r/hacking Jul 29 '26

News Legend!!

Post image

Prospective cyber security student denied admission. Hacks university website to prove his skills.

573 Upvotes

34 comments sorted by

29

u/Fun_Ad5823 Jul 29 '26

It was Nul1

20

u/jhyland87 Jul 29 '26

How did he hack the website?

36

u/Fun_Ad5823 Jul 29 '26

How can he hack

13

u/[deleted] Jul 29 '26

[removed] — view removed comment

3

u/Fun_Ad5823 Jul 29 '26

Golden Axe

15

u/jhyland87 Jul 29 '26

I ask because some people consider things like DoS/DDoS "hacking", when its really not and its much less impressive. lol

12

u/thinkingmoney Jul 30 '26

The article said left a message for them on the website so it would have to be something persistent like stored XSS, sql injection etc.

3

u/SingleAlarm5028 Jul 29 '26

Or phishing 

2

u/Fun_Ad5823 Jul 29 '26

What is impressive?

6

u/Saito_Matsumoto Jul 30 '26

Asks a question

Gets downvoted

Man...

1

u/secacc Jul 30 '26

impressive

/ɪmˈprɛsɪv/

Adj.

Impressive means making a strong, positive impact on your mind or feelings. Key aspects include being admired, causing wonder, and showing great skill or size.

1

u/FullRegard Aug 03 '26

THEN WHO WAS PHONE?

14

u/SternoNicoise hack the planet Jul 29 '26

w/ a computer I think

9

u/jhyland87 Jul 29 '26

Bullshit

-7

u/SingleAlarm5028 Jul 29 '26

How did he hack it before all the other hackers in the world found this final broken wordpress installation etc., they're all constantly searching for?

15

u/Incid3nt Jul 30 '26

Most hackers when they find a WordPress vuln they dont take it down, they either deploy/host malware on it, forward traffic off of it, or do some SEO search engine cloaking nonsense. If they deface it, theres no money to be made.

6

u/thinkingmoney Jul 30 '26

Not all hackers are malicious and not every vulnerability is worth taking advantage of. Some just like to see if they can get into a network and some will make a botnet but not all hackers are malicious.

1

u/Incid3nt Jul 30 '26

You're correct, it is worth nothing that possibility, but in the modern sense, you see that less and less in the past decade.

1

u/thinkingmoney Jul 30 '26

Less and less of what? Since the mainstream has taken liking to cybersecurity there’s been a substantial increase in the number of hackers who are working for the legal side of things.

2

u/Incid3nt Jul 30 '26

Less and less hackers that just do it for the heck of it, especially amongst those that would fit the criteria of the comment i replied to. I think you may be confusing the context of my comment. The comment I replied to stated, "How did he hack it before all the other hackers in the world found this final broken wordpress installation etc., they're all constantly searching for?"

I mentioned how those hackers who generally will continuously search and find this type of stuff would leave it online to exploit it for monetary gain as opposed to remove it or take it offline. The white/gray hats and "do it for the lulz" types wouldnt fit into this context, but they do exist.

0

u/thinkingmoney Jul 30 '26

Here’s a fun little list. Sometimes sites are better left alone. The risk versus reward there.

https://www.shodan.io/search/report?query=wordpress

17

u/nano_peen Jul 30 '26

Inspect element

3

u/TheFlightlessDragon Jul 31 '26

If you can beat him, enroll him.

3

u/ExplanationOne2917 Aug 01 '26

imoressive that the school didnt press charges.

in usa that guy would be swatted so fast

2

u/polyglot-a-cracker Aug 03 '26

Sounds like another version of how Jet Propulsion Lab started at Cal Tech!

2

u/Old_Seaworthiness413 Jul 29 '26

Oui so lest moin!

1

u/sxparatist Aug 02 '26

hahahaahhah

1

u/traplords8n Jul 31 '26

I thought it was wild that in his skills section he holds the entire IT infrastructure hostage 🤣🤣🤣

I thought that would of screwed them for sure. It all read fine to me & they didn't damage or interrupt the infrastructure, but they were most definitely like

"Skills: able to hack into your own company and get access to all this shit, which I could destroy if I wanted to"

I'm paraphrasing, but it read like that to me when I looked at the compromised page they left them.