Tags: misc web vm sql 

Rating:

Get the source code with accessing /?source=1.

Analyze the complex sql based vm code, hand tracing constructs most of flag.
Some character need brute force sql query with Ubuntu+mysql 8.x version.

Original writeup (https://eine.tistory.com/entry/Xmas-CTF-2020-write-ups-focus-on-web-challs).