How I Hacked IIT Delhi
作者通过手动方法成功入侵IITD数据库,在Sqlmap失效后使用subfinder枚举子域名,并通过填写注册表单和邮件验证成功进入系统。 2025-10-30 09:4:42 Author: infosecwriteups.com(查看原文) 阅读量:7 收藏

StvRoot

First of all, don’t judge my excitement by the width of these letters. I will show you how I managed to get inside IITD’s database even when Sqlmap failed. I will outline all the triggers and how I validated my findings without any automated tools just via manual approach.

Press enter or click to view image in full size

Photo by Michael Geiger on Unsplash

From time to time, I purposely stumble on IITs just because I want to bag them all, not just one. This time I thought why not IITD as it was in the second position on Nirf useless table. I enumerated all the subdomains using subfinder. The ONLY tool that helped. Now I started to browse them manually.

By One by one manually I mean , looking for patterns while browsing. I thoroughly search a subdomain, looking at its UI, js files & all the clickables then if I find other similar subdomains, I fast forward through them. It saves time.

I found a subdomain with odd looking login page. I tried basic creds and common sqli payloads. Nothing worked. It had a functionality to register as non-members or as a faculty or foreigner. Usually these are for internal purposes and after you fill the form you actually can’t register.

It had a long form. I was patient and filled it. To my surprise, it sent a verification code on my mail.

very well.

After completing the verification I got another link on my mail.


文章来源: https://infosecwriteups.com/how-i-hacked-iit-delhi-885a7f810292?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh