webeasy

Dead or alive 4

spbctf

Task: SQL injection with WAF filtering spaces, commas, and quotes. Solution: Bypass using TAB character (%09) for spaces, hex encoding (0x...) for quotes, and JOIN subqueries for commas.

$ ls tags/ techniques/
tab_space_bypasshex_encoding_bypassjoin_comma_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]