Week 8 Writeup
Project Spider Infiltration
๐ท๏ธ Oscorp O-COM Portal โ CTF Solution Walkthrough
Challenge Name: Project Spider Infiltration
Category: Cryptography + Web
#Step 1: SQL Injection โ Extract the Encryption Key
Navigate to the O-COM Login tab. The login terminal is vulnerable to SQL injection โ the hint at the bottom and the IT department notice both confirm this.
#1a. Find the column count
The original query selects 3 columns (id, username, clearance). You can confirm this with trial and error:
Username: ' UNION SELECT 1,2,3 --
Password: anythingIf it returns data, the query has 3 columns.
#1b. Read the Field Manual
The downloadable Oscorp Admin Field Manual (from the Transmissions tab) reveals the secret table:
