PortSwigger SQL Injection Lab 3 — Oracle Version Enumeration
A writeup of PortSwigger's Oracle-based SQL injection lab for extracting the database version with a UNION attack.
A writeup of PortSwigger's Oracle-based SQL injection lab for extracting the database version with a UNION attack.
A writeup of PortSwigger's login bypass lab, demonstrating how to bypass authentication with SQL injection.
A writeup of PortSwigger's first SQL injection lab, showing how to retrieve hidden data by injecting into a WHERE clause.
A writeup of the PicoCTF SqlMap1 challenge using SQL injection and password cracking.
A writeup of the PicoCTF Secret Box challenge using an INSERT SQL injection to reveal admin secrets.
A writeup of the PicoCTF No FA challenge with a 2FA session bypass using a leaked database and Flask session cookie.
A writeup of the PicoCTF Hashgate challenge, showing how to exploit an MD5-based profile lookup.
A writeup of the PicoCTF Fool the Lockout challenge showing a flawed IP-rate-limit bypass.
A writeup of the PicoCTF Credential Stuffing challenge using raw TCP and threaded automation.
A detailed writeup of the PicoCTF "where are the robots" web exploitation challenge.