Guest User

Untitled

a guest
May 1st, 2018
290
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.81 KB | None | 0 0
  1. $user = (!empty($_POST['user'])) ? $_POST['user'] : '';
  2. $pass = (!empty($_POST['pass'])) ? $_POST['pass'] : '';
  3.  
  4. $res = mysql_query("SELECT * from users where user='{$user}' AND pass='{$pass}'");
  5.  
  6. $res = mysql_query("SELECT * from users where user='foo' -- ' AND pass=''");
  7.  
  8. $res = mysql_query("SELECT * from users where user='foo' OR (DROP TABLE users) -- ' AND pass=''");
  9.  
  10. $res = mysql_query("SELECT * from users where user='foo'; DROP TABLE users -- ' AND pass=''");
  11.  
  12. For both username and password, I enter:
  13.  
  14. ' OR 1=1 AND '}' '=
  15.  
  16. $user = (!empty($_POST['user'])) ? $_POST['user'] : '';
  17. $pass = (!empty($_POST['pass'])) ? $_POST['pass'] : '';
  18.  
  19. $user = mysql_real_escape_string($user);
  20. $pass = msyql_real_escape_string($pass);
  21.  
  22. $res = mysql_query("SELECT * from users where user='{$user}' AND pass='{$pass}'");
Add Comment
Please, Sign In to add comment