Acme Lookup (Blind SQLi)

web · hard · 350 pts

Acme's user-lookup endpoint always returns the same content. But timing leaks. Extract the admin's password byte-by-byte; submit at /check_flag. --- ### Run locally ```bash cd content/aysec/AYSEC-CTF docker compose up sqli-blind ``` Then open `http://localhost:8000` and start solving.