webeasy

Dead or alive 1

spbctf

Task: perform SQL injection on a web app with no filtering or WAF. Solution: standard UNION-based SQL injection with single quote to break the query, ORDER BY to find column count, then UNION SELECT to extract the flag.

$ ls tags/ techniques/
union_based_sqli

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]