Premium Only Content
Web Security Academy ~ SQLi (Lab #2) ⚙️
If the query returns the details of a user, then the login is successful. Otherwise, it is rejected.
In this lab an attacker can log in as any user without a password simply by using the SQL comment sequence -- (double-dash) to remove the password check from the WHERE clause of the query.
By submitting the username administrator'-- the password results in the following query:
SELECT * FROM users WHERE username = 'administrator'--' AND password = ''
Ignoring the password field, because it comes after the comment sequence (double-dash)
This query returns the user whose username is administrator and successfully logs the attacker in as that user.
💙💙💙💙💙💙💙💙💙💙💙💙
FREE CYBER SECURITY LEARNING RESOURCES :
The Cyber Mentor --- https://academy.tcm-sec.com
Nathan House --- https://www.stationx.net
John Hammond --- https://johnhammond.org
Loi Liang --- https://loiliangyang.com
HackerSploit --- https://hackersploit.org
David Bombal --- https://davidbombal.com
Professor Messer --- https://www.professormesser.com
w3schools --- https://www.w3schools.com
#hacktolearn #websecurityacademy #sqli #commentsequence #doubledash
-
1:01:00
Badlands Media
14 hours agoMAHA News [12.5] Glyphosate Study Retracted (MONSANTO), Vaccine News (COVID), DMSO Chat
35.1K4 -
1:11:14
DeVory Darkins
5 hours agoJeffries SCRAMBLES After National Gas Prices hit record low amid AFFORDABILITY CRISIS
213K94 -
56:44
The Quartering
5 hours agoSpam Calls Are Out Of Control, Candace Hits Rock Bottom & More Poison Food
60.6K90 -
47:44
Tucker Carlson
5 hours agoRupert Lowe Warns of the Globalist Agenda Destroying the West and the Revolution Soon to Come
86K134 -
1:16:03
Sean Unpaved
6 hours agoWill Miami Be "ODD MAN OUT" Of The College Football Playoff? | UNPAVED
35.8K1 -
58:31
Jeff Ahern
4 hours ago $1.25 earnedFriday Freak out with Jeff Ahern
23.3K6 -
27:03
The Kevin Trudeau Show Limitless
2 days agoThey're Not Hiding Aliens. They're Hiding This.
44.1K63 -
2:04:26
The Culture War with Tim Pool
7 hours agoWoke Has INFECTED Goth, Punk, & Metal, MAGA Must Save the Art | The Culture War Podcast
147K65 -
1:12:25
Steven Crowder
7 hours agoCNN Declares J6 Pipe Bomber White & Nick Fuentes Interview Reaction
357K324 -
6:08:30
Dr Disrespect
7 hours ago🔴LIVE - DR DISRESPECT - ARC RAIDERS - FREE LOADOUT EXPERT
53.4K6