Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
sql-injection
ssh
hashcat
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
sql-injection
ssh
hashcat
In this lab, you will exploit a classic SQL Injection vulnerability to access the admin panel of a dating app. From there, you will obtain sensitive credentials and progress to uncover hidden relationships, secret directories, and privileged users. In this lab, you will learn:
hashcat
Follow these instructions to get started:
You are facing a romantic and vulnerable web application. Your mission is to use your technical skills to uncover the secrets behind this panel.
Discover the IP address of the The lovers machine.
nmap
, netdiscover
, or arp-scan
to scan the network.Access the website hosted on the server.: You will find a landing page with a typical dating app login. Use SQL Injection to log in without real credentials.
Access the admin panel of the user Mike.
Connect to the server via SSH as Mike.
Find the first flag.
Explore the secrets
directory.
Discover Amanda's password and switch users.
Access the final flag as root.
Remember: even secret loves leave digital traces. 💔
Good luck!
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
sql-injection
ssh
hashcat
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
sql-injection
ssh
hashcat
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
sql-injection
ssh
hashcat
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
sql-injection
ssh
hashcat
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
sql-injection
ssh
hashcat
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
sql-injection
ssh
hashcat