Hi, I'm fairly new to hacking, so I hope you can forgive my lack of skill, but I'll get straight to the point. My private school has a login page on the old section of their website (They've slowly been changing everything to a newer theme/location) and after completing the HTS basic missions, I was wondering how secure it was. Now, this login page grants access to the community section of the website intended for students/parents and has stuff like news, the lunch menu, sports activities, school forms, etc.). They've been using the same username and password combination since I first came to this school 7 years ago, and so far as I know this is the only combination that works (they've never told us anything else). I've tried a few sql commands and I've looked through the source code but I haven't found anything too obvious to exploit. I wanted to see if you guys had any suggestions as to what I could try. I'm not sure if posting the webpage's source could help (I couldn't find anything on it).
Now, I want to be clear that this isn't my website, its my school's and even though this section of the website hasn't been updated since January and most of the information is obsolete, I don't want to do anything illegal or break any rules. I firmly support HTS's position on illegal activities and don't want to engage in any myself. But since I already know the user/pass, I'm not sure if checking the vulnerability constitutes as illegal, so please tell me if it does and I will drop this idea completely. Thanks in advance for feedback.
