$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: a minimal Werkzeug login form sends GET parameters to /user and reveals different responses for valid and invalid users. Solution: use double-quote SQL injection in login to bypass authentication, then extract the admin password with UNION SELECT and log in as admin.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar