webPromedium
Lab 87 — GridWatch — SQL Injection in Agent Heartbeat API
hackadvisor
Task: Infrastructure monitoring platform with agent heartbeat API that takes Bearer token in Authorization header, SQLite backend. Solution: UNION-based SQL injection in Bearer token with /**/ comment space bypass to enumerate tables and extract flag from system_secrets.
$ ls tags/ techniques/
sqlitesql_injectionunion_based_sqliapisql_commentsdecoy_flagspace_bypassauthorization_headerbearer_tokenheartbeatagent_apimonitoring_platform
sqlite_schema_enumerationdecoy_flag_identificationunion_based_sql_injectionsql_comment_space_bypassauthorization_header_injection
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 238 — PulseWatch — SQL Injection in Collector Configuration— hackadvisor
- [web][Pro]Lab 172 — PulseGuard — Insecure Deserialization via JSON.NET TypeNameHandling— hackadvisor
- [web][Pro]Lab 51 — InsightGrid — SQL Injection via Django JSONField Key Paths— hackadvisor
- [web][Pro]Lab 127 — PulseMetric — Insecure Deserialization via Pickle in Agent Report API— hackadvisor
- [web][Pro]Lab 170 — PulseGuard — SnakeYAML Deserialization to H2 JDBC OOB Exfiltration— hackadvisor