Authentication Bypass
This method consists of considering that the web application isn't interested in the content of the username and password, but in making a matching pair in the users' table.
We assume the database uses a basic query for authentication
We can do a malicious insertion on the password field
After the ;--
is mandatory to put a space
On PHP-based pages, we can replicate the same with a different payload
Last updated
Was this helpful?