← back to the grid
webeasy

SQL Injection 101

HEMLEM PORTAL's login form was written in a hurry. The dev trusted the input string. That was the only mistake they needed to make.

sandbox · allow-scripts · no-same-origin · null-origin● live

practice grid — every target is a toy in your own browser. this is not an invitation to test the real site.

enter flag