- There is a
stock
andusers
table - Can you try to view, add, update the stock?
- Can you try to log in as any user?
- Can you try to log in as a ficticious user?
/playground
- Accepts SQLite queries/login
- Login demos- Login 1 - Basic
- A basic
' OR '1'='1' --
- A basic
- Login 2 - Paranthesis
- Use errors to figure out query
- Login 3 -
/OR/gi
WAF- How can we bypass this?
OORR
- How can we bypass this?
- Login 1 - Basic
yarn
yarn dev