<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SQL-Injection on Cyshield Seclab</title><link>https://seclab.cyshield.com/tags/sql-injection/</link><description>Recent content in SQL-Injection on Cyshield Seclab</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 Cyshield.</copyright><lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://seclab.cyshield.com/tags/sql-injection/index.xml" rel="self" type="application/rss+xml"/><item><title>WAF Evasion 101: How Attackers Bypass “Security Gates”</title><link>https://seclab.cyshield.com/posts/waf-evasion-101-how-attackers-bypass-security-gates/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/waf-evasion-101-how-attackers-bypass-security-gates/</guid><description>Attackers reshape the same malicious payload just enough that the WAF no longer recognizes it, while the backend still executes it exactly as intended. This post walks through the real evasion playbook (encoding tricks, token splitting, noise injection, and reinforcement-learning-driven automated probing) and shows why the problem is structural, not a matter of sloppy engineering.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/waf-evasion-101-how-attackers-bypass-security-gates/featured.webp"/></item><item><title>CyCTF 2023 Challenge: A Whitebox Walkthrough of "The Secret App v1.0"</title><link>https://seclab.cyshield.com/posts/cyctf-2023-challenge-a-whitebox-walkthrough-of-the-secret-app-v1.0/</link><pubDate>Sun, 31 May 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/cyctf-2023-challenge-a-whitebox-walkthrough-of-the-secret-app-v1.0/</guid><description>A whitebox walkthrough of the CyCTF 2023 &amp;lsquo;Secret App v1.0&amp;rsquo; challenge — chaining second-order blind SQL injection, a CAPTCHA logic flaw, and insecure session handling into a full admin account takeover.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/cyctf-2023-challenge-a-whitebox-walkthrough-of-the-secret-app-v1.0/featured.webp"/></item></channel></rss>