> For the complete documentation index, see [llms.txt](https://bunring.gitbook.io/ctf-writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://bunring.gitbook.io/ctf-writeups/try-hack-me/2025/light.md).

# Light

Welcome to the Light database application!

{% embed url="<https://tryhackme.com/r/room/lightroom>" %}

For this challenge, we will bypass conducting an Nmap scan as the room description explicitly directs us to connect to port 1337. Additionally, we are provided with a starting user. The service running on port 1337 is likely the Light database application mentioned earlier.

<figure><img src="https://2564342917-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjsQwj0hMRgqeOaja7rRi%2Fuploads%2FSM7tfJS7WT8Y6pOF1MaF%2Fimage.png?alt=media&amp;token=776b300b-5934-4657-b97a-eb67b16e18fe" alt=""><figcaption></figcaption></figure>

Given that this is a database-focused challenge, we test a simple SQL Injection payload (`'`). The response returns an error, indicating that the service might be vulnerable to SQL Injection. The error message specifies an unrecognized token in `''' LIMIT 30"`, suggesting that the single quote (`'`) broke the string syntax, causing the application to fail.

<figure><img src="https://2564342917-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjsQwj0hMRgqeOaja7rRi%2Fuploads%2FxJBWzfaSKMX0jb2RATMB%2Fimage.png?alt=media&amp;token=ae842276-4425-4a39-b98b-3a98d4a42c15" alt=""><figcaption></figcaption></figure>

Next, we attempt to gather more information by employing a `UNION SELECT` SQL injection. However, the query fails due to an issue with the comment syntax used in our payload.&#x20;

```sql
' UNION SELECT 1 -- -
```

This suggests that the database may not be accepting standard inline comments or the payload requires adjustments to match the query structure.

<figure><img src="https://2564342917-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjsQwj0hMRgqeOaja7rRi%2Fuploads%2FpKGp7pz9tlDgptiwruRg%2Fimage.png?alt=media&amp;token=af9d4e69-15de-4ea4-a31b-a9e12bb866d9" alt=""><figcaption></figcaption></figure>

Alternatively, we switch to using the `#` symbol for comments, which avoids the error encountered earlier. However, certain keywords like `UNION` and `SELECT` appear to be blocked by the application, likely as a security measure to prevent straightforward SQL injection attempts.

<figure><img src="https://2564342917-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjsQwj0hMRgqeOaja7rRi%2Fuploads%2FXOCURouQMQ78pPDsKVYc%2Fimage.png?alt=media&amp;token=22ae7d18-9f2a-426d-b78b-5cb089b28d26" alt=""><figcaption></figcaption></figure>

We attempt switching between capitalized and non-capitalized versions of keywords, but we still encounter errors. This suggests that the application might also be filtering or blocking the `SELECT` statement itself, in addition to `UNION`.

After modifying the `SELECT` statement using the same capitalization technique, we encounter a different error. This time, the error indicates that the token `#` is not recognized, suggesting that the comment syntax might not be supported or is being filtered.

<figure><img src="https://2564342917-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjsQwj0hMRgqeOaja7rRi%2Fuploads%2Fc6FFDW1EcTaziVhMsGDt%2Fimage.png?alt=media&amp;token=af5cd973-d14f-466b-b394-15ca19f5c53e" alt=""><figcaption></figcaption></figure>

We URL-encode `#`, but it doesn't work. Instead, we get a new error related to the `'` character.

<figure><img src="https://2564342917-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjsQwj0hMRgqeOaja7rRi%2Fuploads%2FYO3XNRom98wgjAlIbZpJ%2Fimage.png?alt=media&amp;token=ddb84af4-981f-4589-9f95-39617a7e6f59" alt=""><figcaption></figcaption></figure>

It’s possible the statement resembles this format, which breaks when a `'` is inserted:

```sql
SELECT * FROM users WHERE username = '{input}' LIMIT 30; 
```

Our SQL Injection leading to:

```sql
SELECT * FROM users WHERE username = ''' LIMIT 30;
```

By closing the statement with an additional `'`, we successfully execute a UNION-based SQL injection.

```sql
' UniOn SeLeCt 1 '
```

<figure><img src="https://2564342917-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjsQwj0hMRgqeOaja7rRi%2Fuploads%2FkwhIC6l7q7ubv4sCQm8l%2Fimage.png?alt=media&amp;token=39ee4145-a415-4204-87ce-82375603b7e9" alt=""><figcaption></figcaption></figure>

Next, we query the version to determine the DBMS in use, which reveals that the database is SQLite version `3.31.1`.

```sql
' UniOn SeLeCt sqlite_version() '
```

<figure><img src="https://2564342917-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjsQwj0hMRgqeOaja7rRi%2Fuploads%2FjxcHTEiJAoCojAjokwbv%2Fimage.png?alt=media&amp;token=5edd9beb-a302-40ab-8854-411aef723ccf" alt=""><figcaption></figcaption></figure>

We can refer to this for more information:

{% embed url="<https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/SQL%20Injection/SQLite%20Injection.md>" %}

Next, we query the `sqlite_master` table to retrieve the database structure, where we find two tables: `admintable` and `usertable`.

<figure><img src="https://2564342917-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjsQwj0hMRgqeOaja7rRi%2Fuploads%2FqT5889q1pFw5e8HLnIvk%2Fimage.png?alt=media&amp;token=6dc1b14e-9813-45ed-9a83-5b2b91f24a2b" alt=""><figcaption></figcaption></figure>

We query the `username` and `password` fields from the `usertable`, but we do not find the expected information.

```sql
' UniOn SeLeCt group_concat(username) FROM usertable '
' UniOn SeLeCt group_concat(password) FROM usertable '
```

Next, we query the `username` and `password` from the `admintable` and successfully find the username, password, and the requested flag.

<figure><img src="https://2564342917-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjsQwj0hMRgqeOaja7rRi%2Fuploads%2FP9VCbwUaHEeVDoWhVjAD%2Fimage.png?alt=media&amp;token=cfe5e9b6-f3f9-4ba6-a2ba-58de5b4799e2" alt=""><figcaption></figcaption></figure>
