webPromedium
Lab 80 — GateGuard — SQL Injection in Organization Filter API
hackadvisor
Task: Identity management platform with REST API for organization filtering. Solution: Boolean-based blind SQL injection in field parameter to enumerate sqlite_master and extract flag from platform_secrets table using binary search.
$ ls tags/ techniques/
binary_search_extractionsqlite_schema_enumerationapi_parameter_injectionboolean_based_blind_sqli
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 303 — DevGateway — Broken Access Control in Admin API— hackadvisor
- [web][Pro]Lab 16 — FileGate — Authentication Bypass in API Login— hackadvisor
- [web][Pro]Lab 73 — NetShield — Reflected XSS via 404 Page Attribute Injection— hackadvisor
- [web][Pro]Lab 330 — AuthVault — Blind LDAP Injection in Directory Lookup— hackadvisor
- [web][Pro]Lab 35 — GateKeeper SSO — Open Redirect via Regex URI Validation— hackadvisor