Tries --:--:-- left
Next hack in --:--:--
Warm-up

Your first hack, in 60 seconds

Every Daily Hack works the same way: read the briefing, look at the evidence, type the answer. Try it here first - no XP, no pressure.

Mission briefing

Developers sometimes leave notes in a page's source code that visitors never see. This login page ships one. Read the source below and find the staff password.

Investigate
<form action="/login" method="post">
  <input name="user" placeholder="Username">
  <input name="pass" type="password" placeholder="Password">
  <!-- TODO: remove before launch - staff password is "sunrise" -->
  <button>Sign in</button>
</form>
Your answer
Daily Hack #96 First blood Malekith Solved by vokru Sipmaster PR3J4N0D Dwang evorg luizballstaedt

The invite that made an owner

Privilege Escalation & Post-Exploitation Difficulty Easy ~3 min +10 XP
Mission briefing

Vantage found an Owner in its workspace that nobody remembers creating. The account belongs to a real colleague who was invited in an ordinary batch of four, and the team lead who sent that batch is certain they never touched a role. They are telling the truth: the invite screen offers no role control at all, and it says in plain text that everyone invited from it joins as a Member. But what a page shows and what a page posts are two different documents, and the server believed the second one. This is the screen exactly as it was submitted, captured by the support tool. Read the markup and name the address that arrived as Owner.

Investigate
Your answer

Play freely - sign up to submit your answer and earn XP.

Solved! +10 XP
First blood! You were first to crack today's hack.
How it works

Up next Pro
Play next hack

Nice one!

Sign up free to claim your +10 XP and start your streak.

Claim +10 XP - sign up free
27,000+ Hackers 100+ Labs & Courses Free
Start Hacking Free