Level 23 - Hard Blind SQLi

http://suninatas.com/challenge/web23/web23.asparrow-up-right

Level_23_-_Hard_Blind_SQLi.png

The ... in description means there are more filters which are not listed.

There seems to be Length limit of 30 characters and LIKE keyword is banned. # is also banned.

I thought the database would be MySQL, but it turned out to be Microsoft!

https://portswigger.net/web-security/sql-injection/cheat-sheetarrow-up-right

Payload thinking progress...

To leak the password ideally we need a truthy condition. If we manage to leak characters of password we can bruteforce the start or the end, considering no other user has same password (or similar). Example:

Leak the first character:

circle-check

Last updated