Skip to content

Harden SQL injection challenge levels - #152

Open
tobymoreno wants to merge 2 commits into
OWASP-CTF:dc34-ctffrom
tobymoreno:fix/sql-injection-protection
Open

tobymoreno wants to merge 2 commits into
OWASP-CTF:dc34-ctffrom
tobymoreno:fix/sql-injection-protection

Conversation

@tobymoreno

@tobymoreno tobymoreno commented Aug 9, 2026 •

Copy link
Copy Markdown

Summary

  • replace interpolated MySQL queries with prepared statements in Low, Medium, and High SQL Injection levels
  • use bound parameters for the equivalent SQLite queries
  • require decimal user IDs and bind them as integers to prevent database type coercion of attacker-shaped strings
  • preserve valid user lookup behavior while preventing injected input from changing query structure or resolving an account
  • add authenticated runtime regression tests for all three levels

Runtime coverage

  • Low: ID 1 resolves only admin; boolean payload returns no record
  • Medium: ID 2 resolves only Gordon; numeric boolean payload returns no record
  • High: session ID 3 resolves only Hack; UNION payload returns no record
  • test flow resets the database, logs in, and changes security levels through real CSRF-protected forms

Verification

  • 3/3 authenticated HTTP smoke tests pass with resource warnings treated as errors
  • PHP syntax checks pass for Low, Medium, and High in the rebuilt PR image
  • git diff --check passes
  • scorer previously recognized all three affected challenge levels (6/108 points); the updated commit will re-score them

Signed-off-by: Toby Moreno <chris.moreno.ctr@km.spaceforce.mil>
@github-actions

github-actions Bot commented Aug 9, 2026 •

Copy link
Copy Markdown

🏆 DVWA — CTF Patch Score

█░░░░░░░░░░░░░░░░░░░  6 / 108 pts  (6%)

3 / 55 challenges patched

Per-challenge detail is withheld — it would reveal the rubric.

Commit: 2f6a56b · scoring run

🎉 Your result is on the leaderboard — see where you rank! 🏆

Require decimal user IDs and bind them as integers across MySQL and SQLite. Add authenticated HTTP tests that preserve valid lookups while rejecting boolean, numeric, and UNION injection payloads.

Signed-off-by: Toby Moreno <chris.moreno.ctr@km.spaceforce.mil>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant