πŸ›‘οΈ Security Lab Track A Β· Web Application Security Β· Stage 3

Track A Β· Stage 3

Web Application Security

UNION-based SQL Injection mediumnot started

A product search reflects query results. Use a UNION SELECT to pull data from the hidden secrets table and exfiltrate the flag.

loading simulator…

Blind Boolean SQL Injection hardnot started

A 'check username availability' endpoint returns only Yes/No but is injectable. Extract the admin's secret token one character at a time, then submit it to get the flag.

loading simulator…