Mobile Phones are Bad

Date: 04, July, 2021

Author: Dhilip Sanjay S


  • The hacker said, Gurugram Interns are intelligent enough to get through this challenge. https://mudpmd.hackingbrawl.com/

Let's brush some database

  • Answer: ctf{youdidit}

  • Hint: Well admin will receive otp of 4 digits.

  • Steps to Reproduce:

    • Use a basic SQL injection payload to bypass the login.

    • Error based SQLi

      • username: ' or '1=1

      • password: ' or '1=1

OTP
  • We have the OTP Verification page - without rate limiting.

  • We can bruteforce the OTP!

OTP Verification
  • Bruteforcing Python script:

  • The OTP is 7621:

OTP Hacked

Last updated