webPromedium
Базовая авторизация 2 (Basic Auth 2)
hackerlab
Task: PHP login form with WAF filtering spaces in SQL queries. Solution: WAF bypass using SQL comments /**/ for boolean-based blind SQLi, character-by-character flag extraction with BINARY keyword for case-sensitive comparison.
$ ls tags/ techniques/
waf_bypasssql_injectionmysqlcase_sensitivityphpblind_sqliboolean_based_sqlisql_commentssubstringcharacter_extraction
WAF bypass using SQL comments /**/Boolean-based blind SQL injectionCharacter-by-character extraction with substring()MySQL case-sensitivity awareness (BINARY keyword)
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Базовая авторизация 3 — HackerLab— hackerlab
- [web][Pro]Авторизация 2.0 (Authorization 2.0)— hackerlab
- [web][Pro]Запретный код 2 (Forbidden Code 2) — HackerLab— hackerlab
- [web][Pro]Доступ запрещён (Access Denied)— hackerlab
- [web][Pro]Pryzhok— hackerlab