← Back to Challenges
WebMedium

Healthcare Portal SQL Injection

sql-injectionweb-securityowasp
UNG Cybersecurity Faculty
1/15/2025
200 points

Challenge Files

Challenge Instructions

README.txt

💡 Tip: Additional challenge-specific files are located in the assets folder. Check the instructions file for details.

Challenge Overview

Conduct a security assessment of a healthcare web portal. The login system is vulnerable to SQL injection. Bypass authentication, escalate to admin privileges, and retrieve the flag from the database.

Learning Objectives

  • Apply web analysis techniques
  • Use professional security tools
  • Understand real-world attack scenarios
  • Document findings professionally

Tools You May Need

  • Burp Suite or OWASP ZAP
  • sqlmap for automated testing
  • Browser developer tools

Getting Started

  1. Review the challenge description carefully
  2. Gather and examine all provided materials
  3. Apply systematic analysis methodology
  4. Document your findings as you progress
  5. Submit the flag when discovered

Flag Format

All flags follow the format: ung{descriptive_text}

Good luck!

Hints

💡 Hint 1 (Click to reveal)
Start by examining the basic artifacts and evidence provided
💡 Hint 2 (Click to reveal)
Use industry-standard tools for this type of analysis
💡 Hint 3 (Click to reveal)
The flag follows the format ung{...} with descriptive text

Submit Flag

Found the flag? Submit it below to complete the challenge and earn 200 points.

Note: This is a demonstration platform. In the full version, flags will be validated against secure hashes and your progress will be tracked on the scoreboard.