Researcher Solves Intigriti SQL Injection CTF via Base64-Encoded URL Parameter
A security researcher solved the Intigriti September 2026 Critter Gallery CTF challenge by identifying a SQL injection vulnerability in the application's 'pic' URL parameter. The parameter accepted base64-encoded animal names, which the server decoded and inserted directly into a SQL query without proper sanitization or parameterization. By manipulating the decoded input with boolean conditions and UNION SELECT statements, the researcher confirmed the injection and determined the query returned a single column. Further enumeration of the challenge database via information_schema revealed a table called 'secret_vault' containing a 'note' column, from which the flag was extracted. The successful submission was accepted by Intigriti under reference INTIGRITI-T8Z07V6I.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in