Still stuck on the Wizard King? Watch this to win
00xCanelo
0:00 / 0:00
Still stuck on the Wizard King? Watch this to win
293 просмотра · 10 дней назад
00xCanelo
143 подписчика
293 просмотра · 10 дней назад
In this full walkthrough I take you through the "Wizard King" CTF challenge by B4nka (CATF 2026). This was a tough one — I was the First Blood — and the hardest part isn't a classic exploit, it's abusing the MariaDB command-line client to escape a restricted SQL injection.
What we cover:
• Source code review of the Go proxy and the app (bot.go, proxy server, app.go)
• Finding an HTTP request smuggling bug (CL.TE) inside the proxy
• Using CL.TE smuggling to steal the admin bot's session cookie
• SQL injection in the admin login
• MariaDB command-line exploitation (backslash G / delimiter / system commands) to get code execution
• Bypassing command blacklist filters
• Reverse shell with netcat via hex-encoded IP
• Capturing the flag
If you're preparing for CTFs or trying to get better at web exploitation, this one has a great lesson on why you should never trust a blacklist. Grab a coffee — it's a long one.
Chapters:
0:00 Intro & Challenge Overview
0:35 App Structure & Source Code Review
1:22 Bot & Database Analysis
2:14 Proxy & HTTP Request Smuggling (server.go)
5:23 app.go — Account Pattern & Validators
9:22 Admin Login & SQL Injection
10:55 Docker & Flag Location
11:24 Running the App in Burp Suite
13:53 CL.TE Smuggling to Steal the Admin Cookie
19:42 SQL Injection in the Admin Login
20:46 MariaDB Command-Line Exploitation
32:02 Reverse Shell via Netcat
34:52 Capturing the Flag
35:14 Wrap-up & Key Lessons
#CTF #Writeup #EthicalHacking #PenetrationTesting