Task desc

This task includes a website with an input form on the website: https://login.mars.picoctf.net/

Let’s try a standard SQL injection trick.

image_2

Check source code:

image_3

There is a string similar to a base64 here, let’s try to decode it:

image_4

picoCTF{53rv3r_53rv3r_53rv3r_53rv3r_53rv3r}