<HTML>
<HEAD>
<meta name="robots" content="noindex,nofollow">
<SCRIPT LANGUAGE="JavaScript">
<!-- Hide from JavaScript-Impaired Browsers
al="`1234567890-=~!@#$%^&*()_+qwei"
+"fyutop[]QWERTYUIOP{}|oeeiflryt;A"
+"ASYENDKQ:ajeeurj,./ZXCVBNM<>c?";
bctr=0;
count=0;
function ckPwd()
{
tst=document.isn.username.value+"-"+document.isn.passwrd.value+"-"; //verbindet user und passw
ls=document.pd.pe.value; //ls wird zu der unten stehen zahl
a=eval(ls.substring(0,2))-91; //a = 99- 91=8
ls=ls.substring(2,ls.length); //ls = wird um die ersten beiden Zeichen gekürzt
nls=""; //nls= definiert
flg=0; //Ob man den code geknackt hat oder net
ab=eval(ls.substring(0,2))-93; //ab = 98-93 = 5
while (ls.length>28)
{
ab1=( ab1=="" ? ""+ab:ab1); //es wird geprüft ob ab1 = "" wenn ja dann wird ab1 nun zu ab1 +ab ansonsten bleibt es wie es ist
oab1=ab1; //oab1 wird zu ab1
ls=ls.substring(2,ls.length); //von ls werden die ersten beiden ziffern abgetrennt
for (var i=0;i<ab;i++) //wird sechs mal durch laufen
{
nr=eval(ls.substring(0,2))-a; //nr wird zu den ersten beiden ziffern von ls - 8
ls=ls.substring(2,ls.length); //ls wird um 2 ziffern verkürzt
nls+=al.charAt(nr); //nls=nls und das zeichen welches sich in der variable AL befindet auf der position nr
Alert(nls);
}
nls=nls+al.charAt(count+11); //nls = nls und das zeichen welches sich in der variable al befindet auf position 11
alert(nls); //der wert von nls wird ausgegeben (selber befehl wie unten mit den failed attempt
if (nls.indexOf(tst)>-1) //Die variable nlS wird durchsucht nach der zeichenkette tst (die funktion indexOf gibt die Anfangsposition des strings tst zurück, falls sie sich überhaupt in nls befindet)
{
ls="";
flg=1;
}
}
if (flg==1)
{
tstOk();
}
else
{
bctr++;
if (bctr>3)
{
location.href="denied.htm";
}
else
{
alert("Sorry. Bad Username or Password."
+" Failed Attempt #"+bctr+".");
}
}
}
function tstOk()
{
ab1=ab1+""+a;
alert("Access Granted");
location.href=tst.substring(1,5)+".htm";
}
function srand()
{
today=new Date();
rand=today.getTime();
picker=""+rand
picker=picker.charAt((picker.length-4));
rec=eval(picker);
}
// End Hiding -->
</SCRIPT>
<title>LoginMatrix HackMe Challenge - Level Five</title>
</HEAD>
<BODY BGCOLOR="#000000">
<FORM NAME="pd">
<INPUT TYPE='hidden' NAME='pe' VALUE="999881643741603838598498816760606041815967 "> //unten stehende zahl

</FORM>
<!-- You may put any page content you wish here
The HTML below for the password entry is presently set for blue background and white type. You may change colors to fit your own page design without impacting on the script, so long as the form elements stay the same. -->
<FORM NAME="isn" Action="javascript:ckPwd()"><br><br><br>
<TABLE BORDER=2 CELLPADDING=5 CELLSPACING=0 width="271" bordercolor="red" align="center">
<TR>
<TD COLSPAN=2 ALIGN=middle> <h2><B><font COLOR="red">Password Access<BR>
to Restricted Pages</font></B></h2></TD>
</TR>
<TR>
<TD> <p><B><font COLOR="red">User Name:</font></B></p></TD>
<TD> <INPUT NAME="username" SIZE=10 >
</TD>
</TR>
<TR>
<TD> <p><B><font COLOR="red">Password:</font></B></p></TD>
<TD> <INPUT TYPE="password" NAME="passwrd" SIZE=10 >
</TD>
</TR>
<TR>
<TD COLSPAN=2 ALIGN=middle> <INPUT TYPE="button" NAME="btn" VALUE=" Submit " onClick="ckPwd();return false;" >
</TD>
</TR>
</TABLE>
</FORM>
<SCRIPT LANGUAGE="JavaScript">
<!-- Hide JavaScript from Java-Impaired Browsers
document.isn.username.focus();
// End Hiding -->
</SCRIPT>
</BODY>
</HTML>