<?xml version="1.0" encoding="utf-8" standalone="yes" ?>
<rss version="2.0" 
  xmlns:content="http://purl.org/rss/1.0/modules/content/" 
  xmlns:dc="http://purl.org/dc/elements/1.1/" 
  xmlns:atom="http://www.w3.org/2005/Atom" 
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" 
  xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>SQL Injection on rainbowpigeon</title>
    <link>https://rainbowpigeon.me/tags/sql-injection/</link>
    <description>Recent content in SQL Injection on rainbowpigeon</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <managingEditor>rainbowpigeon.helge[AT]8alias.com (rainbowpigeon)</managingEditor>
    <webMaster>rainbowpigeon.helge[AT]8alias.com (rainbowpigeon)</webMaster>
    <copyright>©2025 rainbowpigeon, All Rights Reserved</copyright>
    <lastBuildDate>Mon, 22 Nov 2021 00:51:06 +0800</lastBuildDate>
    
        <atom:link href="https://rainbowpigeon.me/tags/sql-injection/index.xml" rel="self" type="application/rss+xml" />
    

      
      <item>
        <title>TISC 2021 Writeups</title>
        <link>https://rainbowpigeon.me/posts/tisc-2021/</link>
        <pubDate>Mon, 22 Nov 2021 00:51:06 +0800</pubDate>
        <author>rainbowpigeon.helge[AT]8alias.com (rainbowpigeon)</author>
        <atom:modified>Mon, 22 Nov 2021 00:51:06 +0800</atom:modified>
        <guid>https://rainbowpigeon.me/posts/tisc-2021/</guid>
        <description>&lt;p&gt;I could have been 5th place but unfortunately I did not officially qualify to be a real participant in this event. Still had a good time though, notwithstanding the fact that there was so much &amp;lsquo;steganography&amp;rsquo; and quite a bit of guesswork at certain points :)&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Details&lt;/th&gt;
&lt;th&gt;Links&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Official Event Information Page&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://www.csit.gov.sg/tisc/tisc-home&#34;&gt;https://www.csit.gov.sg/tisc/tisc-home&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Official Event Landing Page&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://www.tisc.csit-events.sg/&#34;&gt;https://www.tisc.csit-events.sg/&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Official Event Summary&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://www.csit.gov.sg/tisc/tisc-2021-summary&#34;&gt;https://www.csit.gov.sg/tisc/tisc-2021-summary&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;</description>
        
        <dc:creator>rainbowpigeon</dc:creator>
        <media:content url="https://rainbowpigeon.me/images/content/tisc-2021/tisc.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>CTF</category>
            
          
            
              <category>Writeup</category>
            
          
            
              <category>Android</category>
            
          
            
              <category>Autopsy</category>
            
          
            
              <category>Forensics</category>
            
          
            
              <category>IDA</category>
            
          
            
              <category>IoT</category>
            
          
            
              <category>Steganography</category>
            
          
            
              <category>SQL Injection</category>
            
          
            
              <category>Reverse Engineering</category>
            
          
            
              <category>Wireshark</category>
            
          
            
              <category>Web</category>
            
          
            
              <category>XSS</category>
            
          
        
        
          
            
              <category>CTF</category>
            
          
        
        
      </item>
      
      <item>
        <title>STANDCON CTF 2021 Writeups</title>
        <link>https://rainbowpigeon.me/posts/standconctf-2021/</link>
        <pubDate>Sun, 25 Jul 2021 12:00:06 +0900</pubDate>
        <author>rainbowpigeon.helge[AT]8alias.com (rainbowpigeon)</author>
        <atom:modified>Sun, 25 Jul 2021 12:00:06 +0900</atom:modified>
        <guid>https://rainbowpigeon.me/posts/standconctf-2021/</guid>
        <description>&lt;p&gt;Good job to my team for obtaining &lt;strong&gt;7th place&lt;/strong&gt;! And also thanks to the challenge creators and organizers of course :)&lt;br /&gt;
🎵 &lt;a href=&#34;https://www.youtube.com/watch?v=ZU-qvYPhFCw&#34;&gt;Nicky Romero &amp;amp; MARF ft. Wulf - Okay&lt;/a&gt;🎵&lt;br /&gt;
&lt;div class=&#34;expand&#34;&gt;
  &lt;button type=&#34;button&#34; class=&#34;expand__button&#34; aria-label=&#34;Expand Button&#34;&gt;
    &lt;span class=&#34;expand-icon expand-icon__right&#34;&gt;
        &lt;svg xmlns=&#34;http://www.w3.org/2000/svg&#34; width=&#34;24&#34; height=&#34;24&#34; viewBox=&#34;0 0 24 24&#34;&gt;&lt;path fill=&#34;currentColor&#34; d=&#34;M9.29 15.88L13.17 12 9.29 8.12c-.39-.39-.39-1.02 0-1.41.39-.39 1.02-.39 1.41 0l4.59 4.59c.39.39.39 1.02 0 1.41L10.7 17.3c-.39.39-1.02.39-1.41 0-.38-.39-.39-1.03 0-1.42z&#34;/&gt;&lt;/svg&gt;
    &lt;/span&gt;
    My solves (4) table
  &lt;/button&gt;
  &lt;div class=&#34;expand__content&#34;&gt;
    &lt;img src=&#34;https://rainbowpigeon.me/images/content/standconctf-2021/solves.png&#34; alt=&#34;Table of Solves&#34; /&gt;
  &lt;/div&gt;
&lt;/div&gt;&lt;/p&gt;</description>
        
        <dc:creator>rainbowpigeon</dc:creator>
        <media:content url="https://rainbowpigeon.me/images/content/standconctf-2021/standconctf_2021.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>CTF</category>
            
          
            
              <category>Writeup</category>
            
          
            
              <category>Burp Suite</category>
            
          
            
              <category>Deserialization</category>
            
          
            
              <category>LFI</category>
            
          
            
              <category>Path Traversal</category>
            
          
            
              <category>SQL Injection</category>
            
          
            
              <category>SSRF</category>
            
          
            
              <category>Web</category>
            
          
        
        
          
            
              <category>CTF</category>
            
          
        
        
      </item>
      
      <item>
        <title>BrainHack CDDC 2021 Writeups</title>
        <link>https://rainbowpigeon.me/posts/cddc-2021/</link>
        <pubDate>Fri, 25 Jun 2021 12:00:06 +0900</pubDate>
        <author>rainbowpigeon.helge[AT]8alias.com (rainbowpigeon)</author>
        <atom:modified>Fri, 25 Jun 2021 12:00:06 +0900</atom:modified>
        <guid>https://rainbowpigeon.me/posts/cddc-2021/</guid>
        <description>&lt;p&gt;I joined the Junior Category this year and I&amp;rsquo;ll be frank: this was quite badly organized. It seems that they did not conduct any proper dry runs of the event. They had broken challenges (missing crucial challenge information, missing code in files, non-functional websites) and the worst thing is that they do not even announce when they are aware of the problem, when they are working on rectifying it, and when they have fixed it. Instead, we were left to figure out ourselves that a particular challenge file had been silently changed, or a vital piece of information was quietly added into some challenge description.&lt;br /&gt;
There were also insufficent challenges (or they were of inadequate difficulty) to cover the duration of the event, which rendered their plan and timing of staggered challenge releases meaningless. Many hours before each challenge-release checkpoint, the top teams were already tied by their scores and idling. This means that the final winner would essentially be based only on the last challenge-release &amp;ndash; which was a Web mission comprising 3 challenges. But because the final Web challenge was inoperative, the top teams basically came to a tie again while waiting for the challenge to be fixed after solving the other 2. Initially, no one knew it was broken so we did not even know what payloads we sent were supposed to work. And when they said it was supposedly fixed, it wasn&amp;rsquo;t. Isn&amp;rsquo;t that disorienting?&lt;br /&gt;
Some more side points to note is that they delayed the winners announcement livestream 3 times for a total of 6 hours, and the live scoreboard was alphabetically sorted rather than based on time in the event that scores were tied.&lt;br /&gt;
Honestly, what&amp;rsquo;s even scarier is that I heard the Senior Category had even more serious issues, such as being only able to login a day after the competition started&amp;hellip;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;Anyway, big shoutout to my team for trying their best to find time to work on this together! We came in &lt;strong&gt;3rd&lt;/strong&gt; and that&amp;rsquo;s satisfactory.&lt;br /&gt;
🎵 &lt;a href=&#34;https://www.youtube.com/watch?v=_4IYe0uQAWM&#34;&gt;Haywood - Backbeat&lt;/a&gt; was a really good tune that I put on for this CTF :)&lt;br /&gt;
&lt;div class=&#34;expand&#34;&gt;
  &lt;button type=&#34;button&#34; class=&#34;expand__button&#34; aria-label=&#34;Expand Button&#34;&gt;
    &lt;span class=&#34;expand-icon expand-icon__right&#34;&gt;
        &lt;svg xmlns=&#34;http://www.w3.org/2000/svg&#34; width=&#34;24&#34; height=&#34;24&#34; viewBox=&#34;0 0 24 24&#34;&gt;&lt;path fill=&#34;currentColor&#34; d=&#34;M9.29 15.88L13.17 12 9.29 8.12c-.39-.39-.39-1.02 0-1.41.39-.39 1.02-.39 1.41 0l4.59 4.59c.39.39.39 1.02 0 1.41L10.7 17.3c-.39.39-1.02.39-1.41 0-.38-.39-.39-1.03 0-1.42z&#34;/&gt;&lt;/svg&gt;
    &lt;/span&gt;
    Missions completed, team score, and player score
  &lt;/button&gt;
  &lt;div class=&#34;expand__content&#34;&gt;
    &lt;img src=&#34;https://rainbowpigeon.me/images/content/cddc-2021/announcement.png&#34; alt=&#34;Placing announcement&#34; /&gt;&lt;br /&gt;
&lt;img src=&#34;https://rainbowpigeon.me/images/content/cddc-2021/player_score.png&#34; alt=&#34;Individual player score&#34; /&gt;&lt;br /&gt;
&lt;img src=&#34;https://rainbowpigeon.me/images/content/cddc-2021/missions.png&#34; alt=&#34;Missions completed and team score&#34; /&gt;
  &lt;/div&gt;
&lt;/div&gt;&lt;/p&gt;</description>
        
        <dc:creator>rainbowpigeon</dc:creator>
        <media:content url="https://rainbowpigeon.me/images/content/cddc-2021/cddc.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>CTF</category>
            
          
            
              <category>Writeup</category>
            
          
            
              <category>Burp Suite</category>
            
          
            
              <category>Buffer Overflow</category>
            
          
            
              <category>Forensics</category>
            
          
            
              <category>IDA</category>
            
          
            
              <category>LFI</category>
            
          
            
              <category>OSINT</category>
            
          
            
              <category>Path Traversal</category>
            
          
            
              <category>PWN</category>
            
          
            
              <category>Reverse Engineering</category>
            
          
            
              <category>SMB</category>
            
          
            
              <category>SQL Injection</category>
            
          
            
              <category>Web</category>
            
          
            
              <category>Wireshark</category>
            
          
        
        
          
            
              <category>CTF</category>
            
          
        
        
      </item>
      
      <item>
        <title>NorzhCTF 2021 Writeups</title>
        <link>https://rainbowpigeon.me/posts/norzhctf-2021/</link>
        <pubDate>Mon, 24 May 2021 12:00:06 +0900</pubDate>
        <author>rainbowpigeon.helge[AT]8alias.com (rainbowpigeon)</author>
        <atom:modified>Mon, 24 May 2021 12:00:06 +0900</atom:modified>
        <guid>https://rainbowpigeon.me/posts/norzhctf-2021/</guid>
        <description>&lt;p&gt;Very unique CTF! Alongside challenges that got you to work with provided files, there was an OSCP-virtual-labs-style network with both external-facing and internal developer and admin subnets. Network reconnaissance and pivoting had to be performed. Unfortunately, I solved little challenges as I only started seriously on the second day :) The delays and infrastructure issues doused the flames of my enthusiasm&amp;hellip; &lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Details&lt;/th&gt;
&lt;th&gt;Links&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;CTFtime.org Event Page&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://ctftime.org/event/1301&#34;&gt;https://ctftime.org/event/1301&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;</description>
        
        <dc:creator>rainbowpigeon</dc:creator>
        <media:content url="https://rainbowpigeon.me/images/content/norzhctf-2021/norzhctf.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>CTF</category>
            
          
            
              <category>Writeup</category>
            
          
            
              <category>Burp Suite</category>
            
          
            
              <category>SQL Injection</category>
            
          
            
              <category>SSRF</category>
            
          
            
              <category>Web</category>
            
          
            
              <category>Werkzeug</category>
            
          
        
        
          
            
              <category>CTF</category>
            
          
        
        
      </item>
      
      <item>
        <title>UMDCTF 2021 Writeups</title>
        <link>https://rainbowpigeon.me/posts/umdctf-2021/</link>
        <pubDate>Tue, 27 Apr 2021 12:00:06 +0900</pubDate>
        <author>rainbowpigeon.helge[AT]8alias.com (rainbowpigeon)</author>
        <atom:modified>Tue, 27 Apr 2021 12:00:06 +0900</atom:modified>
        <guid>https://rainbowpigeon.me/posts/umdctf-2021/</guid>
        <description>&lt;p&gt;I appreciate the organizers for putting this CTF together because I enjoyed it a lot. It was at a very appropriate difficulty level for novices. Many thanks to my teammates for helping out. Even though it was only basically 2 active players 🙂, we managed to get &lt;strong&gt;8th place&lt;/strong&gt;, which I am pretty satisfied with considering our little experience.&lt;br /&gt;
🎵 For this CTF I was listening to &lt;a href=&#34;https://www.youtube.com/watch?v=qV8USJ_XN7Q&#34;&gt;Kygo - Gone Are The Days ft. James Gillespie&lt;/a&gt;!&lt;br /&gt;
&lt;div class=&#34;expand&#34;&gt;
  &lt;button type=&#34;button&#34; class=&#34;expand__button&#34; aria-label=&#34;Expand Button&#34;&gt;
    &lt;span class=&#34;expand-icon expand-icon__right&#34;&gt;
        &lt;svg xmlns=&#34;http://www.w3.org/2000/svg&#34; width=&#34;24&#34; height=&#34;24&#34; viewBox=&#34;0 0 24 24&#34;&gt;&lt;path fill=&#34;currentColor&#34; d=&#34;M9.29 15.88L13.17 12 9.29 8.12c-.39-.39-.39-1.02 0-1.41.39-.39 1.02-.39 1.41 0l4.59 4.59c.39.39.39 1.02 0 1.41L10.7 17.3c-.39.39-1.02.39-1.41 0-.38-.39-.39-1.03 0-1.42z&#34;/&gt;&lt;/svg&gt;
    &lt;/span&gt;
    My solves (22) graph and category breakdown
  &lt;/button&gt;
  &lt;div class=&#34;expand__content&#34;&gt;
    &lt;img src=&#34;https://rainbowpigeon.me/images/content/umdctf-2021/graph.png&#34; alt=&#34;Graph of challenge solves over time&#34; /&gt;&lt;br /&gt;
&lt;img src=&#34;https://rainbowpigeon.me/images/content/umdctf-2021/breakdown.png&#34; alt=&#34;Category breakdown of challenge solves&#34; /&gt;
  &lt;/div&gt;
&lt;/div&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Details&lt;/th&gt;
&lt;th&gt;Links&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;CTFtime.org Event Page&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://ctftime.org/event/1288&#34;&gt;https://ctftime.org/event/1288&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Publicly-released challenges&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://github.com/UMD-CSEC/UMDCTF-2021-Public-Challenges&#34;&gt;https://github.com/UMD-CSEC/UMDCTF-2021-Public-Challenges&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;</description>
        
        <dc:creator>rainbowpigeon</dc:creator>
        <media:content url="https://rainbowpigeon.me/images/content/umdctf-2021/umdcsec.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>CTF</category>
            
          
            
              <category>Writeup</category>
            
          
            
              <category>Burp Suite</category>
            
          
            
              <category>Forensics</category>
            
          
            
              <category>Hashcat</category>
            
          
            
              <category>OSINT</category>
            
          
            
              <category>Shodan</category>
            
          
            
              <category>SQL Injection</category>
            
          
            
              <category>Steganography</category>
            
          
            
              <category>Volatility</category>
            
          
            
              <category>Web</category>
            
          
            
              <category>Wireshark</category>
            
          
        
        
          
            
              <category>CTF</category>
            
          
        
        
      </item>
      

    
  </channel>
</rss>
