webPromedium

Lab 226 — LiveDesk — SQL Injection via WebSocket Message Search

hackadvisor

Task: LiveDesk customer support platform with WebSocket-based message search feature using SQLite. Solution: UNION-based SQL injection through Socket.IO search_messages event to enumerate sqlite_master and extract flag from system_flags table.

$ ls tags/ techniques/
union_based_sqlisqlite_master_enumerationdecoy_flag_detectionwebsocket_sqlisocket_io_event_injection

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups