nday: file storage - m0leCon Teaser CTF

11 September 2024

CRLF

SQLI

m0leCon Teaser CTF

This challenge is from the m0leCon Teaser CTF. It was an interesting but relatively easy challenge, so the write-up will be brief. The objective was to exploit SQL Injection (SQLi) and CRLF (Carriage Return Line Feed) vulnerabilities to retrieve the flag from an internal server. Two services were running: an FTP server and a Node.js application, alongside a PHP server running on Nginx.