Username: 
Password: 
Restrict session to IP 

Challenge: A Black Hats Tale  Go to the A Black Hats Tale challenge

1 2 3
Global Rank: 158
Totalscore: 114684
Posts: 166
Thanks: 158
UpVotes: 114
Registered: 12y 95d
Z`s Avatar



Last Seen: 226d 22h
The User is Offline
Challenge: A Black Hats Tale
Google/translate1Thank You!1Good Post!0Bad Post! link
Some hints regarding the challenge:

If you receive "Login failed, invalid username or password." this means that your reply has been timed out.

Regarding the last part (the challenge is a 3 part ), it looks like that in case of some tools, time zones matters. I have created this challenge in CET/CEST timezone. If you still can't get the right solution, please contact me.

For the token code challenge, a hint:
779286 - from Fri Jul 27 14:23:00 2012 to Fri Jul 27 14:23:59 2012
XXXXX - from Fri Jul 27 14:24:00 2012 to Fri Jul 27 14:24:59 2012 ---> this is the solution
440866 - from Fri Jul 27 14:25:00 2012 to Fri Jul 27 14:25:59 2012

GreetZ and happy challenging
Last edited by Z - Nov 03, 2015 - 15:01:27
Global Rank: 158
Totalscore: 114684
Posts: 166
Thanks: 158
UpVotes: 114
Registered: 12y 95d
Z`s Avatar



Last Seen: 226d 22h
The User is Offline
Challenge: A Black Hats Tale
Google/translate1Thank You!1Good Post!1Bad Post! link
And another important thing regarding the last part:
If you have found a c source code where you have to enter the current token code displayed, than either you have to search for another tool, or you have to modify it.
Totalscore: 335294
Posts: 107
Thanks: 151
UpVotes: 91
Registered: 12y 46d
Jinx`s Avatar










The User is Offline
Challenge: A Black Hats Tale
Google/translate1Thank You!1Good Post!1Bad Post! link
Hello,
Which C-sourcecode are you talking about? Am I missing something?
I'm totally clueless about the 3rd part. I have the given .asc file and that's all.
Global Rank: 158
Totalscore: 114684
Posts: 166
Thanks: 158
UpVotes: 114
Registered: 12y 95d
Z`s Avatar



Last Seen: 226d 22h
The User is Offline
Challenge: A Black Hats Tale
Google/translate1Thank You!1Good Post!0Bad Post! link
The 3.rd part is about to google a tool for this one time password thingy. There are some c codes, but not every is suitable for this challenge, and there is also a general purpose windows hacking program, where the older versions are known to working for this challenge. And you have to know what PSA InSecurID means...
Global Rank: 604
Totalscore: 38383
Posts: 18
Thanks: 12
UpVotes: 7
Registered: 12y 20d


The User is Offline
Challenge: A Black Hats Tale
Google/translate1Thank You!0Good Post!1Bad Post! link
PSA InSecurID is really, really clear. Just change/remove a few letters and it's obvious. I have that code you were talking about, yes, it is useless (unfortunately).

Perhaps you could give a clue about that general purpose windows hacking program. Windows hacking is either obtaining/cracking LM/NT hashes (which is obviously not related to this challenge) or ?Rem*Desk*Con*? hacking?
Global Rank: 158
Totalscore: 114684
Posts: 166
Thanks: 158
UpVotes: 114
Registered: 12y 95d
Z`s Avatar



Last Seen: 226d 22h
The User is Offline
Challenge: A Black Hats Tale
Google/translate1Thank You!0Good Post!1Bad Post! link
The general purpose windows hacking program is called **i* from **i*.it Smile
Global Rank: 604
Totalscore: 38383
Posts: 18
Thanks: 12
UpVotes: 7
Registered: 12y 20d


The User is Offline
Challenge: A Black Hats Tale
Google/translate1Thank You!0Good Post!1Bad Post! link
Even though your hint is... Disturbing... I probably know what is that "general purpose windows hacking program". Isn't that supposed to be **i******? (not one word), seeing what data is given.

EDIT: yes, I was right, thanks for the hint anyway (it helped to ensure THAT was the right tool) ;)
Last edited by WingeDD - Jul 21, 2009 - 10:07:13
Global Rank: 158
Totalscore: 114684
Posts: 166
Thanks: 158
UpVotes: 114
Registered: 12y 95d
Z`s Avatar



Last Seen: 226d 22h
The User is Offline
Challenge: A Black Hats Tale
Google/translate1Thank You!0Good Post!1Bad Post! link
Yes, it is **i* * **** but you dont need the * **** part Smile
Totalscore: 335294
Posts: 107
Thanks: 151
UpVotes: 91
Registered: 12y 46d
Jinx`s Avatar










The User is Offline
Challenge: A Black Hats Tale
Google/translate1Thank You!0Good Post!1Bad Post! link
I found the program to calculate it. Runs fine. But it looks like I've got a newer version of it..
I put everything which is given into the program, but don't get the correct number O_o
It's calculating the correct numbers to my input. It looks like, that it's only calculating the numbers for the new version of the chips ;-)
May I pm someone with my results please?

Last edited by Jinx - Jul 21, 2009 - 11:48:04
Global Rank: 604
Totalscore: 38383
Posts: 18
Thanks: 12
UpVotes: 7
Registered: 12y 20d


The User is Offline
Challenge: A Black Hats Tale
Google/translate1Thank You!0Good Post!1Bad Post! link
If you have used a too new version, it wouldn't even had allowed you to give the token/import .asc.
Are you sure you have set the correct date&time in the correct timezone?
1 2 3
hobbist, digitalseraphim, tunelko, Doantruongduy, Redknee, silenttrack, qdxy, n0tHappy, TheHiveMind, Z, Ge0, samuraiblanco, arraez, jcquinterov, hophuocthinh, alfamen2, burhanudinn123, Ben_Dover, stephanduran89, braddie0 have subscribed to this thread and receive emails on new posts.
1 people are watching the thread at the moment.
This thread has been viewed 38010 times.