Exploits
Brainstorming
Dir guessing Looking in source SQL Injection RFI Cookie poisoning Blind SQL Injection
this is just an idea, however what we could do is have somewhere the user could post some XSS. Then there could be an automatic reply to that thread or whatever it is(code in PHP to have it reply). The admin(php code) would reply to the thread and after that the hacker would go to his site where the cookies were posted from the admin recieving the XSS attack, and the hacker gets his cookies and log's in as the admin.
I have an idea which could be added somehow to the game. We don't know the storyline yet, but maybe it'll fit in. Here's the idea. You get access to a system which records phone calls by date ( or location or who knows what ). You're told to search for a specific location/time file. You download it ( mp3 ) and play it. It should contain a convo where a known person from one company talks to an unknown in rebuses ( stegano ). You need to find out the dialled number with some DTMF voice analyzer. That's all. So the mp3 file should contain the DTMF tones of the dialled number, and a short convo after that.