SQLGuardJS Protection Flow

How it defends against injection and XSS attempts

CTF Challenge: Bypass SQLGuardJS

Problem Statement

This web application is secured by SQLGuardJS, a request verification layer that intercepts SQL injection and XSS payloads. Your objective is to discover a bypass technique that circumvents the guard's detection mechanisms and successfully executes a malicious SQL query against the backend SQLite database.

The Goal

A secret flag is hidden within the flags table in the database. You can try to bypass the Authentication endpoint or extract data via the Search endpoint.

If you successfully bypass the filter, your output will look something like this:

{ "success": true, "results": [ { "role": "CTF{y0ur_h4ck3r_fl4g_h3r3}" } ] }

Without SQLGuardJS

Attacker
↓
Express Route
↓
Application Logic
↓
Database Executed / Rendered

With SQLGuardJS

Attacker
↓
🛡️ SQLGuardJS Middleware
↓
Blocked (403) or Passed to Route
← Back to Defense Lab