easy for me, but there is no way I'd be able to do level 4.

Last edited by mckerney : 10-21-2003 at 01:38 AM.
mckerney is offline   Reply With Quote
Old 10-21-2003, 01:39 AM   #35
rdo
n00b
 
Join Date: Oct 2000
Location: Brisbane
Quote:
Originally posted by Solecismic
Yeah, I see that one from the code above. But I'm stuck on level 2. Any good hint would be appreciated.


Take a closer look at the shockwave file
rdo is offline   Reply With Quote
Old 10-21-2003, 01:39 AM   #36
Solecismic
Solecismic Software
 
Join Date: Oct 2000
Location: Canton, OH
Just looks like garbage to me. Perhaps I downloaded it wrong (save-as through netscape).
Solecismic is offline   Reply With Quote
Old 10-21-2003, 01:42 AM   #37
mckerney
Coordinator
 
Join Date: Oct 2000
Here's what you should get:

FWS p _  C 3?    Courier New   *  w _0  ( Username :
    *  w _0  ( Password :
  +~ ?\  e#_B k@  5ozs
0>([ tR ;)>/" N r3r
PuP ?  eS
HMh'[W  +++_$`U> +++ 4:1<\3"J!wc
ML1w5? r͔$)˃2y Qkҩ쀀 ?&  e#_B  f ozg: a|Q vR|^Dbc:g:_ UCYҰ 0bZS?_\}6r_,0F$BT!ꣿ:P j,>  f !5ozYΆvp{oo_:){ X Xιι(:mtln?L+  >Kϖ+ =qg/k,ȫ $bgV'3l UҀQ` ?  \P   5n?s4 >L .>Xl tVkW5M ( "/d9P gHzΔ  Mh'[C +++ n'>8* ~gevr Brī{ @_$`U  +++ q_9YkfdQD txtUsername 
try2hack I
txtPassword 
irtehh4x0r! I   level3-.xhtml _self  uU>UC_ ]
pS[~p_T_  -VE hd|T8G^PP ]n _F 
 + w
@@     ( txtUsername  > OE4
 + w
@     ( txtPassword 
Pfe @

Last edited by mckerney : 10-21-2003 at 01:42 AM.
mckerney is offline   Reply With Quote
Old 10-21-2003, 01:47 AM   #38
Solecismic
Solecismic Software
 
Join Date: Oct 2000
Location: Canton, OH
Thanks... that doesn't look anything like what I downloaded.

level 4 is just a matter of going backward from a couple of key lines.
Solecismic is offline   Reply With Quote
Old 10-21-2003, 08:26 AM   #39
Fido
High School Varsity
 
Join Date: Aug 2002
Location: New Hampshire, USA
Level 6 and officially giving up.
__________________
Author of FOF Reporter and TCY Helper.
Fido is offline   Reply With Quote
Old 10-21-2003, 09:03 AM   #40
KevinNU7
College Starter
 
Join Date: May 2003
Location: Beantown
Anyone else keep getting taken to the Disneystore website?
__________________
Boston Bashers - III.14 - (8347)
KevinNU7 is offline   Reply With Quote
Old 10-21-2003, 09:21 AM   #41
Fido
High School Varsity
 
Join Date: Aug 2002
Location: New Hampshire, USA
Quote:
Originally posted by KevinNU7
Anyone else keep getting taken to the Disneystore website?

Everyone who enters the wrong password...
Fido is offline   Reply With Quote
Old 10-21-2003, 10:19 AM   #42
Celeval
Pro Starter
 
Join Date: Nov 2000
Location: Cary, NC, USA
Bah, you guys are giving too many hints. :-)

Level 5 and counting
Celeval is offline   Reply With Quote
Old 10-21-2003, 10:38 AM   #43
Celeval
Pro Starter
 
Join Date: Nov 2000
Location: Cary, NC, USA
Level 6, and trying to remember networking. :-)
Celeval is offline   Reply With Quote
Old 10-21-2003, 10:53 AM   #44
johnnyshaka
College Benchwarmer
 
Join Date: Oct 2002
Location: Edmonton, AB
Quote:
Originally posted by KevinNU7
Anyone else keep getting taken to the Disneystore website?


Oh crap...I thought that meant I had won...whoops!!!
johnnyshaka is offline   Reply With Quote
Old 10-21-2003, 11:41 AM   #45
Celeval
Pro Starter
 
Join Date: Nov 2000
Location: Cary, NC, USA
Ha! This is fun. Level 7 and counting..
Celeval is offline   Reply With Quote
Old 10-21-2003, 12:20 PM   #46
CamEdwards
Stadium Announcer
 
Join Date: Mar 2002
Location: Burke, VA
now surfing ESPN and counting.
__________________
I don't want the world. I just want your half.
CamEdwards is offline   Reply With Quote
Old 10-21-2003, 01:29 PM   #47
Celeval
Pro Starter
 
Join Date: Nov 2000
Location: Cary, NC, USA
Hehe... so some of us are geekier than others. Up to Level 8, but I think it's time to stop doing this at work, since we're working on exploits now.
Celeval is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump


All times are GMT -5. The time now is 03:33 PM.



Powered by vBulletin Version 3.6.0
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.