webhard

Не Уцуцуга (Ne Utsutuga)

hackerlab

Task: Web application with registration form where standard SQLi doesn't work. Solution: Fragmented SQL Injection via backslash escape - adding backslash at end of email field escapes the closing quote, allowing profession field to contain SQL code. Used DIOS technique to extract admin credentials.

$ ls tags/ techniques/
Fragmented SQL Injection via backslash escapeDIOS (Dump In One Shot) for data extractionMulti-field INSERT injectionBackslash quote escape bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]