Home > Javascript, Try2Hack.nl, Wargames > Try2Hack – Level 2

Try2Hack – Level 2

Level 2: http://www.try2hack.nl/levels/level2-xfdgnh.xhtml

As usual, right click trying to view source code but it pops a dialog saying right-click on mouse disabled.

So I grep the source code by downloading it to local to view; however, for more convenience,  I use this online tool: Web Sniffer to analyze the request and HTML code.

This is the interesting part:

  Enter the username and password below to continue:<br /><br />[CRLF]

Then it’s a Shockwave Flash file __level2.swf__. Again, download this file and decrypt the ActionScript inside.
I use this tool for Flash Decoder: Flare

movie 'C:\Downloads\level2.swf' {
// flash 5, total frames: 1, frame rate: 12 fps, 400x300 px

  button 9 {

    on (release) {
      if (txtUsername == 'try2hack' and txtPassword == 'irtehh4x0r!') {
        getURL('level3-.xhtml', '_self');

Login with this id: __user | pass = try2hack | irtehh4x0r__ .
Going to level 3 now.



Pete Houston

  1. April 3, 2015 at 5:09 am

    or you could have opened a new window and entered ” view-source:” in front of the url

  2. j
    April 14, 2017 at 5:42 am

    How does one download the .swf file ?

  3. Aaron Stone
    November 8, 2017 at 9:42 am

    yeah plz tell… how does one download the .swf file ??

  4. Gulsar
    March 4, 2018 at 7:07 am

    open a new tab in the browser and paste http://www.try2hack.nl/levels/level2.swf and hit enter. That’s it.

  5. Typo
    March 16, 2018 at 8:28 pm

    Also you can ‘view page info’, look in ‘media’ for the file and click ‘save’.

  1. No trackbacks yet.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )


Connecting to %s

%d bloggers like this: