HackThisSite Basic Missions 8

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
1,796
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Aug 9, 2009

HackThisSite Basic Missions 8.
The password is yet again hidden in an unknown file. Sam's daughter has begun learning PHP, and has a small script to demonstrate her knowledge.

Requirements: Knowledge of SSI (dynamic html executed by the server, rather than the browser)

Sam remains confident that an obscured password file is still the best idea, but he screwed up with the calendar program. Sam has saved the unencrypted password file in /var/www/hackthissite.org/html/missions/basic/8/
However, Sam's young daughter Stephanie has just learned to program in PHP. She's talented for her age, but she knows nothing about security. She recently learned about saving files, and she wrote an script to demonstrate her ability.

The SSI really inspired me.
SSI: Server Side Includes are directives, placed in HTML pages and evaluated on the server while the pages are being served. It lets you add dynamically generated content to an existing html page.

As you see our code in the video. It executes the Unix date command using the shell and it displays the result of the ls command.

As we have seen before, the Unix LS command lists the files in the current directory.

The SSI Exec command inserts the output from a CGI script or a shell command in the document.

For any help, contact me.

Category:

Entertainment

Tags:

License:

Standard YouTube License

  • likes, 0 dislikes

Link to this comment:

Share to:
see all

All Comments (3)

Sign In or Sign Up now to post a comment!
  • Whats the song?

  • @jonhy794 you forgot the #

  • hmm it doesnt work for me ... it say this when i do that :If you are trying to use server side includes to solve the challenge, you are on the right track: but I have limited the commands allowed to ones relevant towards finding the password file for security reasons(because there will always be that one person who decides to execute some rather nasty commands). So please manipulate your code so that it is a little more pertaining to the level.

Loading...
Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more