Secure Room

User avatar
dj-boris
Posts: 3
Joined: Thu Dec 23, 2010 9:58 am

Post by dj-boris »

Jackpot, after trying and trying, I got it :-) , it needs just the right number of '
Thank you very much!
BlackShadow is watching you
bspus
Posts: 9
Joined: Sun Sep 04, 2011 5:16 pm

Post by bspus »

gfoot wrote:As the challenge description says, you have to log in as 'adum' in order to see his secrets.
I logged in as adum (and as someone else) and still get the no secrets treatment. I even got it to work with the user name field having just the word adum in it so that it will show properly on the next page.

I'm actually surprised this wasn't enough, not because it was hard but because I think I have done what I was required to do. What am I missing?
DaymItzJack
Posts: 106
Joined: Thu Oct 29, 2009 9:21 pm

Post by DaymItzJack »

bspus wrote:
gfoot wrote:As the challenge description says, you have to log in as 'adum' in order to see his secrets.
I logged in as adum (and as someone else) and still get the no secrets treatment. I even got it to work with the user name field having just the word adum in it so that it will show properly on the next page.

I'm actually surprised this wasn't enough, not because it was hard but because I think I have done what I was required to do. What am I missing?
I think the answer to this challenge is the password, not positive though, I solved it awhile ago.
bspus
Posts: 9
Joined: Sun Sep 04, 2011 5:16 pm

Post by bspus »

DaymItzJack wrote:I think the answer to this challenge is the password, not positive though, I solved it awhile ago.
Even if I got the password, I would expect to log in and see the same "you have no secrets" message.
Considering that the challenge tells you not to try to "guess the password" as well as the fact that it asks you to break into his account and discover his "secret", it would be very misleading.
DaymItzJack
Posts: 106
Joined: Thu Oct 29, 2009 9:21 pm

Post by DaymItzJack »

bspus wrote:
DaymItzJack wrote:I think the answer to this challenge is the password, not positive though, I solved it awhile ago.
Even if I got the password, I would expect to log in and see the same "you have no secrets" message.
Considering that the challenge tells you not to try to "guess the password" as well as the fact that it asks you to break into his account and discover his "secret", it would be very misleading.
I managed to log into adums account and the secret was right in front of me. I don't know exactly what you're doing but there aren't any tricks or anything.
bspus
Posts: 9
Joined: Sun Sep 04, 2011 5:16 pm

Post by bspus »

I got in too by trying something slightly different. The thing is, it should have worked with my first method.
I believe the reason is that this is not a real vulnerability but just an exercise. The "exploit" is expected so it's all just make believe.
I 'll make a post in the solved section at some point to discuss it further.

edit: nevermind. My other method works now too. I wonder if something is changed
Nquit
Posts: 5
Joined: Fri Jul 15, 2011 11:02 pm

Post by Nquit »

Aparently i must be stupid about Injections.. I can't get it to work.. and it's pissing me off.. Any who can help a nub?
Nquit
Posts: 5
Joined: Fri Jul 15, 2011 11:02 pm

Post by Nquit »

I finally made it.. QUite easy now that i see how it's done
Valar_Dragon
Posts: 21
Joined: Sun Jan 04, 2015 3:34 pm

Post by Valar_Dragon »

This is a great challenge! Once you figure it out it makes complete sense!
SevenPlath
Posts: 1
Joined: Mon Apr 11, 2022 4:23 am

Does Secure Room still work?

Post by SevenPlath »

Hello! I got 500 Internal Server Error when visiting http://www.adum.com/secureroom/
Is this challenge still running?
AMindForeverVoyaging
Forum Admin
Posts: 496
Joined: Sat May 28, 2011 9:14 am
Location: Germany

Post by AMindForeverVoyaging »

You can try to send a mail to: adum (at) adum (dot) com
Post Reply