Skip to content

Meridian Holdings · after hours

SQLHeist

Every system has a door somebody forgot to lock.

You find them. A real database is on the other side — no simulation, no safety net but the sandbox. Pull three cases. Then learn how they should have stopped you.

LIVE FIRE: USERS.SEARCH INJECTION MODE
YOUR INPUT
' OR '1'='1' --
EXECUTED SQL
SELECT id, username, role
FROM users
WHERE username = '' OR 1=1 -- '
RESULT 3 ROWS

1adminadmin

2aliceuser

3bobuser

DEFENSE AVAILABLESwitch to a parameterized query and the attack stops.

0 ROWS

The five-move heist

  1. 01Brief

    Neo names the mark and the take — never the method.

  2. 02Recon

    Case the target. Find where your input actually lands.

  3. 03Exploit

    Type into the form, watch the live query your input builds, then run it.

  4. 04Loot

    The take and your score. Nobody stopped you — that is the point.

  5. 05Debrief

    The vulnerable code beside the fix that closes it. This is defence.

Three cases · one path

Choose the next door.

8 objectives across three escalating cases. Each run gets a freshly seeded local database.

Real database · safe playground

Practice on live SQL. Break it. Fix it. Understand it.

Every case runs against SQLite in your browser. The target is isolated, seeded fresh, and resettable at any time.

  • Isolated targetYour practice database stays on this device.
  • Reset anytimeReturn the case to its initial state.
  • Real, not toyActual SQL engine. Observable results.
Safe by design

No real target. No external system receives your payload.

VULNERABLE: CONCATENATIONINJECTION RISK
// Input is inserted into source
const q = "SELECT id, username, role
  FROM users WHERE username = '" + input + "'";
USER INPUT' OR 1=1 --

The value escapes the string and rewrites the logic.

SECURE: PARAMETERIZED QUERYSAFE
// Structure and value stay separate
const q = "SELECT id, username, role
  FROM users WHERE username = ?";
db.execute(q, [input]);
PARAMETER BOUND, NOT EXECUTED["' OR 1=1 --"]

The input remains data. Query structure cannot change.

  1. 01Run the attack

    Submit the injected value.

  2. 02Observe the result

    See rows the user should not get.

  3. 03Switch to the fix

    Use the parameterized query.

  4. 04Run it again

    Submit the same exact input.

  5. 05Confirm it is safe

    Only intended data is returned.

Operator support

Pre-flight check.

Everything is isolated, resettable, and made for learning. Clear the questions before your first operation.

Read every answer Neo gives
01Is this legal?

Yes. Every job targets only the sandboxed SQLite database in your browser. The practice payload never reaches a real system; site delivery and optional account sync are separate from the target.

02Do I need to install anything?

No. It runs in a modern browser. The SQLite engine loads on demand the first time you need it — no account needed, no downloads, no setup.

03Do I need to know SQL already?

It helps. The game assumes you can read a SELECT and roughly follow a WHERE clause. It teaches you injection — not SQL from zero.

04Are you teaching people to attack real websites?

We teach how injection works so you can recognise it and close it — every job ends with the fix, not the break-in. Use it only on systems you own or are allowed to test.

Neo · “Three cases. You keep what you learn — Meridian keeps the bill.”

The door is open. Walk through it.

Take the first case