Rating:
- Manipulating `X-Forwarded-For` header to gain access to login page
- Blind SQL injection for authentication bypass
- Non-blind SQL injection to dump database
[Full Writeup](https://zeyu2001.gitbook.io/ctfs/2021/typhooncon-ctf-2021/clubmouse)