webeasy

Decoder

spbctf

Task: Web service with login form and base64 decoder, source code available showing SQL query. Solution: Exploited SQL injection in login form using classic injection or UNION-based attack to extract flag from database.

$ ls tags/ techniques/
second_order_sql_injectionlogin_form_injection

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]