$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: a static 'Lugx Gaming Shop' PHP/MySQL site whose newsletter Subscribe form has an input with id=email but no name attribute, so the email parameter is never submitted by a browser. Solution: manually POST email to index.php, discover a !empty() gate (email=0 vs email=x) hiding a no-output backend SELECT, then exploit it via time-based blind SQL injection with single-row-scoped SLEEP to extract the flag stored as a subscriber's email.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar