webProeasy

Pryzhok

hackerlab

Task: a PHP login page behind Apache redirected unauthenticated users to login.php and rejected normal credentials, while naive SQLi caused 500 errors. Solution: establish a PHP session first, then use a balanced parenthesis SQL injection with /**/ comments to bypass authentication as admin.

$ ls tags/ techniques/
comment_based_space_bypassparenthesis_balancinglogin_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups