UGN Security Forums
My ProfileMember DirectoryLogin
Search our ForumsView our FAQView our Site Rules
View our CalendarView our Active TopicsGo to our Main Page

UGN Security Store
 

Network Sites UGN Security, The GoNix Initiative, Elite Web Gamers, Back of the Web, EveryDay Helper, VNC Web Design & Development
Our Sponsors
Sponsor Advertisements



Sponsor Advertisements
Latest Postings
Graphics
by heathdyer
05/26/13 01:32 AM
Latest Reviews
Topic Options
Rate This Topic
#10304 - 06/11/04 02:49 AM Little Quiz
ninji1234 Offline
Junior Member

Registered: 06/10/04
Posts: 2
Loc: Afha
Hi there,
here is a little quiz for you, i hope you can break it out, enjoy.

Here we go:

It was known, that at one server (bolero) runs a program exchanging secret messages. The client file in order to use this service can be seen here client.c

The client muss type the username and one-time-password, which sent unencrypted and can not be used for the next time.

Meanwhile, part of the Authenticationscomponents from the server is known, and unfortunately only three are arrive with SMS, namely:

Code:
 #include <sys/socket.h> #include <netinet/in.h> #include <time.h> #define LISTENPORT 12012 #define MAXLINELEN 128 #define PASSLEN 32 void passwd_gen(char *pass) {int i; 
Code:
  return; } int main(int argc, char **argv) {int s; int client; struct sockaddr_in addr; socklen_t addrlen;char *str,*str2; FILE *sock;char password[PASSLEN];char line[MAXLINELEN];
Code:
 ;read(client,line,MAXLINELEN);if (strncmp (line,"USER QAEDA",10)) {fclose (sock);close (client);continue;}fflush (sock);fprintf(sock,"USER %s OK, SEND PASSWORD\n",line); 
The Mission:
The program in the server is vulnerable.
modify the client in order to get the secret message without any passwort

Top
Our Sponsors
Sponsor Advertisements



Sponsor Advertisements
#10305 - 06/11/04 04:10 AM Re: Little Quiz
jonconley Offline
UGN Super Poster

Registered: 10/08/02
Posts: 955
Loc: Merrill, IA, USA
Don't post topics in multiple forums.

Top
#10306 - 06/11/04 12:27 PM Re: Little Quiz
Ntd Offline
Member

Registered: 01/21/03
Posts: 217
Loc: Melbourne, Victoria, Australia
Oooo i love quizs, too bad i have no idea what to do. Could you some how do a goto and skip the password?

Top



Moderator:  Infinite 
Featured Member
Registered: 03/16/13
Posts: 5
Forum Stats
2200 Members
46 Forums
25369 Topics
60539 Posts

Max Online: 1567 @ 04/25/10 10:20 AM
Top Posters
UGN Security 18529
Gremelin 7192
§intå× 3255
SilentRage 1273
Ice 1146
pergesu 1136
Infinite 1041
jonconley 955
Girlie 908
unreal 860
Newest Members
heathdyer, Thes33ker, Selex, baird, colin
2200 Registered Users
Who's Online
0 registered (), 295 Guests and 294 Spiders online.
Key: Admin, Global Mod, Mod
Latest News


Donate
  Get Firefox!
Get FireFox!