Fancy yourself as a hacker?

Fancy passing some time this Friday afternoon by testing your hacking skills? Go to the Starfleet Academy and see how far you get. I got as far as level 3, signed the guestbook, then got bored and gave up.

The lesson to be learnt is that JavaScript can not secure your webpages. Well, derrr...


    • Aden
    • Wed 4 Feb 2004 07:02

    Level 8?

    Am I missing something or is it a case of pure guess work.


    • Rob McDonagh
    • Wed 4 Feb 2004 07:12

    Hm. I got to level 8, but he seems to want you to guess the next URL to get to level 9. He's running IIS on the 'entry' pages (and apache on the scripted ones), so I guess you could try a known IIS exploit to crawl the site. I dunno. Too much effort, methinks...

    • Dibbo
    • Wed 4 Feb 2004 07:23

    ohhh..I got to level 5 in 20mins. I suppose not bad to say i've never tried to hack or used JavaScript in this way before.

  1. Erdinger has played a major part in my Friday afternoon - Level 4

    • me
    • Wed 4 Feb 2004 08:22

    just leave the file name off and it will give you a list of the directory structure (only works on that directory) which in turn will give you the file you want, keep going!! 11 is a swine

  2. I got to 6 and then had to get some work done - thanks for sharing the link!

    • Mark Gottschling
    • Wed 4 Feb 2004 09:08

    Completed 11. Level 12 is taking too much time up. Maybe i'll try later.

    • jerrith
    • Wed 4 Feb 2004 09:41

    Damned, I'm stuck at level 10. I can't find where the prompt comes from, since in the linked javascript there's only comments??

    • marcus
    • Wed 4 Feb 2004 13:03

    jerrith, i believe that's a riddle...

  3. This was fun. I got as far as level 7 but couldn't figure out how to go on.

    • Esther
    • Wed 4 Feb 2004 14:06

    OK, got to level 10 in about 15 minutes, but now absolutely stuck. I almost failed math, and I've been out of school many years - I can't remember stuff about prime numbers! I know that Erdos re-proved the theorem, but what now!?

    • Trent
    • Wed 4 Feb 2004 14:33

    It would be nice if you could go to each challenge directly instead of playing through ones you've already done.

    • Andrew Tetlaw
    • Wed 4 Feb 2004 14:49

    1. Don't use IE. This way you can view source easily because his right click protection only works for IE. Also in Moz you can execute JS in the JS Console, This makes getting around obfusication of the passwords easy.

    2. If you view source of the homepage you'll see this interesting JS:

    "if (document.referrer == '{Link}



    I guess he's hoping to put off people coming from that URL. Go to that url (www.7er-forum.com/forum/viewthread.php?tid=13456) and you'll see all the answers :P

    I think that deserves extra credit!!!

  4. Yeah -- #12 is the mean one, since knowing what the password evaluates to is not enough -- there are 36 combinations possible. You need a Java decompiler for #13. #14 is a simple alert() (and the answer on the banned site is wrong, BTW). #15 is the first "real" hack (get the .htaccess file), and that's about all the gaming I can take....

  5. Nah -- I couldn't stop. The last one needs "crypto quote" skills (everyone who rides a subway/tube should have those, right?) but the resulting, very simple, question needs a German answer. Ever notice that Babelfish never give you the right part of speech on a single-word translation?

    • Trent
    • Wed 4 Feb 2004 17:09

    I beat 10, but I have no idea how it works. I saved the page to my local drive and I could see the password. But viewing the source online just showed words about prime numbers.


    • Jerry Carter
    • Wed 4 Feb 2004 21:23

    I stopped after level 14. I didn't want to go after the .htaccess file... mainly because I don't have a clue how. :-)

    Btw, y'all, if you read the intro... giving away the secrets is vorbotten!!

    • Henk
    • Thu 4 Mar 2004 10:10

    I finally solved it! I spent hours on this while I should have been working. Thanks Jake! ;-)

    I learned a thing or two along the way, so it's not a complete waste of time.

    The last level is a nice puzzle. Hint: the only thing you need to know to solve it is that the text is in English. Enjoy!

    • Tom B
    • Thu 4 Mar 2004 22:53

    Made it to level 11 but but going further would take more time that I am willing to spend.

  6. Lots of things are verboten -- like hacking into obviously restricted areas. Since the whole premise of the game is purposeful breaking of rules, then any rules put in place are, by definition, invalid.

    For the last one, you also need to know that there is a mistake in the substitution code in the first word (depending on the order in which you solve the problem, it can make a difference).

    Trent -- for #10, it's not what you get, it's how you get it. Think about the HTTP request header, and what's in it.

    • Gareth Hay
    • Tue 4 May 2004 10:49

    For Andrew


    it makes IE open the page in notepad - also most right-click disablements don't work if they throw up a dialog.

    I'm sure you can keep the right mouse button down and press return and you will get the context menu.

    I got to level 8 then my boss wondered what I was doing :-S

  7. What a blast!

    I'm having Jerrith's problem on number 10. Even saving all the .js and .htm files on my comp, I still only see the comments... and I've tried it in IE, Firefox, and all sorts of text editors. LOL...

    • Charlotte
    • Fri 4 Jun 2004 04:15

    Gosh, I got past 5. :) I was threw off level 4. I'll try again when I have the time.

    • Jerrith
    • Fri 4 Jun 2004 04:38

    I used My Lotus Notes client to open the page for level 10 and then opened it in the Web database where the document is stored and voilà instant hack :)


    I'm now at level 13 where I need a way to download the java class so I can see what's in there :)

    • Flo
    • Sat 5 Jun 2004 16:34

    Stan, how do you view the .htaccess file?

    • Sumic
    • Mon 11 Oct 2004 19:01

    Can someoen help me get past level 3??? i can't figure it out. ppllleeeaaassseseee help me???

    • Viper
    • Fri 5 Nov 2004 05:57

    right click -save

    linkcolor is given

    don't you know html?

    • Viper
    • Fri 5 Nov 2004 06:01

    Level 10

    don't get it

    I know that the script file is a distraction

    And I know about the HTTP request header

    but just didn't get it...

  8. I got to level 40,

    quite simple if you ask me.

    wait till you see the pl.koij file.

    • fart pants
    • Thu 10 Feb 2005 19:28



    You'll need a decrypter for what's inside

    Google for John the Ripper

