/tripwire_ctf

SQL Injection Code for Tripwire VERT Cyber Security CTF Contest

Primary LanguagePython

This repository contains code that I wrote for Tripwire VERT's Cyber Security 
Capture The Flag Contest as well as a copy of a pastebin hint that was given to us.

More context can be found by visiting my post at Tripwire's blog:
Part 1: http://www.tripwire.com/state-of-security/off-topic/how-i-captured-the-flags-in-tripwire-verts-cyber-security-contest-part-1/
Part 2: http://www.tripwire.com/state-of-security/off-topic/how-i-captured-the-flags-in-tripwire-verts-cyber-security-contest-part-2/
or on my personal website:
https://ilias.giechaskiel.com/posts/tripwire_ctf/index.html

The output of the injection.py program is as follows:

Database name
ctf2
Table name
notes
Column names 0
username
Column names 1
dname
Column names 2
note
Password for flag 
48C8d9EKdcTNU
Flag 
The flag is '4 8 15 16 23 42'. Tell this sequence to a contest official to claim a prize if you qualify!