Published on

AUPCTF'23 - Web - SQLi 2

Authors

Solution

We're given the following URL to work with:

https://challs.aupctf.live/sqli-2/

Upon visiting the URL, we're greeted with a login page:

Login Page

Now, since we already know that the challenge is of SQLi, we will try and use the same payload from SQLi-1. And... it works!

Login Page

Now, using the same script we wrote in SQLi-1 and just changing the URL, we get the flag Flag: aupCTF{m3d1um-sql-1nj3cti0n}