is the goal to hack the chess game or the admin panel? I never know how to do these things
is the goal to hack the chess game or the admin panel? I never know how to do these things
Analyzing and listing out ways to interact with the site will show you your surface area, although sometimes the interaction is so opaque you might have to check the "robots.txt" or other well known files.
The start button, the difficulty level, making a move, and the admin panel all offer ways to test different inputs to see if you can get unexpected output.
What inputs do they accept? What headers do they have? What encodings do they use? Are there any input checks done client side rather than server side?
Then it becomes a matter of thinking about what happens with these inputs/outputs. Did it ask for a file name? What if I feed it a file it doesn't expect. Might this input be used for a database query, how could I abuse that? Could my input or the output be marshaled? Could my input be passed to an exec somewhere? Can I find artifacts that tell me what programming languages/servers/libraries are being used? How can I probe for these things?
The people who do these for fun several times a month will often make writeups that offer hints of techniques to solve problems when the competition is done.
These are some related sites:
See: http://wbec-ridderkerk.nl/html/UCIProtocol.html , https://github.com/official-stockfish/Stockfish/issues/3720
That said I don't think a strong chess engine alone would be enough to pass this puzzle.
A 500 is almost always a good sign when it comes to hacking. Hacking is the art of finding the difference between intended behavior and actual behavior. That is pretty much the definition of a 500.
I tried brute forcing the login admin panel but no luck yet.
What username should I use? I tried all the basic ones and cant get it to display anything besides "Invalid Login!".
What do you imagine the code that takes the logins eventually does? It seems likely that the username and password will end up in a query against a database to see if the user is valid and (theoretically) if the hash of the password matches the stored value.
What kind of input could you try to see if that behavior is done securely?
This is a good site to start learning about security: https://owasp.org/www-project-top-ten/
Injection will be the most immediately relevant.