CTF Write-Up: SQL Injection via Base64 Parameter Cracks Intigriti's Critter Gallery
Security researcher solved Intigriti's Challenge 0926, a capture-the-flag puzzle disguised as an animal photo gallery, on September 27, 2026. The vulnerability stemmed from a base64-encoded query parameter that passed user input directly into a single-quoted SQL string without sanitization. A behavioral mismatch between PHP's case-sensitive image lookup and MySQL's case-insensitive description query revealed that two separate layers processed the same input differently, signaling a potential injection point. Using classic SQL injection techniques — including a boolean-based proof and a UNION-based extraction — the researcher enumerated the database schema and dumped a hidden table called secret_vault. The flag, INTIGRITI{01a09f56-74a2-700b-a849-ffe6742327b2}, was retrieved in 14 probing steps and accepted by Intigriti.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in