> For the complete documentation index, see [llms.txt](https://sayonara.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sayonara.gitbook.io/writeups/ctf/cyber-heroines-ctf-2023/web/shafrira-goldwasser.md).

# Shafrira Goldwasser&#x20;

### <mark style="color:blue;">Challenge Description</mark>

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2Ffze94IZ14Mq3uevJPuVz%2Fimage.png?alt=media&amp;token=321203ec-e9f3-4a40-8fab-ec2fc8fcd2c0" alt=""><figcaption></figcaption></figure></div>

### <mark style="color:blue;">Challenge Attachment</mark>

{% file src="/files/AxqgSqrBHP3Tw1QwWeh4" %}

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2Fq5H4OcrXpnL7Hd9LHhbz%2Fimage.png?alt=media&amp;token=5fd928be-c1cc-4045-abb0-575bd5d735c7" alt=""><figcaption></figcaption></figure></div>

so this application gives you options and for each one it brings the biography related to it from the database

### <mark style="color:blue;">SQL Injection</mark>

to find an attack vector we will look at the source code

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FtXv4uzWLsC66vd4bvLGA%2Fimage.png?alt=media&amp;token=57b18725-1990-46e5-b4a0-1159ad185dec" alt=""><figcaption></figcaption></figure></div>

so we have an sql injection since the user input is not parametrized and sanitized but even if we manage to pull the whole database we won't find the flag in it&#x20;

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FxHsyr8ruzHnv5HAsnfni%2Fimage.png?alt=media&amp;token=4c4729be-947f-4079-bfaf-bff45a550409" alt=""><figcaption></figcaption></figure></div>

### <mark style="color:blue;">Command Injection</mark>

we have another attack vector which is command injection since the sql command is executed within a subprocess so what we have to is try to find a way to inject other commands besides sqlite3 command

doing it directly without visualizing the query generated is going to be very hard so what we will be doing is running the app locally and print the query and the result to help us construct the payload

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2F4iFDbLqpaVt2Luk6m0yH%2Fimage.png?alt=media&amp;token=cbc3694f-aedd-4d98-aa80-8154da1422c7" alt=""><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FFAqVCPeZh3EnXY8fynNv%2Fimage.png?alt=media&amp;token=61c67169-ccb7-4734-a361-4a1f179f107d" alt=""><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FaIQguXWw4JnuDhRuI5hy%2Fimage.png?alt=media&amp;token=2eda54f7-a1ed-464c-84b8-f7d07d09e5d2" alt=""><figcaption></figcaption></figure></div>

using burp repeater we will be manipulating the user input to find a working payload

so the payload we will generate is simple we will try to escape the first command which is&#x20;

```
sqlite3 database.db "SELECT biography FROM cyberheroines WHERE name='userInput' "
```

to do that we have to get out of the double quote add the injected command and then the remaining garbage should be commented

### payload

```
AdaLovelace'";ls;#
```

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2F0Z01xsGxb4sFrzjMYV3z%2Fimage.png?alt=media&amp;token=2679613a-ecb0-4d3b-bd59-d1e095744797" alt=""><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2F9gY2TJKzwYo5y62xRr0s%2Fimage.png?alt=media&amp;token=9968724b-4777-44da-868e-398776fe6580" alt=""><figcaption></figcaption></figure></div>

now let's go back to the original web server and try to use this and find the flag

listing the current directory doesn't contain the flag file

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FsYCEiwzrZjRWFZso8KxK%2Fimage.png?alt=media&amp;token=3007861d-ef6a-410b-8d18-5847602c3f9e" alt=""><figcaption></figcaption></figure></div>

let's check the current working directory using pwd command

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FlYhQbaXRx2uC1JcH8Q8V%2Fimage.png?alt=media&amp;token=74dbe115-264e-4b00-af63-4b7660800e3d" alt=""><figcaption></figcaption></figure></div>

let's see what are the files in the root / directory

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FuKfopwpYiqFpp9tC375N%2Fimage.png?alt=media&amp;token=41efff0f-ac1a-4482-9372-bf2c160011ef" alt=""><figcaption></figcaption></figure></div>

let's read its content using cat command

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FANageMtjfmiX3JfN0QBY%2Fimage.png?alt=media&amp;token=2aa580d3-94d2-402b-ae3f-9a57da0e3022" alt=""><figcaption></figcaption></figure></div>

### <mark style="color:blue;">Flag</mark>

```
chctf{CH4ng3d_h0w_w3_th1Nk_of_pr00f$}
```
