From the first challenge, I don't think that searching the page source for a link to <a href="http://www.google.com/search?q=llun+sdrawkcba" rel="nofollow">http://www.google.com/search?q=llun+sdrawkcba</a> counts as "real world hacking knowledge."<p>That's a lateral thinking puzzle, not a demonstration of poor null checking in passwords.
Reminds me of not pr0n (<a href="http://deathball.net/notpron/notpron.htm" rel="nofollow">http://deathball.net/notpron/notpron.htm</a>), except I'm able to make progress!