CODE
' OR 1=1--
I dont know what the "OR" is but i do know what the "1" is...
1=Correct...
0=Incorrect...
X=Anything...
dont ask what the "=" is becuase i dont know...
But anyways... People would type that in as a username and password... I dont know how, but it tells the server that you have entered a correct password (Thats what the "1" does) letting you login without a real username and password...
People nowa days use big complex injections like
CODE
INSERT INTO 'admin_login' ('login_id', 'login_name', 'password', 'details') VALUES (666,'neo2','newpas5','NA')--
But i dont know anything about those.... I am just telling you what i know and trying to give you an idea of what it is
Note:I can guarentee this exploit does not work anymore... like i said, its one of the first expliots...
Sorry if this is confusing or i didnt explain right...
You can find out more about sql here...
http://www.sqlcourse.com/

