Skip to content

Latest commit

 

History

History
21 lines (14 loc) · 471 Bytes

File metadata and controls

21 lines (14 loc) · 471 Bytes

The Vault

Points: 250

Category

Web Exploitation

Question

There is a website running at http://2018shell1.picoctf.com:56537 (link). Try to see if you can login!

Hint

No Hints.

Solution

An SQLi challenge where the php code running the query filters out the term OR.

Using LIKE, we can circumvent the filter.

Working solution solve.py

Flag

picoCTF{w3lc0m3_t0_th3_vau1t_c09f30a0}