old-21 -- SQLi (Blind Extract Password)

URL: https://webhacking.kr/challenge/bonus-1/arrow-up-right

old-21.png

By the looks of it we should perform Blind SQLi.

Trying the basic bypass gives us wrong password instead of login fail with valid username.

old-21-1.png

Username injection is confirmed, now we need to get password.

Login with credentials and pwn the room.

old-21-2.png

Last updated