> For the complete documentation index, see [llms.txt](https://thamizhiniyancs.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://thamizhiniyancs.gitbook.io/writeups/overthewire/natas/level-14-level-15.md).

# Level 14 - Level 15

```
Username: natas15
Password: TTkaI7AWG4iDERztBcEyKV7kRXH1EZRB
URL:      http://natas15.natas.labs.overthewire.org
```

## Overview

This time we got an input field, which checks whether the given username exists and also we got the link to the source code.

<figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2F7A6RjNl3J9vwFNE3M0OA%2Fimage.png?alt=media&amp;token=cdb0d8bb-89fa-4b61-aed6-ea513a8f5366" alt=""><figcaption></figcaption></figure>

***

## Source Code Analysis

Let's take a look at the source code.

<figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2F1QpHYOMLi8kaCO50VxH8%2Fimage.png?alt=media&amp;token=00ba44fe-dc11-47f2-b5e2-4a763810ce5e" alt=""><figcaption></figcaption></figure>

The input field is vulnerable to SQL Injection and also from the source code, we can identify the current database name and table name as `natas15` and `users` respectively.

***

## Testing SQL Injection

I first checked whether the SQL injection works by using the same payload that we used in the last level.

<div><figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2FwbfOwdeGLpA1EASIAJvR%2Fimage.png?alt=media&amp;token=91bfe162-a899-44a5-a778-8a021f5b6a46" alt=""><figcaption></figcaption></figure> <figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2Fa5G5NSXgwbbrhuhfVvCt%2Fimage.png?alt=media&amp;token=065c191a-6eff-4ea5-9aab-54cf824ec8eb" alt=""><figcaption></figcaption></figure></div>

Next I just gave `"` as the payload, looking out for clues in error thrown in the response, but no details were disclosed in the error.

<div><figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2Fuki7lwhpC0MhZKKvmeSO%2Fimage.png?alt=media&amp;token=ace6fd2a-17be-4ca4-9c1c-591422fcc749" alt=""><figcaption></figcaption></figure> <figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2FnOvB2nQhnWaPnnDWFuPn%2Fimage.png?alt=media&amp;token=3293305b-26dd-43fa-9761-0dad40ba48bb" alt=""><figcaption></figcaption></figure></div>

***

## Getting the Password

Since, no details were disclosed, we have to check for blind and time based SQL injection. So, I captured the request using burpsuite and saved the request to a file to test the input field with sqlmap.

<div><figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2F2VDGbAvTTnRw9EwbE6yu%2Fimage.png?alt=media&amp;token=44c24ef2-5ba1-43d5-b0aa-fc3adc04eac8" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2FimZOI5EVhpSSSGNffUw1%2Fimage.png?alt=media&amp;token=2723ddb4-da44-4091-923c-0ab956132304" alt="" width="563"><figcaption></figcaption></figure></div>

From the results of sqlmap, we can see that the input field is vulnerable to boolean-based blind SQL injection. Since we know the current database name and the table name, I directly dumped the table, in which the password for the next level is present.

<div><figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2FqqURQk5OcHYHf4i4C5d7%2Fimage.png?alt=media&amp;token=e5c64d30-511b-4e23-b939-20b463fb7dcf" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2FxJrr64qXlgUho92bMtAM%2Fimage.png?alt=media&amp;token=c4429441-eab8-4cbf-8a87-a9a96a4aca61" alt="" width="359"><figcaption></figcaption></figure></div>
