Time-based extraction from a silent endpoint
50 points · about 90 minutes · flag formatDC{...}Brief
Injection is untrusted input reaching an interpreter as code rather than as data. When a value you supply is concatenated into a SQL query or a shell command, characters that mean something to that interpreter let you change what it does — read tables you should not, or run commands the app never intended.
This lab: Time-based extraction from a silent endpoint. Break out of a query or a shell command through unescaped input.
Work it against your own copy of the target. When you have the flag, submit it below.
Objective
Find an input that is built into a query or a command, break out of the data and into the syntax, and extract something you should not be able to reach. Capture the flag it exposes.
Sign in and join the Academy to submit a flag, take hints and track your progress.
Sign inWalkthrough
Locked until you solve it — or reveal it above, which forfeits the points. 3 hints available before then.