Rating:

- Manipulating `X-Forwarded-For` header to gain access to login page
- Blind SQL injection for authentication bypass
- Non-blind SQL injection to dump database

[Full Writeup](https://zeyu2001.gitbook.io/ctfs/2021/typhooncon-ctf-2021/clubmouse)

Original writeup (https://zeyu2001.gitbook.io/ctfs/2021/typhooncon-ctf-2021/clubmouse).