Mobile Phones are Bad
Date: 04, July, 2021
Author: Dhilip Sanjay S
The hacker said, Gurugram Interns are intelligent enough to get through this challenge.
https://mudpmd.hackingbrawl.com/
Let's brush some database
Answer: ctf{youdidit}
Hint: Well admin will receive otp of 4 digits.
Steps to Reproduce:
Use a basic SQL injection payload to bypass the login.
Error based SQLi
username:
' or '1=1password:
' or '1=1

We have the OTP Verification page - without rate limiting.
We can bruteforce the OTP!

Bruteforcing Python script:
The OTP is 7621:

Last updated