> First recon step here is to run a port scan to discover if there is any service. As a result I got port 80
Overkill much? :)
> There is only one user ("admin", "5f4dcc3b5aa765d61d8327deb882cf99"). Is that a hash? Googled it and found the answer, yes it is: md5('password'). Now we are able to log in using admin:password or even using the sqli
Stuff like this makes me think the author accidentally went into this stuff in reverse order. The username/password combo seems almost expected to be manually bruteforceable.
Also, the whole blind-querying of strings using sleep() is awesome. Is that a common technique or did the author make it up on the spot?