$50M CTF from Hackerone – Writeup
github.com
github.com
Overkill much? :)
> There is only one user ("admin", "5f4dcc3b5aa765d61d8327deb882cf99"). Is that a hash? Googled it and found the answer, yes it is: md5('password'). Now we are able to log in using admin:password or even using the sqli
Stuff like this makes me think the author accidentally went into this stuff in reverse order. The username/password combo seems almost expected to be manually bruteforceable.
Also, the whole blind-querying of strings using sleep() is awesome. Is that a common technique or did the author make it up on the spot?
You have full details on what these requests look like here: https://www.owasp.org/index.php/Blind_SQL_Injection
Every time I see one of there I reflect on the fact that if a person is prepared to do all this work for either lulz or some kUSD, imagine what efforts people might be prepared to do to gain 1-10-100 MUSD.
We know these attackers may expend a lot of effort. They also have more education, tooling, and labor out there than at any time before. Might as well use technology that makes blocking them something we don't even think about vs a cat and mouse game where we must consider every detail for even common operations or apps.
The writeup is okay thou.