My personal favorite category, hack 'n slash your way through 3 completely insecure sites and gain complete control over them using your web techniques.
mission: steal the Livebox router data, the mission itself can be found here.
Dear fWWWiWWWnWWWiWWWsWWWhWWWeWWWd,
I have a mission for you, I'd like to join a hackers group called EvilHackersCrew, they are pretty
infamous on the Internet and wrote their own linux distro(EHCOS), they challenged me to download a file from
a share on their wireless local network after that they make me member.
Sadly I'm only good at decompiling software, and not in this branch of the hacking scene.
Now I have an idea, and am pretty sure it will work out, one of the members is my neighbour he has a WLAN,
it's protected with mac filtering and a wep key, he also hosts their webserver and a cvs server as well (used for their linux distro).
A rather funny detail is that the crew has a page on this webserver that redirects members
to different parts of the site depending on the ip-address that visits this page.
One of the ip-address ranges redirects to the router of my neighbour's network, and that's where it gets interesting.
They gave me these clues:
- I need an ip-address in the range between 200-212(.***.***.***)
- The last clue leaves me clueless, they say that I can only get access to the site if my OS is their's,
how can I use their own OS if I don't have access to their software???
Maybe you can steal information from their router to gain access to their network share, if so I'll need following:
- the mac-address that has access to the WLAN
- wep key
- broadcast id
To gain these you'll need to login to the router, I haven't got an idea which username or password is used though.
PS) Please don't tell these guys!