webeasy

Bypass

spbctf

Task: perform SQL injection when quotes and comment characters are filtered. Solution: exploit a numeric parameter (id=) that does not require quotes in SQL, inject UNION SELECT directly without quotes or comments.

$ ls tags/ techniques/
numeric_sqlifilter_evasion

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]