SQL Injection Challenges

Tutorials here

Reset the Database Before Using It

Challenge 4 (30): Put your name into this file, using the form below.
/tmp/sqlchal4winner

Query:      

Within a minute, your name will appear on the Winners page as shown below:

Challenge 5 (50): Use a different server, without the option to use raw SELECT queries.

Before starting, click the button below to reset the database:

Now use this name search form:

Name:      
Put your name into this file on that server:
/tmp/sqlchal5winner
Within a minute, your name will appear on the Winners page as shown below:


Posted for TORO.Hack 4-6-18