I stumbled upon this website: http://web.ctflearn.com/web8/ and I think they have the flag in their somewhere. UNION might be a helpful command
6 days ago
The task isn't hard at all, just had to search through long list of tables to find the flag table
7 months ago
Do not use sqlmap.It is actually not complicated.
8 months ago
Just use sqlmap :)
ezpz
9 months ago
clue: search about information_schema
10 months ago
I'm new here, it's pretty hard for me lol
11 months ago
i rate this challenge 3 * , and medium difficulty
1 year ago
ezzpz
6 years ago
Great challenge!
4 years ago
If you're struggling, the concepts on this blog are explained very nicely-
Exploiting SQL Injection: a Hands-on Example
3 years ago
You're the best!
hmmm I just started doing all the techniques in the article but it's not working for me nearly in the same way
5 years ago
you're great, bro
Found this very difficult, took me lots of research to solve. Site mentioned in comments was helpful. In the end got much better at understanding sql stuff and am ready to break the interweb.
Very awesome and one of the CTF in this website!!
2 years ago
I swear i knew sql for sqli like 2 months ago and i just forgot most of it ☠️
show tables in information_schema.tables then show column in information_schema.columns
use --random-agent in sqlmap to bypass firewall
6 days ago
The task isn't hard at all, just had to search through long list of tables to find the flag table