Перейти к содержимому

Still stuck on the Wizard King? Watch this to win

00xCanelo

0:00 / 0:00

Still stuck on the Wizard King? Watch this to win

293 просмотра · 10 дней назад
00xCanelo
143 подписчика
293 просмотра · 10 дней назад
In this full walkthrough I take you through the "Wizard King" CTF challenge by B4nka (CATF 2026). This was a tough one — I was the First Blood — and the hardest part isn't a classic exploit, it's abusing the MariaDB command-line client to escape a restricted SQL injection. What we cover: • Source code review of the Go proxy and the app (bot.go, proxy server, app.go) • Finding an HTTP request smuggling bug (CL.TE) inside the proxy • Using CL.TE smuggling to steal the admin bot's session cookie • SQL injection in the admin login • MariaDB command-line exploitation (backslash G / delimiter / system commands) to get code execution • Bypassing command blacklist filters • Reverse shell with netcat via hex-encoded IP • Capturing the flag If you're preparing for CTFs or trying to get better at web exploitation, this one has a great lesson on why you should never trust a blacklist. Grab a coffee — it's a long one. Chapters: 0:00 Intro & Challenge Overview 0:35 App Structure & Source Code Review 1:22 Bot & Database Analysis 2:14 Proxy & HTTP Request Smuggling (server.go) 5:23 app.go — Account Pattern & Validators 9:22 Admin Login & SQL Injection 10:55 Docker & Flag Location 11:24 Running the App in Burp Suite 13:53 CL.TE Smuggling to Steal the Admin Cookie 19:42 SQL Injection in the Admin Login 20:46 MariaDB Command-Line Exploitation 32:02 Reverse Shell via Netcat 34:52 Capturing the Flag 35:14 Wrap-up & Key Lessons #CTF #Writeup #EthicalHacking #PenetrationTesting