HomeRapidalertThe Pwnzilla solution from the distinguished Penetration Tester Evangelos Mourikis!

The Pwnzilla solution from distinguished Penetration Tester Evangelos Mourikis!

The-US-Accuses-China-of-Economic-Espionage SecNews publishes the solution of the Pwnzilla competition , which was organized in collaboration with the University of Piraeus and invited security researchers, security enthusiasts, and anyone who wished to test their knowledge in hacking systems through Web applications.

The competition was admittedly very difficult and it was not easy to identify the SQL Injection vulnerability using well-known tools and automated tools. This did not prevent over 930 researchers, individual users as well as security managers from banks, telecommunications operators and companies from taking an active part.

As we mentioned in a previous article , Greek researcher and penetration tester Evangelos Mourikis shared with the editorial team of SecNews and the University of Piraeus, step-by-step, the most comprehensive solution to the challenge.

Evangelos Mourikis proved to be one of the most highly skilled participants, as he completely decoded the Challenge. web security It is worth mentioning that apart from Evangelos Mourikis, we received a similar solution at a later time from user Georgios Spanos.

We publish the most detailed solution exactly as Mr. Mourikis below:

[gview file=”Pwnzilla_Writeup.pdf” save=”0″]

In fact, the penetration tester even created his own appropriate subroutines to conduct his test quickly and bypass any security measures that had been placed in the code of the exposed application!

In addition to Mr. Evangelos Mourikis who impressed everyone with his high level of knowledge, it is worth expressing our congratulations to the Department of Digital Systems of the University of Piraeusand specifically to the Assistant Professor of the University of Piraeus, Mr. Christos Xenakis as the scientific supervisor of Pwnzilla , as well as to the technical supervisor of the Doctoral Candidate of the Department of Digital Systems, Mr.Anastasios Stasinopoulos, who undertook the technical implementation of the exercise.

Soon expect new similar competitions that will highlight new talents in information systems security and identifying weaknesses in real systems. The SecNews management team is trying, in consultation with sponsors, financial institutions and telecommunications providers who have expressed interest in holding new competitions to highlight new talents, to achieve the payment of monetary prizes corresponding to the Bug bounty provided by companies abroad.

So stay tuned for more. Thank you to all participants! The server will remain active so that anyone who wishes can try the solution!

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS