$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: AI-powered analytics platform (DataPilot) with natural language to SQL conversion. The AI chat has guardrails against direct prompt injection but fails to sanitize SQL fragments in natural language input. Solution: UNION-based SQL injection through the AI interface by embedding SQL payloads in natural language queries, bypassing table-level access controls to extract hidden system_config table containing the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar