DEV Community

Discussion on: Hacker101 CTF - Petshop Pro

Collapse
 
koroep profile image
koroep • Edited

You need to use an error message which isn't on the page when it finds the right username. In this case, the login page will display the message "Invalid username" until you find the right one, which will then change to "Invalid password". So you want Hydra to know that it succeeds when the "Invalid username" is no longer displayed.

Thanks for the great post!