Irish Repo Name
Irish-Name-Repo 1
Description
AUTHOR: CHRIS HENSLER
There is a website running at https://jupiter.challenges.picoctf.org/problem/33850/ (link) or http://jupiter.challenges.picoctf.org:33850. Do you think you can log us in? Try to see if you can login!
Solution
When we visit Support someone complains that they're getting SQL error because of Conan O'Brien.

We got to Login page and try basic SQLi payload ' or 1=1 -- and we get in.
Flag: picoCTF{s0m3_SQL_f8adf3fb}
Irish-Name-Repo 2
Description
AUTHOR: XINGYANG PAN
There is a website running at https://jupiter.challenges.picoctf.org/problem/64649/ (link). Someone has bypassed the login before, and now it's being strengthened. Try to see if you can still login! or http://jupiter.challenges.picoctf.org:64649
Solution
Same payload isn't working, since OR is being filtered. We can try to login with AND. Payload admin' AND 1=1 --
Flag: picoCTF{m0R3_SQL_plz_aee925db}
Irish-Name-Repo 3
Description
AUTHOR: XINGYANG PAN
There is a secure website running at https://jupiter.challenges.picoctf.org/problem/54253/ (link) or http://jupiter.challenges.picoctf.org:54253. Try to see if you can login as admin!
Solution
Trying previous payloads doesn't work. Looking into HTML source code there's odd element.
Hidden debug? I changed the value from 0 to 1 directly from Developer Tools, also you can remove type="password" from password input to see what you're writing.
The characters are transpositioned, OR became BE. Inspecting the difference between characters we get delimiter of 13, ROT13?

Final payload = ' BE 1=1 --
Flag: picoCTF{3v3n_m0r3_SQL_7f5767f6}
Last updated