Username: 
Password: 
Restrict session to IP 

Hash?  Go to the Railsbin challenge

Global Rank: 3128
Totalscore: 4649
Posts: 2
Thanks: 1
UpVotes: 1
Registered: 3y 215d
Last Seen: 108d 2h
The User is Offline
Hash?
Google/translate1Thank You!1Good Post!0Bad Post! link
It looks like I've found the salted hash in Blowfish format but it seems to be too short. Plus I've found 2 different versions of it.
Should I get it rather from DB by using SQL injection instead?
Last edited by bfumaster - Apr 27, 2018 - 17:40:06
Global Rank: 1
Totalscore: 719317
Posts: 380
Thanks: 406
UpVotes: 343
Registered: 9y 323d











The User is Offline
RE: Hash?
Google/translate1Thank You!1Good Post!0Bad Post! link
How to find it is the whole challenge.

As for the two versions, obviously someone else added a user with the same name, but I'm sure you can figure out which is the right one.
Global Rank: 3128
Totalscore: 4649
Posts: 2
Thanks: 1
UpVotes: 1
Registered: 3y 215d
Last Seen: 108d 2h
The User is Offline
RE: Hash?
Google/translate0Thank You!0Good Post!0Bad Post! link
I was not talking about two different users but 2 hash versions of the same user. Whatever.
Last edited by bfumaster - Apr 30, 2018 - 08:44:28
Global Rank: 1
Totalscore: 719317
Posts: 380
Thanks: 406
UpVotes: 343
Registered: 9y 323d











The User is Offline
RE: Hash?
Google/translate0Thank You!0Good Post!0Bad Post! link
Quote from bfumaster
Apr 30, 2018 - 08:42:20

Whatever.

That's the spirit...

I've had another look an it is indeed true that in some places different hashes are shown for the same user. This is due to some Rails magic in combination with bad coding.

As far as I can tell, if you find a way to get the full hash, you'll get the right one. So no need to worry about it at this stage.
Global Rank: 231
Totalscore: 84565
Posts: 1338
Thanks: 1188
UpVotes: 700
Registered: 11y 120d




Last Seen: 17m 44s
The User is Offline
RE: Hash?
Google/translate0Thank You!0Good Post!0Bad Post! link
Quote from dloser
Apr 30, 2018 - 15:07:12

Quote from bfumaster
Apr 30, 2018 - 08:42:20

Whatever.

That's the spirit...

I've had another look an it is indeed true that in some places different hashes are shown for the same user. This is due to some Rails magic in combination with bad coding.

As far as I can tell, if you find a way to get the full hash, you'll get the right one. So no need to worry about it at this stage.


Haha... "Rails magic and bad coding" does not involve @gizmore, right?
i only wrote like 5 lines for that railsbin app... Euh

Happy Hacking!
The geeks shall inherit the properties and methods of object earth.
Last edited by Gizmore - May 01, 2018 - 00:57:49
zM_, tunelko, silenttrack, qdxy, TheHiveMind, Z, Ge0, samuraiblanco, arraez, jcquinterov, hophuocthinh, alfamen2, burhanudinn123, Ben_Dover, stephanduran89 have subscribed to this thread and receive emails on new posts.
1 people are watching the thread at the moment.
This thread has been viewed 4387 times.