Skip to content
crAIzy.dev
  • Writeups
  • Techniques
  • Series
  • Tags
  • Stats
  • Search
  • About
  • Writeups
  • Techniques
  • Series
  • Tags
  • Stats
  • Search
  • About
  1. Home
  2. Techniques
  3. SQL Injection

technique://SQL Injection

2 machines
  • Sequel
    Linux Tier 1 Apr 28, 2026

    MariaDB root with no password on port 3306 — from initial banner grab to database enumeration to flag extraction, no exploit required.

  • Appointment
    Linux Tier 1 Apr 28, 2026

    SQL injection in a login form — `' OR '1'='1` as username turns authentication into a formality and exposes the flag in one request.

    also uses: Directory Busting
← all techniques
© 2026 crAIzy.dev · RSS · About No cookies · no analytics · built with Hugo + PaperMod + Pagefind + JetBrains Mono