πŸ›‘οΈ Security Lab Track A Β· Web Application Security Β· Stage 2

Track A Β· Stage 2

Web Application Security

OS Command Injection easynot started

A 'network tools' page runs ping on a host you supply by concatenating your input into a shell command. Inject your own command to read the flag file on the server.

loading simulator…

SQL Injection β€” Authentication Bypass easynot started

A login form builds its SQL query by string concatenation. Log in as admin without knowing the password to reveal the flag.

loading simulator…