← missions
Intermediate

SQLi Data Extraction

A login form is vulnerable to SQL injection. Extract the admin credentials from the database and document your methodology. Bonus: identify whether blind SQLi is also possible.

mission brief

300

XP reward

45 min

est. time

> Objectives

01Confirm the SQLi vulnerability with a proof-of-concept
02Extract the users table schema
03Retrieve the admin username and password hash
04Identify whether time-based blind SQLi is possible
#sqli#injection#database