Advertisement
Guest User

Untitled

a guest
Oct 13th, 2016
57
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.42 KB | None | 0 0
  1. My IP: 107.77.210.189
  2.  
  3. Leviathan1:rioGegei8m
  4. Leviathan2:ougahZi8Ta
  5. Leviathan3:Ahdiemoo1j
  6.  
  7. For your convenience we have installed a few usefull tools which you can find
  8. in the following locations:
  9.  
  10. * peda (https://github.com/longld/peda.git) in /usr/local/peda/
  11. * gdbinit (https://github.com/gdbinit/Gdbinit) in /
  12. * pwntools (https://github.com/Gallopsled/pwntools) in /usr/src/pwntools/
  13. * radare2 (http://www.radare.org/) should be in $PATH
  14.  
  15.  
  16.  
  17. usr/local/gdbinit/
  18.  
  19.  
  20. Natas
  21.  
  22. Natas teaches the basics of serverside web-security.
  23.  
  24. Each level of natas consists of its own website located at http://natasX.natas.labs.overthewire.org, where X is the level number. There is no SSH login. To access a level, enter the username for that level (e.g. natas0 for level 0) and its password.
  25.  
  26. Each level has access to the password of the next level. Your job is to somehow obtain that next password and level up. All passwords are also stored in /etc/natas_webpass/. E.g. the password for natas5 is stored in the file /etc/natas_webpass/natas5 and only readable by natas4 and na
  27.  
  28.  
  29. http://natas0.natas.labs.overthewire.org
  30. <!--The password for natas1 is gtVrDuiDfck831PqWsLEZy5gyDz1clto -->
  31. <!--The password for natas2 is ZluruAthQk7Q2MqmDeTiUij2ZvWy2mBi -->
  32.  
  33. # username:password
  34. alice:BYNdCesZqW
  35. bob:jw2ueICLvT
  36. charlie:G5vCxkVV3m
  37. natas3:sJIJNW6ucpu6HPZ1ZAchaDtwd7oGrD14
  38. eve:zo4mJWyNj2
  39. mallory:9urtcpzBmH
  40.  
  41.  
  42.  
  43. natas4:Z9tkRkWmpt9Qr7XrR5jWRkgOU901swEZ
  44.  
  45.  
  46. Access granted. The password for natas5 is iX6IOfmpN7AYOQGPwtn3fXpbaJVJcHfq
  47.  
  48. Access granted. The password for natas6 is aGoY4q2Dc6MgDq4oL4YtoKtyAg9PeHa1</div>
  49.  
  50. <?
  51. $secret = "FOEIUWGHFEEUHOFUOIU";
  52. ?>
  53.  
  54. Access granted. The password for natas7 is 7z3hEENjQtflzgnT29q7wAvMNfZdh0i9
  55.  
  56. Natas8:DBfUBfqQG69KvJvJ1iAbMoIpwSNQ9bWe
  57. --->Secret is oubWYf2kBq
  58.  
  59. Access granted. The password for natas9 is W0mMhUcRRnG8dcghE4qvk3JA9lGt8nDl
  60.  
  61.  
  62. natas10:nOpp1igQAkUzaI1GUUjzn1bFVj7xCNzu
  63.  
  64. /etc/natas_webpass/natas11:U82q5TCMMQ9xuFoI3dYX61s7OZD9JKoK
  65.  
  66. The password for natas12 is EDXp0pS26wLKHZy1rDBPUZk0RKfLGIR3
  67.  
  68. Natas13:jmLTY0qiPZBbaKc9341cqPQZBJv7MQbY
  69.  
  70. Natas14:ÿØÿà Lg96M10TdfaPyVBkJdjymbllQ5L6qdl1
  71.  
  72.  
  73. SELECT * from users where username=\"".$_REQUEST["username"]."\" and password=\"".$_REQUEST["password"]."\"
  74.  
  75. Successful login! The password for natas15 is AwWj0w5cvxrZiONgZ9J5stNVkmxdk39J
  76.  
  77. " OR 9=9; SELECT * FROM users INTO OUTFILE '/var/www/html/orders.txt'--
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement