Bitcoin Forum
June 17, 2024, 06:48:56 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 [4]  All
  Print  
Author Topic: [SOLVED] satoshihack.com - hack the 0.1 BTC reward! - ROUND NR 3  (Read 3733 times)
ndnh
Legendary
*
Offline Offline

Activity: 1302
Merit: 1005


New Decentralized Nuclear Hobbit


View Profile
April 05, 2015, 05:07:07 PM
 #61

lol, came back online for another round and gone! Smiley
Congratz to injust Cheesy

Can someone share the lvl5 answer? (leave lvl 6 in suspense Wink)

piCube got first the hash...

I decrypted to cryptoanarchist

and Injust added the 333 =)))


=> Was a team work Smiley)

It certainly says solved by Injust...
Anyway, level 6 is pretty easy If I get that string it is over Wink .

I don't really get the lvl 5 part...

Who cracked lvl 5? (I think Injust did that)
Injust
Legendary
*
Offline Offline

Activity: 1008
Merit: 1000



View Profile
April 05, 2015, 05:52:37 PM
 #62

lol, came back online for another round and gone! Smiley
Congratz to injust Cheesy

Can someone share the lvl5 answer? (leave lvl 6 in suspense Wink)

piCube got first the hash...

I decrypted to cryptoanarchist

and Injust added the 333 =)))


=> Was a team work Smiley)

It certainly says solved by Injust...
Anyway, level 6 is pretty easy If I get that string it is over Wink .

I don't really get the lvl 5 part...

Who cracked lvl 5? (I think Injust did that)

Here's the entire backstory. I couldn't, for the life of me, get past level 4. I know, I'm dumb Roll Eyes
So when ca333 posted the "Only when you are from NSA, you can enter lvl6..." hint, I immediately thought of HTTP referers, even though I hadn't made it past level 4 yet.
So I asked piCube to test it, setting the HTTP referer to NSA's website. And it worked. Because according to the HTTP referer, you're are going to the site "from" the NSA.
So piCube practically gave me the answer for level 4, and while I was getting an extension to change HTTP referers, piCube posted the hash that you get in level 6.
I put the hash through CrackStation, gave a partial match. I compared md5(cryptoanarchist) with the hash, found that the only thing different was the 333 at the end, so the answer was cryptoanarchist333.
ca333 (OP)
Hero Member
*****
Offline Offline

Activity: 520
Merit: 522


Developer - EthicHacker - BTC enthusiast


View Profile
April 05, 2015, 05:55:03 PM
 #63

lol, came back online for another round and gone! Smiley
Congratz to injust Cheesy

Can someone share the lvl5 answer? (leave lvl 6 in suspense Wink)

piCube got first the hash...

I decrypted to cryptoanarchist

and Injust added the 333 =)))


=> Was a team work Smiley)

It certainly says solved by Injust...
Anyway, level 6 is pretty easy If I get that string it is over Wink .

I don't really get the lvl 5 part...

Who cracked lvl 5? (I think Injust did that)

piCube and Injust noticed referer-manipulation and are ONLY who reach lvl6. Injust provided complete decrypted code first. biCube posted md5-hash in IRC first. But like old hackathons it only count who post the FULL solution. We (me and injust) gave advice to piCube so to not post hashs from the hackathon public before its not solved fully.

Explaining Level 5:
Level 5 check your HTTP-Header. the lvl5 look for your "HTTP-REFERER". this is php object from SERVER-Data array what your client send in the http-packet. So now my lvl5-site look for your referer information. In example when you look many otherside check your referer data for marketing, log, statistics, .... Also advertisin-company (web advertisement banners, links,...) check the referer.. Now you must "fake" the referer and write data into this element. Here its the URL of NSA-website. you can in example make this with "curl". This is a commandline tool you can write
Code:
curl --referer http://www.thesiteyouCOMEFROM.com http://www.thesiteyouwantTHEDATAFRom.com/

now curl loads the data from http://www.thesiteyouwantTHEDATAFRom.com/ and when this site check the referer in your client information then it gets http://www.thesiteyouCOMEFROM.com. So the site think you COME FROM http://www.thesiteyouCOMEFROM.com. And in level5 the site let you then enter level 6 automatical.

other option: you can also use browser-plugins for header-manipulation and modification. this exist for many web-browser. i.e. mozilla firefox, google chrome you can google and you find lot of web-debug addons. So you can change the http-referer also here.

this space is available (free) for humanitarian nonprofit organizations - please contact me
ndnh
Legendary
*
Offline Offline

Activity: 1302
Merit: 1005


New Decentralized Nuclear Hobbit


View Profile
April 05, 2015, 06:26:53 PM
 #64

piCube and Injust noticed referer-manipulation and are ONLY who reach lvl6. Injust provided complete decrypted code first. biCube posted md5-hash in IRC first. But like old hackathons it only count who post the FULL solution. We (me and injust) gave advice to piCube so to not post hashs from the hackathon public before its not solved fully.

Explaining Level 5:
Level 5 check your HTTP-Header. the lvl5 look for your "HTTP-REFERER". this is php object from SERVER-Data array what your client send in the http-packet. So now my lvl5-site look for your referer information. In example when you look many otherside check your referer data for marketing, log, statistics, .... Also advertisin-company (web advertisement banners, links,...) check the referer.. Now you must "fake" the referer and write data into this element. Here its the URL of NSA-website. you can in example make this with "curl". This is a commandline tool you can write
Code:
curl --referer http://www.thesiteyouCOMEFROM.com http://www.thesiteyouwantTHEDATAFRom.com/

now curl loads the data from http://www.thesiteyouwantTHEDATAFRom.com/ and when this site check the referer in your client information then it gets http://www.thesiteyouCOMEFROM.com. So the site think you COME FROM http://www.thesiteyouCOMEFROM.com. And in level5 the site let you then enter level 6 automatical.

other option: you can also use browser-plugins for header-manipulation and modification. this exist for many web-browser. i.e. mozilla firefox, google chrome you can google and you find lot of web-debug addons. So you can change the http-referer also here.


Thanks Smiley

I am looking for a chrome extension now.. I tried to read it up from stackoverflow. I understand the concept. Only don't know how to change it.

Thanks for posting all that information. Cheesy
ndnh
Legendary
*
Offline Offline

Activity: 1302
Merit: 1005


New Decentralized Nuclear Hobbit


View Profile
April 05, 2015, 06:28:48 PM
 #65

Here's the entire backstory. I couldn't, for the life of me, get past level 4. I know, I'm dumb Roll Eyes
So when ca333 posted the "Only when you are from NSA, you can enter lvl6..." hint, I immediately thought of HTTP referers, even though I hadn't made it past level 4 yet.
So I asked piCube to test it, setting the HTTP referer to NSA's website. And it worked. Because according to the HTTP referer, you're are going to the site "from" the NSA.
So piCube practically gave me the answer for level 4, and while I was getting an extension to change HTTP referers, piCube posted the hash that you get in level 6.
I put the hash through CrackStation, gave a partial match. I compared md5(cryptoanarchist) with the hash, found that the only thing different was the 333 at the end, so the answer was cryptoanarchist333.

lol, you lucky guy. Tongue
Next time I get a hash I will keep it a secret. Wink
Injust
Legendary
*
Offline Offline

Activity: 1008
Merit: 1000



View Profile
April 05, 2015, 10:22:00 PM
 #66

I am adding another 5000MUE to the winner. Good Luck!

I have received the 5000 MUE from upgradeadvice.
Thanks!
DougB62
Hero Member
*****
Offline Offline

Activity: 672
Merit: 500


Banned: For Your Protection


View Profile
April 06, 2015, 02:39:21 AM
 #67

Wow! Glad everyone had fun - I somehow COMPLETELY forgot, and missed it all! lol!  Undecided
Darkblock
Full Member
***
Offline Offline

Activity: 124
Merit: 100


photo taken by ESSA-7 satelite. 1968


View Profile
April 06, 2015, 10:28:23 AM
 #68

Wow! Glad everyone had fun - I somehow COMPLETELY forgot, and missed it all! lol!  Undecided

same here. I even had a reminder on my phone but didn't manage to get up before it was solved. Sad  well, lets make sure we ll join the next one. seems a pretty funny challange. Congratz to the winner btw.
zen2
Full Member
***
Offline Offline

Activity: 155
Merit: 100



View Profile
April 06, 2015, 11:24:18 AM
 #69

gratulation for the winner! i was stuck in level 3 and when i solved it the hackathon is already hacked. but it was awesome! very nice. next time i try it again.
maybe one day i reach last level. Smiley
jorgelugra
Member
**
Offline Offline

Activity: 266
Merit: 10


View Profile
April 08, 2015, 04:21:52 AM
 #70

damn i have lost two hackatons since the last, i was absent Sad, and i notice that injust its very advanced in this area Sad congratulations man you rocks again!
DougB62
Hero Member
*****
Offline Offline

Activity: 672
Merit: 500


Banned: For Your Protection


View Profile
April 25, 2015, 01:43:11 AM
 #71

Is there going to be any more of these upcoming, or have I missed something?
ca333 (OP)
Hero Member
*****
Offline Offline

Activity: 520
Merit: 522


Developer - EthicHacker - BTC enthusiast


View Profile
April 26, 2015, 08:10:39 AM
 #72

Is there going to be any more of these upcoming, or have I missed something?

no you have not missed it. more will come. i had a problem in RL so i am not able to do it. (https://bitcointalk.org/index.php?topic=993678.msg11061995#msg11061995)

the #4 hackathon is in preparation for the next days.
thank you!
ca333

this space is available (free) for humanitarian nonprofit organizations - please contact me
ndnh
Legendary
*
Offline Offline

Activity: 1302
Merit: 1005


New Decentralized Nuclear Hobbit


View Profile
April 26, 2015, 08:16:12 AM
 #73

Is there going to be any more of these upcoming, or have I missed something?

no you have not missed it. more will come. i had a problem in RL so i am not able to do it. (https://bitcointalk.org/index.php?topic=993678.msg11061995#msg11061995)

the #4 hackathon is in preparation for the next days.
thank you!
ca333

Same issues here. Don't bother. Launch it after 3 weeks, or so, when I get more time.  Grin
DougB62
Hero Member
*****
Offline Offline

Activity: 672
Merit: 500


Banned: For Your Protection


View Profile
April 26, 2015, 02:02:11 PM
 #74

Is there going to be any more of these upcoming, or have I missed something?

no you have not missed it. more will come. i had a problem in RL so i am not able to do it. (https://bitcointalk.org/index.php?topic=993678.msg11061995#msg11061995)

the #4 hackathon is in preparation for the next days.
thank you!
ca333

Ah, I see. Speedy healing to you! Looking forward to it when you are able.  Wink
ca333 (OP)
Hero Member
*****
Offline Offline

Activity: 520
Merit: 522


Developer - EthicHacker - BTC enthusiast


View Profile
April 28, 2015, 03:52:12 PM
 #75

Is there going to be any more of these upcoming, or have I missed something?

no you have not missed it. more will come. i had a problem in RL so i am not able to do it. (https://bitcointalk.org/index.php?topic=993678.msg11061995#msg11061995)

the #4 hackathon is in preparation for the next days.
thank you!
ca333

Same issues here. Don't bother. Launch it after 3 weeks, or so, when I get more time.  Grin

Smiley prepare and make yourself ready for this weekend.

Is there going to be any more of these upcoming, or have I missed something?

no you have not missed it. more will come. i had a problem in RL so i am not able to do it. (https://bitcointalk.org/index.php?topic=993678.msg11061995#msg11061995)

the #4 hackathon is in preparation for the next days.
thank you!
ca333

Ah, I see. Speedy healing to you! Looking forward to it when you are able.  Wink

thank you! i have finished it and will publish the hackathon the coming weekend. The countdown on the site is now accurate.

this space is available (free) for humanitarian nonprofit organizations - please contact me
DougB62
Hero Member
*****
Offline Offline

Activity: 672
Merit: 500


Banned: For Your Protection


View Profile
April 28, 2015, 04:33:12 PM
 #76


thank you! i have finished it and will publish the hackathon the coming weekend. The countdown on the site is now accurate.

Great! Looking forward to it!
Pages: « 1 2 3 [4]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!