← Back
Flag5 - SQL Injection | Avishai’s CTF Writeups

Avishai's CTF Writeups

Yalla Balagan! A collection of my CTF writeups and solutions.

View on GitHub

Let’s first have a look at the challenge:

400

It tried this payload as username a' or '1'='1' -- -:

400 We can see we actually got logged in as admin, and got the password which looks like some hash.