目前分類:Web Pentester (20)
- Nov 24 Fri 2017 15:46
apache struts cve-2017-5638
- Sep 08 Fri 2017 09:58
Hack This Site - Basic 10
This time Sam used a more temporary and "hidden" approach to authenticating users, but he didn't think about whether or not those users knew their way around javascript...
- Sep 08 Fri 2017 09:56
Hack This Site - Basic 9
The password is again hidden in an unknown file. However, the script that was previously used to find it has some limitations. Requirements: Knowledge of SSI, unix directory structure.
- Sep 08 Fri 2017 09:54
Hack This Site - Basic 8
The password is yet again hidden in an unknown file. Sam's daughter has begun learning PHP, and has a small script to demonstrate her knowledge. Requirements: Knowledge of SSI (dynamic html executed by the server, rather than the browser)
- Sep 08 Fri 2017 09:52
Hack This Site - Basic 7
The password is hidden in an unknown file, and Sam has set up a script to display a calendar. Requirements: Basic UNIX command knowledge.
- Sep 08 Fri 2017 09:50
Hack This Site - Basic 6
An encryption system has been set up, which uses an unknown algorithm to change the text given. Requirements: Persistence, some general cryptography knowledge.
- Sep 08 Fri 2017 09:49
Hack This Site - Basic 5
Similar to the previous challenge, but with some extra security measures in place. Requirements: HTML knowledge, JS or FF, an email address.
- Sep 08 Fri 2017 09:48
Hack This Site - Basic 4
An email script has been set up, which sends the password to the administrator. Requirements: HTML knowledge, an email address
- Sep 08 Fri 2017 09:47
Hack This Site - Basic 3
Some intuition is needed to find the location of the hidden password file. Requirements: Basic HTML knowledge
- Sep 08 Fri 2017 09:45
Hack This Site - Basic 2
slightly more difficult challenge, involving an incomplete password script. Requirements: Common sense.
- Sep 08 Fri 2017 09:43
Hack This Site - Basic 1
- Jan 31 Tue 2017 02:02
PentesterLab - Code injection (*Ex3)
- Jan 30 Mon 2017 20:00
PentesterLab - File Include (*Ex 2)
- Jan 24 Tue 2017 04:00
PentesterLab - XML attacks
- Jan 23 Mon 2017 20:47
PentesterLab - Commands injection
- Jan 22 Sun 2017 13:54
PentesterLab - SQL injections
- Jan 22 Sun 2017 13:00
PentesterLab - Directory traversal
- Jan 22 Sun 2017 04:00
PentesterLab - File Upload
- Jan 22 Sun 2017 00:29
PentesterLab - LDAP attacks
- Jan 21 Sat 2017 22:00
PentesterLab - XSS