-NO SPOILERS The only help you can give is exterior links eg google explaining the method of attack, or broad help such as, "search for hidden links," or "read this paper on sqli it will help understand" is aloud
Not aloud: "go to /javascript1help.php the password is there" etc