webhard
Не Уцуцуга (Ne Utsutuga)
hackerlab
Task: Web application with registration form where standard SQLi doesn't work. Solution: Fragmented SQL Injection via backslash escape - adding backslash at end of email field escapes the closing quote, allowing profession field to contain SQL code. Used DIOS technique to extract admin credentials.
$ ls tags/ techniques/
sql_injectionmysqlfragmented_sqliinsert_injectionbackslash_escapediosregistration_formmulti_field_injectionquote_escape
Fragmented SQL Injection via backslash escapeDIOS (Dump In One Shot) for data extractionMulti-field INSERT injectionBackslash quote escape bypass
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]