Hack This Site! Realistic missions: Basic 2

Nouf
Oct 17, 2020

Level 2

Challenge:

Message: I have been informed that you have quite admirable hacking skills. Well, this racist hate group is using their website to organize a mass gathering of ignorant racist bastards. We cannot allow such bigoted aggression to happen. If you can gain access to their administrator page and post messages to their main page, we would be eternally grateful.

Solution:

nothing is attracted in the page, so I went to the source code and found update.php and it was a login page

I do not have any credentials so SQL Injection came to my mind, and bingo it is vulnerable

so I logged successfully in with ‘ OR ‘a’=’a as username and password

--

--