Saturday, September 30, 2017

VulnHub - GameOver vm - Hackademic_Challenges - challenge 010

The last challenge was in regards to bypassing the Login screen, getting a serial number and becoming a member of a hacker team.

I intercepted the page with BurpSuite and before Forwarding it, I modified the Login information from False to True, and the password of 'LetMeIn' (found in the source code of the page, but did not see it anywhere on the page, so it was suspect to me...) .

I was redirected to a webpage with a javascript pop-up, with the text:
%53%65%72%69%61%6C%20%4E%75%6D%62%65%72%3A%20%54%52%56%4E%2D%36%37%51%32%2D%52%55%39%38%2D%35%34%36%46%2D%48%31%5A%54

, that I ended up converting to a serial number of:
Serial Number: TRVN-67Q2-RU98-546F-H1ZT

After clicking OK, I was redirected to a logon page with a populated email for r00t@n1nj4h4x0rzcrew.com , filled out the empty spaces, and received:



The End....

0 comments:

Post a Comment

About Us