What is it? @.@

Here is the place where I record some tactics about wargame, systems, and other security issues.

2012-09-16

Hack This Site! - Realistic 2

Description:

Chicago American Nazi Party
Racist pigs are organizing an 'anti-immigrant' rally in Chicago. Help anti-racist activists take over their website!

Realistic 2
From: DestroyFascism 

Message: I have been informed that you have quite admirable hacking skills. Well, this racist hate group is using their website to organize a mass gathering of ignorant racist bastards. We cannot allow such bigoted aggression to happen. If you can gain access to their administrator page and post messages to their main page, we would be eternally grateful.
Solution:
  1. View page source code
  2. In the bottom of the page, you will find a "update" page link
    < a href="update.php">< font color="#000000">update< /font>< /a>
  3. Visit the page, you will find out there is a LOGIN FORM, it's your target.
  4. There's no any hint for you. So, let's try the SQL Injection.
    Each time when you meet a login page has a traditional username-and-password form, just try SQLin Injection.
    Reference: http://en.wikipedia.org/wiki/SQL_injection
  5. You can input anything into the username field, but remember to input the injection below into the password field.
    enter your username and password, white brother!
    username: foo
    password: ' or '1'='1;
  6. Send the request.
  7. Congratulations, you have successfully completed Realistic 2!