← All labs
MasterSQL / command injection

Reading files through the database engine

100 points · about 180 minutes · flag format DC{...}
Injection

Brief

Injection is untrusted input reaching an interpreter as code rather than as data. When a value you supply is concatenated into a SQL query or a shell command, characters that mean something to that interpreter let you change what it does — read tables you should not, or run commands the app never intended.

This lab: Reading files through the database engine. Break out of a query or a shell command through unescaped input.

Work it against your own copy of the target. When you have the flag, submit it below.

Objective

Find an input that is built into a query or a command, break out of the data and into the syntax, and extract something you should not be able to reach. Capture the flag it exposes.

Sign in and join the Academy to submit a flag, take hints and track your progress.

Sign in

Walkthrough

Locked until you solve it — or reveal it above, which forfeits the points. 3 hints available before then.