Sunday, November 1, 2009

SQL Injection / Hacking security

With SQLServer/ Mysql server running at the background try:

abc' or 1=1--

Enter above line of code in username and hit login, you might get shocked when you actually login to the site with a valid user.

For testers this is an important point to ensure a secure application.
And for hackers a boon!! ;)

No comments:

Post a Comment

I welcome your comment, will respond and post it at the earliest:)