/Baby_CQLi

A hard SQLi-RCE web challenge that I wrote for Securinets ISI Mini CTF

Primary LanguageHack

This is the Dockerfile for a hard web challenge that I wrote for Securinets ISI Mini CTF.

The challenge basically includes an SQLi vulnerability and using some of the build-in sqlite3 functionalities, you can get an RCE to grab the flag located in the file system. There are some applied filters that you need to bypass.

I only provided the value-score.php file along with the challenge during the CTF.

Please reach out if you encounter any issues when setting up the challenge.

Writeup: https://wassila-chtioui.com/post/baby_cqli/