Your first hack, in 60 seconds
Every Daily Hack works the same way: read the briefing, look at the evidence, type the answer. Try it here first - no XP, no pressure.
Developers sometimes leave notes in a page's source code that visitors never see. This login page ships one. Read the source below and find the staff password.
<form action="/login" method="post">
<input name="user" placeholder="Username">
<input name="pass" type="password" placeholder="Password">
<!-- TODO: remove before launch - staff password is "sunrise" -->
<button>Sign in</button>
</form>
Two victims, one supplier
A clinic group and a freight company, in different sectors and with no customers, staff or networks in common, were both robbed in the same week by a session that nobody ever logged into. Neither one can find a phishing mail, a stolen password or a piece of malware, and both were running multi-factor authentication that was never challenged. What two organisations like that share is suppliers. Six public records are on the board. Work out which supplier is in both stories and is the one that can create a session without a login.
Play freely - sign up to submit your answer and earn XP.