nday: file storage - m0leCon Teaser CTF
11 September 2024
CRLF
SQLI
m0leCon Teaser CTF
This challenge is from the m0leCon Teaser CTF
. It was an interesting but relatively easy challenge, so the write-up will be brief. The objective was to exploit SQL Injection
(SQLi) and CRLF
(Carriage Return Line Feed) vulnerabilities to retrieve the flag from an internal server. Two services were running: an FTP server and a Node.js application, alongside a PHP server running on Nginx.