<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: HTS Basic Web 9: Directory Transversal</title>
	<atom:link href="http://timjoh.com/hts-basic-web-9-directory-transversal/feed/" rel="self" type="application/rss+xml" />
	<link>http://timjoh.com/hts-basic-web-9-directory-transversal/</link>
	<description>Code, games, chess and everything but the kitchen sink</description>
	<pubDate>Wed, 19 Nov 2008 21:49:06 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: nooneatall</title>
		<link>http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-88773</link>
		<dc:creator>nooneatall</dc:creator>
		<pubDate>Sat, 20 Sep 2008 11:20:33 +0000</pubDate>
		<guid isPermaLink="false">http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-88773</guid>
		<description>type this in on level 8 challenge to get the level 9 password:

&lt;!--#exec cmd="ls ../../9"--&gt;</description>
		<content:encoded><![CDATA[<p>type this in on level 8 challenge to get the level 9 password:</p>
<p><!--#exec cmd="ls ../../9"--></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-88772</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sat, 20 Sep 2008 11:19:39 +0000</pubDate>
		<guid isPermaLink="false">http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-88772</guid>
		<description>type this in on level 8 challenge to get the level 9 password:

&lt;!--#exec cmd="ls ../../9"--&gt;</description>
		<content:encoded><![CDATA[<p>type this in on level 8 challenge to get the level 9 password:</p>
<p><!--#exec cmd="ls ../../9"--></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zyriab</title>
		<link>http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-88763</link>
		<dc:creator>zyriab</dc:creator>
		<pubDate>Sat, 20 Sep 2008 10:03:10 +0000</pubDate>
		<guid isPermaLink="false">http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-88763</guid>
		<description>It's really annoying not to be able to use all possible commands, I've tried "ls ~/******/***/*" which should do the same as the allowed answer but I couldn't go any further because I get that this command was not allowed.</description>
		<content:encoded><![CDATA[<p>It&#8217;s really annoying not to be able to use all possible commands, I&#8217;ve tried &#8220;ls ~/******/***/*&#8221; which should do the same as the allowed answer but I couldn&#8217;t go any further because I get that this command was not allowed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy</title>
		<link>http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-70500</link>
		<dc:creator>Andy</dc:creator>
		<pubDate>Tue, 20 May 2008 13:27:59 +0000</pubDate>
		<guid isPermaLink="false">http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-70500</guid>
		<description>Am i missing something here, on the blog i see
In the last mission, you entered the following in the name field:


Which, with .., goes down one step from 




What did we enter in the name field? every bit of code seems to be gone from this blog and the comments so it doesn't really make a lot of sense to me</description>
		<content:encoded><![CDATA[<p>Am i missing something here, on the blog i see<br />
In the last mission, you entered the following in the name field:</p>
<p>Which, with .., goes down one step from </p>
<p>What did we enter in the name field? every bit of code seems to be gone from this blog and the comments so it doesn&#8217;t really make a lot of sense to me</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WhoCARESS</title>
		<link>http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-63164</link>
		<dc:creator>WhoCARESS</dc:creator>
		<pubDate>Fri, 18 Apr 2008 16:57:36 +0000</pubDate>
		<guid isPermaLink="false">http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-63164</guid>
		<description>blast... I had an entire different logic when trying to solve mission 9. i thought he had an regex like /&lt;!--\s*#exec cmd="ls (?:..)?"\s*--&gt;/ and I tried all sort of stuff to bypass or fool that match so I can execute 2 SSI commands with one having an ..\.. . Guess this was easier in the end and I just deviated like hell from the answer. THIS LAST DAMNED MISSION TOOK LONGER THEN ALL THE OTHERS SUMED.</description>
		<content:encoded><![CDATA[<p>blast&#8230; I had an entire different logic when trying to solve mission 9. i thought he had an regex like /<!--\s*#exec cmd="ls (?:..)?"\s*-->/ and I tried all sort of stuff to bypass or fool that match so I can execute 2 SSI commands with one having an ..\.. . Guess this was easier in the end and I just deviated like hell from the answer. THIS LAST DAMNED MISSION TOOK LONGER THEN ALL THE OTHERS SUMED.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-55373</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sat, 15 Mar 2008 15:04:09 +0000</pubDate>
		<guid isPermaLink="false">http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-55373</guid>
		<description>why do i hafto put ../../9 to go p a directory????</description>
		<content:encoded><![CDATA[<p>why do i hafto put ../../9 to go p a directory????</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: blarg</title>
		<link>http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-52510</link>
		<dc:creator>blarg</dc:creator>
		<pubDate>Fri, 29 Feb 2008 06:17:53 +0000</pubDate>
		<guid isPermaLink="false">http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-52510</guid>
		<description>how can you get 8 but not 9.
nine is easier than eight i think, and yeah +1 about level 10</description>
		<content:encoded><![CDATA[<p>how can you get 8 but not 9.<br />
nine is easier than eight i think, and yeah +1 about level 10</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-50317</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sun, 17 Feb 2008 16:22:10 +0000</pubDate>
		<guid isPermaLink="false">http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-50317</guid>
		<description>The claim that the script rejected all but two values is what threw me; this is dimply not the case.</description>
		<content:encoded><![CDATA[<p>The claim that the script rejected all but two values is what threw me; this is dimply not the case.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ash</title>
		<link>http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-30923</link>
		<dc:creator>Ash</dc:creator>
		<pubDate>Mon, 22 Oct 2007 00:45:17 +0000</pubDate>
		<guid isPermaLink="false">http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-30923</guid>
		<description>LvL 10 basic being solved by anyone?</description>
		<content:encoded><![CDATA[<p>LvL 10 basic being solved by anyone?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Orc4</title>
		<link>http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-26602</link>
		<dc:creator>Orc4</dc:creator>
		<pubDate>Mon, 24 Sep 2007 00:04:19 +0000</pubDate>
		<guid isPermaLink="false">http://timjoh.com/hts-basic-web-9-directory-transversal/#comment-26602</guid>
		<description>Ha...actually this quite easy...if we ever try to search file with nasty way...we already feel that we are in the rigth path...we just need to know that level 8 is corelatted with level 9, thank's to Timjoh..i feel more confidence with my decicion in solving HTS basic 9...
1.In Basic 8 &#62;&#62; Name : &lt;!--#exec cmd="ls     /home/xec96/public_html/missions/basic/9"--&gt;
2.http://www.hackthissite.org/missions/basic/9/p91e283zc3.php
3.eureka....Got the password</description>
		<content:encoded><![CDATA[<p>Ha&#8230;actually this quite easy&#8230;if we ever try to search file with nasty way&#8230;we already feel that we are in the rigth path&#8230;we just need to know that level 8 is corelatted with level 9, thank&#8217;s to Timjoh..i feel more confidence with my decicion in solving HTS basic 9&#8230;<br />
1.In Basic 8 &gt;&gt; Name : <!--#exec cmd="ls     /home/xec96/public_html/missions/basic/9"--><br />
2.http://www.hackthissite.org/missions/basic/9/p91e283zc3.php<br />
3.eureka&#8230;.Got the password</p>
]]></content:encoded>
	</item>
</channel>
</rss>
