Inj3ction Time
100 points Hard

I stumbled upon this website: http://web.ctflearn.com/web8/ and I think they have the flag in their somewhere. UNION might be a helpful command

Flag
Rating 4.71
5
4
3
2
1

Discussion

BBBBBBBBOOOOOOOOOOOTTTTTTTTTTTTTAAAAAAAAAAKKKKKKKKKK!!!!!!!!!!!!

0

now it would actually be hard if you didn't give away the part that requires thinking, which is to use UNION and ORDER BY

0

thats really good practice but its med level , some hints for starters : 1- check first what is url looks like before and after send data so you can know about filtering . 2- union is 1st step for any sqli, so read more about it . 3- after that you can see clearly how you can write your injection queries without blocking filters . 4- now , what you looking for is two things mainly : () - tables () - coulmns , after all that => you will find the REAL flag .

0

I'm confused. I tried the commands shown in the comments but nothing returned. Has this challenge changed since the comments were posted?

-1

i used sqlmap , used the opportunity to learn about sqlmap

0

Should be considered an easy injection question, solvable without using any tool with just manual trial and error in a cpl minutes. Now it would actually be hard if you didn't give away the part that requires thinking, which is to use UNION and ORDER BY

-1

I swear i knew sql for sqli like 2 months ago and i just forgot most of it ☠️

4

Needs basic understanding of union and order in sql injection perspective.

0

A beautiful concept explained here, as it focuses on SQLi using UNION.

0

Is it by design that https://web.ctflearn.com/web8/fade.js is missing and returns 404 when browser tries to load it?

0

WOW! I've learned a lot! For those of you who struggle have a look on this website. A lot of useful infromation!

http://www.securityidiots.com/Web-Pentest/SQL-Injection

4

nice keep learning and stay foolish lelz

1

nice keep learning and stay foolish lelz

0

that site helped me....thanks :)

1

Thanks for the resource! It helped a lot

0