$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: a PHP login page behind Apache redirected unauthenticated users to login.php and rejected normal credentials, while naive SQLi caused 500 errors. Solution: establish a PHP session first, then use a balanced parenthesis SQL injection with /**/ comments to bypass authentication as admin.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar