> For the complete documentation index, see [llms.txt](https://ad3n.gitbook.io/ad3n/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ad3n.gitbook.io/ad3n/home/ctf-writeups/curtin-malaysia-ctf-2023/web-sqli.md).

# Web - SQLi

* ## Try to login

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2F6H25q8aOhLmJ0eGkcoo4%2Fimage.png?alt=media&amp;token=ff52e348-7809-4d56-b267-db739a7883e5" alt="" width="344"><figcaption></figcaption></figure>

Straight forward challenge which I use burp suite intruder to inject list of sql payload at username parameter and got the flag.

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2F4AlA7ydYNszJQBexegAh%2Fimage.png?alt=media&amp;token=20022842-0b1a-4870-a32a-b20d53fa64a5" alt="" width="563"><figcaption></figcaption></figure>

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FSnArhdeXJ2HtKkqVthL7%2Fimage.png?alt=media&amp;token=0355bcf3-4aee-42b7-9ddb-650909bd369b" alt="" width="476"><figcaption></figcaption></figure>

Flag: `CURTIN_CTF{5H0pT1m3}`

***

* ## Try logging in... again

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FhooygGdyQw8jrpzPAZh8%2Fimage.png?alt=media&amp;token=bb6fdb80-008a-45d0-a732-290f581d7271" alt="" width="322"><figcaption></figcaption></figure>

Same as previous challenge use the same payload, which this time it will filter certain character. Still managed to get the flag.

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FpCgc97KXvMHrDXz4t8rj%2Fimage.png?alt=media&amp;token=2e625ac7-feeb-41c5-a75b-f530dd0f0128" alt="" width="502"><figcaption></figcaption></figure>

Flag: `CURTIN_CTF{welc0m3aG@1n}`

***

* ## Database Discovery Quest

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2F706EVHTcxl3UONvahvYg%2Fimage.png?alt=media&amp;token=2293481a-c1f2-4563-b3c8-886c1c759357" alt="" width="293"><figcaption></figcaption></figure>

From search product page, try to inject this payload `' UNION SELECT 1,2,3,4,5;--`. It return the exact amount of columns available. After able to determine the number of columns, try to retrieve the database and it will show the flag using this payload `' UNION SELECT null,schema_name,null,null,null FROM information_schema.schemata;--`.

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FezW9HqpVcEmwiFWC36aV%2Fimage.png?alt=media&amp;token=c034f7e7-2bb2-49d0-a8c1-40227e3a498a" alt="" width="479"><figcaption></figcaption></figure>

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FZHI4gbEJvdMlcYpxHeXb%2Fimage.png?alt=media&amp;token=c125c5e2-2f94-4e14-9cb9-dba55263492d" alt="" width="494"><figcaption></figcaption></figure>

Flag: `CURTIN_CTF{d8_@_Ba$3}`

***

* ## Table Name Treasure Hunt

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FALIie2TbSOp5iMMPJKN1%2Fimage.png?alt=media&amp;token=99dfddbd-eb21-45ab-9775-90c1d7491b54" alt="" width="315"><figcaption></figcaption></figure>

Since previous challenge we discover suspicious database `sqlitraining`, I try to list all the table available in the database using this payload `' UNION SElECT null,table_name,null,null,null FROM information_schema.tables WHERE table_schema = 'sqlitraining';--`. It show the flag that divided into 2 part.

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2F33Ms0tOatkBrLJILcgCW%2Fimage.png?alt=media&amp;token=a736e975-e6ce-4bfb-b5a3-401c1dd29848" alt="" width="504"><figcaption></figcaption></figure>

Flag: `CURTIN_CTF{#1y!n#2Y@ng}`

***

* ## Fiver Fever

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FpLNEgh2ZkUPuCMYQmdXT%2Fimage.png?alt=media&amp;token=f78f5e10-a91a-46ff-918d-2ccf5c0d4df2" alt="" width="358"><figcaption></figcaption></figure>

The challenge ask to pick 5th person (`alice`) on the table `users` and hash the hashed password to make it as flag. Listed all the users using this `‘ UNION SELECT * FROM users;--` and make it into flag format.

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FHXdbliSGFiJJeBBxa2c4%2Fimage.png?alt=media&amp;token=f8f347e9-774e-480c-a5a8-65bc28f73bfa" alt="" width="486"><figcaption></figcaption></figure>

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FnRu0miz1b9ONyuL3jisR%2Fimage.png?alt=media&amp;token=09c224e0-4226-4cb2-8b07-6c1f1162afee" alt="" width="563"><figcaption></figcaption></figure>

Flag: `CURTIN_CTF{ab57c73efc0563ea1a25df5fb6c7590a}`

***

* ## Slow Down...

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2F0g1gPMDUxg9hCpFm6atm%2Fimage.png?alt=media&amp;token=c17e9f8a-95cb-4294-9861-d97fed95e442" alt="" width="401"><figcaption></figcaption></figure>

For this challenge, the link will go directly to the profile page which ask to do time-based blind sql injection. Looking at the url I assume that `user` parameter are vulnerable.

&#x20;

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FiUA9GhKMrfeQ0afUjEAz%2Fimage.png?alt=media&amp;token=2d501cef-5fa2-406e-8b35-4e8091f5e7a5" alt="" width="563"><figcaption></figcaption></figure>

Burp suite intruder will make it easier for me to inject list payload of time-based sqli and got the flag with the following payload `'&&SLEEP(5)&&'1`.

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2Fot16QRyFVPb3XIWj873u%2Fimage.png?alt=media&amp;token=0d106af6-c049-41b3-8b7e-99be6486357f" alt="" width="473"><figcaption></figcaption></figure>

Flag: `CURTIN_CTF{5l0wpOk3}`

***

* ## Unveiling the Dark Wizard's Secrets

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FjAdJLa3Lneqi7tW2ifhj%2Fimage.png?alt=media&amp;token=5dc1b382-33e4-4623-bf3f-ddb576878047" alt="" width="353"><figcaption></figcaption></figure>

Since the challenge ask to find user Tom, I try to list all user in search product page but did not manage to get it. Then, from the profile page I stumble upon hint to solve this challenge.

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FoPJpBa3XrFR23aRqxP6I%2Fimage.png?alt=media&amp;token=914824aa-58e7-4ca4-8362-e3b4cda9b619" alt="" width="563"><figcaption></figcaption></figure>

Following the hint of challenge 7, give me some interesting column in sqlitraining database `fname`. List all the name using `' UNION SELECT null,fname,password,null,null FROM users;--` and finally find what we are looking for, which is hashed password of `Tom` and put it into flag format.

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FDW0BwDhRYARpfIODQL7l%2Fimage.png?alt=media&amp;token=14ddc87f-02be-4e84-852e-3d8ed3d6223f" alt="" width="563"><figcaption></figcaption></figure>

<figure><img src="https://906050983-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNUYCtlc0k8qWwmB2FmiA%2Fuploads%2FblqRUDjp4e4XhpSgiRj1%2Fimage.png?alt=media&amp;token=dcd7ad12-74e0-4a3a-b5d9-d6e40a74b39c" alt="" width="563"><figcaption></figcaption></figure>

Flag: `CURTIN_CTF{872fc8ed4cae593dc5e62f00157b7db6}`
