webProeasy

Слепая инъекция (Blind Injection)

bug-makers

Task: Node.js API injects user input directly into SQL WHERE clause, returning boolean true/false. Solution: boolean-based blind SQLi with binary search using unicode(substr()) to extract flag character by character.

$ ls tags/ techniques/
binary_search_extractionboolean_blind_sqlisqlite_unicode_substrdirect_where_injection

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups