Tags: blindsqli sqlinjection web 

Rating:

Time based SQL Injection to get the key from database.
Because of filtered keywords (count, sleep, benchmark) I used heavy query to lookup n1ip rows with useless joining self table.

Original writeup (https://eine.tistory.com/entry/n1ctf-2020-web-signIn-write-up).