What you are looking at
Many beginner labs still use a login check that concatenates the username and password into SQL. If the application never uses parameterized queries, a single quote in the username field can change the meaning of the statement.
Lab only
A typical broken check
SELECT * FROM users
WHERE username = 'INPUT'
AND password = 'INPUT'
LIMIT 1;If the username value closes the string and adds a condition that is always true, the password check never matters. The application then treats the first returned row as an authenticated user.
What to observe in the lab
- Submit a normal username and watch a failed login.
- Add a single quote and look for a SQL error, a blank page, or a different status code.
- Confirm whether the query is reflected in an error message — that is a strong signal.
- Once you can change the boolean logic, try to land on a valid session in the lab.
Fix the application, not the payload
The durable fix is parameterized queries (or an ORM that binds values), plus hashing passwords with a slow algorithm. Escaping quotes by hand is fragile and usually fails the next encoding trick.
Try it hands-on