Hack This Site.co.uk - Main 7
Objectives
The password is again stored in a txt file. This time however it is not as straight forward as viewing the source.
You wouldn't even find the page by using a search engine as search bots have been excluded.
Solution
Wooooop secret words in the hint **** seach bots have been exclude*******
alright kids we all know what search bots use right?
let's all say it at once
Robot.txt
that's right robots.txt. Good job kids lets see if we can use that to our advantage here with out digging into the source code at all
https://www.hackthis.co.uk/robots.txt
User-agent: *
Allow: /
Disallow: /contact.php
Disallow: /inbox/
Disallow: /levels/
Disallow: /levels/extras/userpass.txt
Disallow: /users/
Disallow: /ctf/8/php/*
User-agent: Mediapartners-Google
Disallow:
User-agent: Yahoo Pipes 1.0
Disallow: /
User-agent: KSCrawler
Disallow: /
User-agent: Spinn3r
Disallow: /
Sitemap: https://www.hackthis.co.uk/sitemap.xml
Dissalow:/levels/extras/userpass.txt looks interesting lets see whats there.
https://www.hackthis.co.uk/levels/extras/userpass.txt
48w3756
u3qh458
Great jobs kids. Remember to tune in next week for level 8
Objectives
The password is again stored in a txt file. This time however it is not as straight forward as viewing the source.
You wouldn't even find the page by using a search engine as search bots have been excluded.
Solution
Wooooop secret words in the hint **** seach bots have been exclude*******
alright kids we all know what search bots use right?
let's all say it at once
Robot.txt
that's right robots.txt. Good job kids lets see if we can use that to our advantage here with out digging into the source code at all
https://www.hackthis.co.uk/robots.txt
User-agent: *
Allow: /
Disallow: /contact.php
Disallow: /inbox/
Disallow: /levels/
Disallow: /levels/extras/userpass.txt
Disallow: /users/
Disallow: /ctf/8/php/*
User-agent: Mediapartners-Google
Disallow:
User-agent: Yahoo Pipes 1.0
Disallow: /
User-agent: KSCrawler
Disallow: /
User-agent: Spinn3r
Disallow: /
Sitemap: https://www.hackthis.co.uk/sitemap.xml
Dissalow:/levels/extras/userpass.txt looks interesting lets see whats there.
https://www.hackthis.co.uk/levels/extras/userpass.txt
48w3756
u3qh458
Great jobs kids. Remember to tune in next week for level 8
Comments
Post a Comment