Put it together on a live target. The invoice portal concatenates your search into a MySQL query: find the injection, enumerate the schema, and recover the compromised analyst's credentials.
Hands-on lab
Runs on your machine, your server or your cloud account through the Cyber CTF launcher.
Checking your machines