$ cat writeup.md…
$ cat writeup.md…
ringzer0ctf
Task: a bare PHP login form returns a byte-identical page for every scalar SQLi/array/header payload, with no feedback. Solution: MongoDB NoSQL operator injection via PHP bracket-array params (password[$ne]=1) gives a blind boolean oracle; $regex plus binary search blind-extracts admin's password, which is the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar