490 likes | 706 Views
How to Hack The Box. A tutorial on how to get your login access code. Welcome to Hack The Box!. In this tutorial we will be using the Chrome web-browser installed on Windows 10 build 17063 or later. Open your Chrome web-browser and navigate to the website hackthebox.eu .
E N D
How to Hack The Box A tutorial on how to get your login access code
Welcome to Hack The Box! In this tutorial we will be using the Chrome web-browser installed on Windows 10 build 17063 or later.
Open your Chrome web-browser and navigate to the website hackthebox.eu. Click on the link titled individuals.
This is the invite page. As you can see, we need an invite code, but how do we get it?
Step 1 Right-click on the page and select Inspect, from the drop-down menu.
Step 2 This brings up the Chrome development tools window. Looking through the code in the Elements tab, we see something interesting. /js/inviteapi.min.js To see what this is, let us go to hackthebox.eu/js/inviteapi.min.js
Step 3 This brings up a page with more code on it. Looking through this code we see makeInviteCode. We can use this information along with Chrome Dev Tools to make an invite code.
Step 4 On the Chrome Dev Tools page, go to the Console tab. At the bottom, we are going to type in makeInviteCode() and hit enter.
Step 5 We successfully found some information! This information will be different for every person. Use the arrows to open the information as shown in the picture by first clicking the arrow next to the initial line, and then the arrow next to data. As you can see, the data is encoded, but it tells us the encoding type right under the data. In this case, it uses ROT13. I have also seen it use BASE64. Use google to find a website to decode this message based on your encoding type. ROT13: https://cryptii.com/pipes/rot13-decoder BASE64: https://www.base64decode.org/
Step 6 After decoding the message, you should get the following plain text: In order to generate the invite code, make a POST request to /api/invite/generate
Step 7 To make a POST request, we are going to use the cURL command in the windows command prompt. Open the windows command prompt by searching for cmd in windows.
Step 8 After opening the windows command prompt. Type the command bellow and hit enter: curl –XPOST https://hackthebox.eu/api/invite/generate Again we get information that is encoded. This time it looks like it is in BASE64. As before, this information will be different for every person. Note: cURL is installed by default on Windows 10 build 17063 or later. It can be manually installed if you’re on an earlier version.
Step 9 Decoding QkpRWlItTEZVR1QtWUFRVFUtWVRBWEQtRFpTSUI= Resulted in the following unique code BJQZR-LFUGT-YAQTU-YTAXD-DZSIB
Step 10 Return to hackthebox.eu/invite and enter your unique code in the invite code box. Then click sign up.
Step 11 Enter your information to register your account.