SMP CTF 2024 - Selection Round

Injection – Networking Challenge Writeup | SMP CTF 2024 - Selection Round

As i mentioned in launch Date challenge i found an injection point. where attacker use a malicious sql query in sender param which reveled all the chats including the launch date.

So the endpoint was process_getChat.php

0 people love this