We covered a scenario of blind SQL Injection where the web application accepts user input without sanitization or filtering. We used a blind SQL query to guess the password by guessing the characters and their order. We finally wrapped this up with a simple python script that does the job.. This was part of OverTheWire War Games Natas Level 15
Natas Level 16 Password:
TRD7iZrd5gATjj9OkPEuaOlfEjHqj32V
Video Walkthrough
Show Comments